Hospital cyberattacks underscore growing financial and operational risks
Recent disruptions at hospitals show how healthcare cybersecurity incidents can affect patient care, revenue cycle operations and financial performance as new federal requirements loom.
As seen in two incidents over the past month and in a newly issued warning, cyberattacks are a relentless threat to hospitals and their communities.
The South Carolina-based health system AnMed and Texas-based JPS Health experienced disruptions that included implementation of downtime procedures and patient-diversion protocols.
And in recent days, the American Hospital Association highlighted the relevance to hospitals of an August 2026 joint advisory from the National Security Agency and other federal agencies. The advisory describes active cyber threats to Siemens S7 Series programmable logic controllers (PLCs), devices that monitor equipment in areas such as climate control and access control.
“The actors are using internet scanning services to find PLCs that are using outdated software or are poorly protected,” states the AHA’s notice.
“It is strongly recommended that vulnerable PLCs be disconnected from the internet or placed on isolated networks,” stated Scott Gee, the AHA’s deputy national advisor for cybersecurity and risk, who also suggested the warning is applicable to other PLCs in addition to Siemens S7s.
AnMed attack shuts down EHR and outpatient services
The July 26 malware attack on AnMed caused multiday closures of more than 80 physician offices and imaging facilities, alongside a shutdown of the organization’s electronic health record (EHR).
Emergency care at the organization’s 495-bed medical center remained available, but some patients were diverted to nearby health systems and some discharges took place without formal paperwork. Services such as oncology and radiation were paused to funnel needed resources to areas such as the emergency department, urgent care and labs.
As of mid-August, 10 of the system’s outpatient facilities remained closed, but most EHR access (i.e., read-and-write access) was restored. Patients with an active MyChart account and a mobile number on file could view their health information, although features such as electronic messaging between clinicians and patients reportedly were unavailable.
Also in August, a ransomware group posted to the health system’s Facebook page to say it had six terabytes of patient data, including sensitive records such as HIV-positive cases, suicide registries and cases of sexual assault. Data allegedly would be released if the health system did not pay a ransom.
The post was subsequently deleted, and AnMed said its legitimacy has not been verified. On Aug. 21, the organization confirmed that the cybercriminals obtained information in the attack, but the specifics of that information required further investigation.
Fitch Ratings issued a commentary stating that AnMed’s AA- credit rating and “Stable” outlook were unlikely to change because of the attack.
JPS Health uses downtime procedures to contain threat
Fort Worth, Texas-based JPS Health Network, which includes a Level I trauma center, dealt with a network outage starting Aug. 3.
JPS said it flagged suspicious activity before widespread damage occurred, implementing controlled network-downtime procedures. Resulting steps included manual charting and the diversion of emergency transport services to other hospitals. Patients faced delays obtaining prescriptions, along with restrictions in accessing the MyChart portal.
One patient told a local news outlet that when she went for a hospital appointment in the days following the attack, on-site doctors “didn’t know my history. I told them I just had a CT scan. They couldn’t see [that].”
A bigger concern, she indicated, was her inability to reach the pharmacy to fill prescriptions for two medications.
By Aug. 14, the system’s EHR was back online and diversion of emergency patients had ended. Elective procedures resumed, as did normal operations at outpatient pharmacies and community clinics. Two days later, MyChart was accessible.
Recent trends in healthcare data breaches
Healthcare has topped all industries in average data-breach costs for 13 years, most recently tallying a global average of $6.6 million per incident over a 12-month period in 2025-2026, according to an annual report (registration required) by IBM and the Ponemon Institute.
The report pinpoints a surge in AI-enabled attacks (e.g., deepfake impersonations and AI-generated malware), making attacks more cost-effective for ransomware groups. On the flip side, organizations utilizing security AI and automated monitoring tools reportedly save an average of nearly $2 million per breach, compared with other organizations.
As highlighted in the 2024 attack on the revenue cycle vendor Change Healthcare, ransomware groups also are targeting the third parties that contract with hospitals. Among healthcare industry breaches reported to HHS’s Office of Civil Rights in 2026, one of the biggest in volume of exposed patient records was at the billing-services vendor TriZetto Provider Solutions, where nearly 3.5 million individuals were affected.
In another shift, stronger endpoint security defenses and more reliable off-network backups at healthcare organizations have prompted a rise in “extortion-only” attacks. Instead of deploying ransomware to jam a hospital’s software, hackers exfiltrate volumes of protected health information and demand a ransom to refrain from releasing the data.
Cyber incidents can strain margins and credit profiles
In a special report (login required), Fitch analysts wrote that “the frequency, sophistication and impact of cyber incidents have increased significantly” in healthcare.
“Recent incidents demonstrate that the financial impact of an attack often extends well beyond remediation expenses,” the report states, citing the potential for prolonged impacts on EHRs, patient scheduling, revenue cycle operations and other areas.
Impacts can include delayed billing and collections, reduced patient volumes and increased labor costs.
“In many cases, the most significant financial effects emerge during the recovery period rather than during the attack itself,” according to the report.
Credit downgrades stemming from an attack are more likely in organizations that already faced operational or financial stress, the report notes.
Federal policy could raise hospital cybersecurity requirements
A pending update to the HIPAA Security Rule is intended to shore up healthcare cybersecurity gaps. In response to stakeholder concerns expressed during the notice-and-comment period, HHS pushed back scheduled publication of the final rule by one year, to July 2027.
Provisions in the proposed version of the rule called for largely eliminating the distinction between “required” and “addressable” specifications, thereby making a wider array of security controls mandatory.
Other requirements in the rule pertain to multifactor authentication across access points, stronger encryption of data at rest and in transit, and tighter incident-response windows. There also would be stricter mandates for testing and digital-asset management.
In Congress this year, the Senate Health, Education, Labor and Pensions (HELP) Committee advanced the Health Care Cybersecurity and Resiliency Act of 2026 on a 22-1 vote. The bill would require HIPAA-regulated entities to implement steps such as universal multifactor authentication and end-to-end encryption of protected health information.
The bill would establish a grant program to support cybersecurity in rural and under-resourced healthcare facilities. Hospitals that incur an attack would be subject to substantially lower fines and penalties for HIPAA violations if they demonstrate that they used cybersecurity best practices over the 12 months before the breach.
Resources
Federally recommended cybersecurity best practices are available from HHS and from CISA.