Hospital Ransomware Raises Patient Mortality 38%: Black Hat and HIMSS Launch Healthcare Summit

Patient in bed with IV
Olga Kononenko/Unsplash

When a ransomware attack hits a hospital, every minute of downtime is a clinical decision made without data. Clinicians work blind — medication histories gone, imaging systems dark, allergy records inaccessible. Emergency departments activate diversion protocols and send ambulances elsewhere. Pharmacies revert to paper. Surgeries are postponed. And patients already in the building die at measurably higher rates. Research published in the American Economic Journal: Economic Policy in February 2026 found that in-hospital mortality for patients already admitted when an attack begins rises 34 to 38 percent — not a modeled estimate, but a figure derived from Medicare claims data linked to confirmed ransomware incidents. The Halcyon Ransomware Research Center, drawing on University of Minnesota data, puts the cumulative toll at 42 to 67 preventable deaths over five years, with mortality rising from roughly three in 100 hospitalized Medicare patients to four in 100 under attack conditions.

That evidence is now the reason Black Hat USA 2026, which opened its training sessions this morning at Mandalay Bay Convention Center in Las Vegas, will host something it has never hosted in its 29-year history: a dedicated Healthcare Summit, built in formal partnership with HIMSS — the Healthcare Information and Management Systems Society — for the first time either organization has collaborated.

Black Hat Meets HIMSS: What Changed

The partnership between Black Hat and HIMSS was announced June 23, 2026, and described by both organizations as the first time they had ever joined forces. Suzy Pallett, President of Black Hat, said the collaboration is intended to establish “a new standard for cross-industry collaboration” by pairing HIMSS’s institutional knowledge of healthcare technology operations with Black Hat’s offensive security research community. Hal Wolf, HIMSS President and CEO, framed the moment more plainly: the summit addresses “one of the most urgent challenges facing health systems.”

The Healthcare Summit is scheduled for Tuesday, August 4, 2026, Summit Day at Mandalay Bay. It will bring together hospital CISOs, healthcare IT professionals, security practitioners, and clinical leaders for a full-day program focused on resilience, clinical disruption response, and patient trust. Varun Acharya, CISO at Healthscope, one of Australia’s largest private hospital operators, will serve as Summit Emcee. Pindrop serves as the summit’s premium sponsor; foundation sponsors include Akamai and Beacon, with Feroot Security, KLAS Research, and Rubrik as event sponsors.

The summit does not appear in a vacuum. Black Hat established the program directly in response to what its announcement materials called “the wave of cyberattacks targeting healthcare systems and patient data.” That wave has been large enough to prompt the first proposed update to the HIPAA Security Rule in a decade — a Notice of Proposed Rulemaking published by HHS on January 6, 2025, that would mandate multi-factor authentication, encryption of patient data at rest and in transit, annual penetration testing, and network segmentation as enforceable requirements rather than voluntary guidelines. As of August 2026, the final rule has not been issued; the Office of Management and Budget now targets July 2027 for finalization.

Hospital Ransomware at Scale: Why This Summit Is Overdue

The United States’ Department of Health and Human Services confirmed, as of July 31, 2025, that the February 2024 Change Healthcare ransomware attack affected approximately 192.7 million individuals — roughly two thirds of the US population. The attack was carried out by the ALPHV/BlackCat ransomware group, which exfiltrated more than 6 terabytes of billing and protected health information before encrypting Change Healthcare’s systems; a $22 million ransom was paid. Total costs from the attack are estimated at between $2.5 billion and $3 billion, and Ascension Health — a separate hospital network hit by ransomware in May 2024, exposing PHI for 5.6 million patients — reported a $1.1 billion net loss for fiscal year 2024, citing the attack as a material financial factor. The Synnovis pathology services ransomware attack in the United Kingdom in June 2024 — carried out by the Qilin group — exposed the data of nearly one million NHS patients; King’s College Hospital NHS Foundation Trust later confirmed that one patient died during the attack, with the death attributable in part to a delayed blood test result caused by the attack’s disruption of pathology services.

The FBI’s Internet Crime Complaint Center logged 460 ransomware incidents in the US healthcare and public health sector in 2024, more than any other critical infrastructure sector among the 16 designated under Presidential Policy Directive 21. Healthcare organizations reported 770 HIPAA breaches in 2025, the highest annual total on record, with Q1 2026 already showing a 29.4 percent increase in the number of individuals affected compared to the same period in 2025. Healthcare data breaches cost an average of $7.42 million per incident in 2025 — the highest of any industry for the 14th consecutive year — according to IBM’s Cost of a Data Breach Report 2025. When ransomware takes hospital systems offline, average downtime costs approximately $900,000 per day. A rural Illinois hospital permanently closed after 14 weeks offline because billing and staffing losses pushed its cash flow past recovery.

How Does Ransomware Make Hospital Mortality Worse

The technical architecture of most US hospitals creates structural vulnerability that ransomware operators have specifically learned to exploit. EHR systems such as Epic, Cerner, and Oracle Health function as centralized platforms that simultaneously serve medication records, imaging systems, laboratory orders, pharmacy management, and billing. When ransomware encrypts or disables that infrastructure, clinicians lose all of those systems at once — not selectively. ORDR’s 2026 Healthcare Cybersecurity Statistics Report found that 99 percent of hospitals manage devices containing known, exploited vulnerabilities, and that the average breach takes 241 days to identify and contain, giving attackers more than eight months of undetected access.

The majority of hospital networks are still minimally segmented — EHR systems, laboratory systems, pharmacy management, and administrative billing often share network access, meaning that a single compromised endpoint can enable lateral movement to all clinical systems simultaneously. The proposed HIPAA Security Rule update would mandate network micro-segmentation, partitioning hospital infrastructure by function to contain lateral movement. In the 13 years since the current HIPAA Security Rule was finalized, that segmentation has remained a best practice rather than a legal requirement for most facilities.

The tactic mix is also evolving. Encryption rates in US healthcare ransomware attacks fell from 74 percent to 34 percent of incidents in 2025, while extortion-only attacks — in which attackers steal PHI without encrypting systems and demand payment to prevent its release — tripled to 12 percent of cases, according to Sophos data. The Verizon 2025 Data Breach Investigations Report documented that exploitation of vulnerabilities surpassed stolen credentials as the primary ransomware entry point in healthcare for the first time in the report’s 19-year history. Attackers also routinely target backup systems: in roughly two thirds of healthcare ransomware cases, attackers specifically disable or encrypt backup infrastructure, ensuring that restoration from clean backups is not available as a bypass to payment.

During active ransomware attacks, the effects cascade beyond the targeted hospital. A JAMA Network Open study documented that during a 2021 four-hospital ransomware attack, two adjacent, unaffected hospitals experienced surges in ED volume, longer wait times, and increased stroke code activations. A separate analysis found that at hospitals not directly hit but affected by nearby attacks, ED arrivals rose 15 percent, wait room time increased 48 percent, cardiac arrests surged 81 percent, and suspected strokes climbed 75 percent. Survival rates for cardiac arrests also fell during these periods, reflecting delays in emergency response caused by system-wide disruptions.

What the Summit Will Address

The inaugural Black Hat × HIMSS Healthcare Summit is designed for healthcare IT leaders, CISOs, and security practitioners who must defend clinical environments under ongoing attack pressure. The program will examine how to secure AI applications in clinical settings, protect machine learning models from adversarial attacks, leverage AI-powered security solutions to safeguard patient safety and sensitive health data, and develop practical resilience strategies for organizations whose downtime tolerance is measured in patient outcomes rather than revenue.

The summit is part of Black Hat’s broader six-summit Summit Day on August 4, which also includes the invite-only CISO Summit (12th year), the AI Summit (3rd year, presented by TrendAI), the Financial Threat Summit (2nd year), the Innovators and Investors Summit (3rd year), and the Omdia Analyst Summit (6th year). The bipartisan Healthcare Cybersecurity Act of 2025 would, if enacted, direct CISA and HHS to collaborate more closely on training and incident response. A separate bipartisan bill, the Health Care Cybersecurity and Resiliency Act, would authorize HHS to provide cybersecurity grants to eligible healthcare providers. Neither has been enacted as of August 2026. The Halcyon Ransomware Research Center has characterized the current state as requiring a “whole-of-society” response — providers, government agencies, cybersecurity vendors, and community partners acting in coordinated defense rather than isolated silos.

What Can Hospitals Actually Do Right Now

The proposed HIPAA Security Rule update, if finalized, would transform several existing “addressable” recommendations into mandatory enforceable requirements: MFA on all systems accessing electronic protected health information, full encryption of ePHI at rest and in transit, network segmentation by function, annual penetration testing, vulnerability scans every six months, and a 72-hour incident reporting requirement. The 240-day compliance window would begin only after a final rule is published — now expected no earlier than mid-2027 at the earliest. Hospitals that wait for the final rule before beginning MFA deployment and network segmentation projects risk being unable to comply within the window, given vendor capacity and internal implementation timelines.

Healthcare organizations managing legacy medical devices — imaging systems, IV pumps, patient monitors, and other equipment that cannot be patched through standard IT update mechanisms — face a structural exposure that no compliance framework fully resolves. The ORDR report notes 99 percent of hospitals run such devices, many containing known exploited vulnerabilities. Network segmentation, which would isolate these devices from the EHR and billing infrastructure that ransomware actors target most aggressively, is the closest available mitigation.

The Halcyon Ransomware Research Center recommends that hospital security teams implement network micro-segmentation by clinical function (separating EHR, lab, pharmacy, and billing traffic), deploy dedicated anti-ransomware tools that monitor behavior at the point of execution rather than relying on signature-based detection, maintain offline backups following the 3-2-1 principle (three copies across two media types, one copy isolated), enforce phishing-resistant MFA across all systems accessing ePHI, and establish pre-negotiated relationships with external incident response firms and regional FBI and CISA contacts before an attack occurs rather than after.


Frequently Asked Questions

How does ransomware directly harm hospital patients?

When ransomware encrypts or disables a hospital’s electronic health record system, clinicians lose simultaneous access to medication histories, allergy records, imaging results, laboratory orders, and pharmacy management. Emergency departments cannot safely triage patients without medication records; surgeries are postponed when anesthesia records are inaccessible; ICU nurses cannot record vital signs digitally. Research published in the American Economic Journal: Economic Policy in February 2026 found that in-hospital mortality for patients already admitted when an attack begins rises 34 to 38 percent. The effects also cascade to neighboring hospitals: during nearby ransomware attacks, unaffected hospitals see cardiac arrests surge 81 percent and suspected strokes climb 75 percent as diverted patients overwhelm their capacity.

Has a patient ever definitively died because of a hospital ransomware attack?

Yes. King’s College Hospital NHS Foundation Trust in the UK confirmed that a patient died during the June 2024 Qilin ransomware attack on Synnovis, a pathology and laboratory services provider. The hospital’s internal patient safety investigation identified “a number of contributing factors” to the death, including a long wait for a blood test result caused by the attack’s disruption of pathology services. The UK NHS’s confirmation was the first official institutional acknowledgment from a named healthcare organization that a ransomware attack directly contributed to a patient’s death.

Why is Black Hat partnering with HIMSS specifically, and why now?

Black Hat and HIMSS represent the two distinct professional communities that must now work together if hospital networks are going to be defended effectively: the offensive security research community that discovers and discloses vulnerabilities, and the healthcare technology standards body that sets operational frameworks for hospital IT. The two organizations had never formally collaborated before their June 2026 announcement. The timing reflects the accumulated evidence: the Change Healthcare breach affecting 192.7 million Americans, 770 record HIPAA breaches in 2025, peer-reviewed confirmation that ransomware raises patient mortality, and still-pending HIPAA Security Rule updates that have not been finalized. Both organizations described the moment as too urgent to address within existing siloed structures.

What does the proposed HIPAA Security Rule update actually require, and has it been finalized?

The HHS Notice of Proposed Rulemaking published January 6, 2025, proposes to replace HIPAA’s current “addressable” security recommendations with mandatory enforceable requirements: multi-factor authentication on all systems accessing electronic protected health information, mandatory encryption of ePHI at rest and in transit, network segmentation by clinical function, annual penetration testing, vulnerability scans every six months, and 72-hour incident notification timelines. As of August 2026, the final rule has not been issued. The Office of Management and Budget now targets July 2027 for finalization, meaning the mandatory requirements would not become enforceable until approximately early 2028 under a standard 240-day compliance window. Healthcare organizations currently operate under the original 2013 HIPAA Security Rule, which treats most of these controls as recommended but not required.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *