When Cyberattacks Hit Medical Devices, Patients Pay the Price

Healthcare organizations have spent years discussing cybersecurity through the lens of data breaches, ransomware payments, regulatory exposure, and reputational damage. Those risks matter. But when cybersecurity conversations begin and end with protecting data, we miss the bigger issue. In healthcare, the most serious consequence of a cyberattack is what happens to patient care.
As an emergency physician and Chief Medical Officer, I’ve spent my career working in environments where seconds matter and where clinicians depend on technology to make critical decisions. When systems become unavailable, unreliable, or difficult to access, care delivery changes immediately. Clinicians lose visibility into the information they need. Workflows break down. Communication becomes harder. Treatment can be delayed.
That reality becomes even more important as medical devices become increasingly connected to the broader healthcare ecosystem. Today’s devices are woven into the workflows clinicians rely on to diagnose, monitor and treat patients. When those devices are disrupted by a cyberattack, the consequences extend far beyond the technology itself.
That’s why medical device security should not be viewed primarily as an IT issue. It is a patient safety issue.
Medical Device Threats Are No Longer a Niche Threat
Recent research found that nearly one in four healthcare organizations experienced cyberattacks impacting medical devices over the past year. Of those incidents, 80 percent directly affected patient care. When medical devices are compromised, care must change in real time, often to its detriment. Safeguarding against such attacks is just as much about protecting endpoints or reducing organizational risk exposure as it is about keeping care delivery running safely. The issue with responding to such alarming statistics from an IT and compliance silo is that the two most common ways to address them (locking things down so much that they are unusable or working around them) can inadvertently cause the same damage to care delivery as the attacks themselves. The real solution needs to be good technology that secures the endpoints but remains easy to use.
I have seen firsthand how fragile clinical workflows can become when technology suddenly becomes difficult to access, is unavailable, or is untrustworthy in performing its intended function. Most people outside healthcare lack insight into how interconnected modern care delivery has become. Medical devices are deeply integrated into clinical workflows, authentication systems, electronic health records, medication administration processes, monitoring platforms, and communication systems.
What Care Disruption Actually Looks Like on the Frontlines
One of the realities of healthcare is that clinicians will always find a way to care for patients.
When technology becomes difficult to access, clinicians do not simply stop working. They adapt. They create workarounds. They share information through alternate channels. They delay documentation. They revert to manual processes. They do whatever they believe is necessary to keep care moving. That resilience is one of healthcare’s greatest strengths, but it can also create risk.
I have seen this firsthand throughout my career. In emergency medicine, clinicians simply cannot accept unnecessary delays when caring for critical patients. When devices become inaccessible, clinicians may delay documentation, share credentials, bypass standard authentication steps, revert to paper processes, manually transcribe information, or postpone diagnostics or procedures until systems become available again. Those decisions are made with the best intentions: keeping patient care moving under difficult circumstances. But every workaround introduces new opportunities for error, gaps in accountability, and additional security risk.
Consider what happens if an infusion pump network becomes unavailable because of a cyber incident. Medications may need to be administered through alternate workflows. Verification steps that are normally automated may become manual. Nurses may spend additional time documenting, double-checking information, or reconciling records across systems. This may sound simple. But, in reality, this is a huge burden. Healthcare environments already operate under significant cognitive and operational strain. Adding even small amounts of friction during a crisis increases the likelihood of mistakes and creates opportunities for delays, miscommunication, or error.
Security Must Work the Way Care is Delivered
Historically, healthcare cybersecurity strategies have focused heavily on protecting devices by patching endpoints, segmenting networks, and securing hardware. Those controls remain essential. But they do not fully address how care is delivered day by day, hour by hour.
A secure device that clinicians cannot access efficiently during patient care is still a problem. In fact, if security controls create enough friction that clinicians begin bypassing them, organizations can inadvertently increase risk rather than reduce it.
This is why cybersecurity decisions cannot be made in isolation from clinical operations. Every additional step, every delay, and every obstacle introduced into a workflow has the potential to affect patient care. Security controls that sound effective in theory can create unintended consequences at the bedside if they fail to account for how care is actually delivered.
Healthcare security cannot succeed if it ignores the realities of clinical workflows. That is where many organizations need to evolve their approach. They need to move beyond thinking only about devices and networks and focus equally on how clinicians access systems, move through workflows, and continue delivering care under pressure — without introducing unnecessary friction.
Cyber Resilience Is Clinical Resilience
Attackers understand that hospitals are uniquely vulnerable to operational disruption because patient care cannot simply stop. The need to get systems back online is far more critical by nature than in most other industries, making healthcare uniquely vulnerable to attacks designed to create urgency and chaos. Because many connected devices operate on legacy systems, are difficult to patch, or rely on complex vendor ecosystems that complicate visibility and accountability, medical devices expand the attack surface. The challenge is not only preventing these disruptions, but ensuring organizations can continue delivering safe care when they occur.
Hospitals respond more effectively during incidents when cybersecurity teams, clinical leadership, biomedical engineering, and frontline staff already know how to work together. Most organizations now conduct downtime drills for electronic health record outages, but far fewer meaningfully simulate medical device disruptions across interconnected workflows.
That gap means that there is rarely time to build safe processes in the middle of an incident. Organizations that regularly test response plans are better positioned to identify blind spots, clarify responsibilities, and understand how care delivery will continue when critical systems become unavailable. In many ways, resilience is built long before an attack occurs.
Healthcare organizations need to evolve their thinking. Medical device security matters because these technologies have become deeply embedded in how clinicians diagnose, monitor, and treat patients. Protecting them requires more than securing hardware or responding to incidents after the fact. It requires designing security, access, and operational processes that support the realities of care delivery, especially during periods of disruption.
Cyber resilience and clinical resilience are increasingly the same thing.
The organizations that will be best prepared are those that recognize cybersecurity as an integral part of patient safety strategy, not a separate technical function operating alongside it.
Because when a cyberattack affects a medical device, the most important question isn’t what happened to the technology. It’s what happened to the patient.
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!





