In August 2026, Boston Scientific announced that a cyberattack resulted in disruption to some business applications and operating systems. There was no known impact to the functionality of existing implantable cardiac rhythm management devices at that time. Remote monitoring activations of new devices were affected, which prevented some newly implanted systems from sending available data to remote patient-management platforms.
Providers can use HIPAA compliant email to maintain a list of affected patients, schedule in-person device checks, and confirm that remote monitoring is available again. Coordinating these updates in writing can help clinical teams track device information until the supporting service is restored.
A medical device is part of a larger system
A systematic review in Computers in Biology and Medicine explains, “The Internet of Medical Things (IoMT) is a network of interconnected medical devices and applications aiming to facilitate real-time data sharing and personalised patient care.” It enables real-time data exchange between devices and facilitates personalized patient care. Along with the physical device, that system can include bedside or home communicators, mobile applications, vendor platforms, hospital networks, and electronic health records. An attack can disrupt data flow by taking down one of these components, even if the device appears to work during patient care. HIPAA compliant email provides a secure way to send necessary protected health information about which services were lost, how clinicians should respond, and what information needs to be gathered after systems are restored.
Boston Scientific gave further clarification when describing the impact on its systems. While the cyberattack did not interfere with how the devices work, it could prevent clinicians from receiving their information as usual. Until connectivity is restored, healthcare providers can document notices like this one, any workarounds that were attempted, and follow-up care via secure email. Paubox’s ability to confirm that a message was received can prevent important updates from being missed.
Other technology outages can cause similar care disruptions
Researchers behind a study published in JAMA Network Open note, “Modern health care depends on digital infrastructure.” They examined 2,232 hospitals and detected service disruptions at 759 of them during the CrowdStrike outage of 2024. Although caused by a defective security software update, clinicians were still unable to access certain systems during the four-hour outage. Patient-record access, fetal-monitoring interfaces, interhospital transfers, and telemonitoring-management platforms were among the affected services.
Ransomware attacks exhibit the same challenge. After hackers infiltrated the computer systems of a general hospital, a Frontiers study found that returning each clinical system was associated with increases in clinical activity. Restoring electronic medical records increased workload by 30%, and imaging archives by 50%.
According to the authors, rebooting these three clinical systems was the most crucial step for restoring the hospital to its previous clinical volume. During any downtime, providers can use encrypted email to distribute instructions about what services remain available, share urgent results and revised procedure dates, or request that clinicians resend records before reviewing workloads. Requiring recipients to acknowledge receipt can help prevent important updates from being missed.
In another JAMIA published journal article, researchers who analyzed 76 patient-safety reports about electronic health record downtime found that 49% involved problems with laboratory orders or results and 15% involved medication ordering or administration. They concluded that EHR downtime events pose patient safety hazards. Healthcare organizations can outline which information can be sent through HIPAA compliant email, which should be confirmed by telephone, and which will require clinicians to follow established procedures for placing orders. Encrypting permitted communications can limit exposure while providing clinicians with a viable alternative.
Vendor outages can delay equipment and procedures
Although its products were not affected by the cyberattack, Stryker announced during the March 2026 cyberattack that delivery delays would require some patient-specific procedures to be postponed. Boston Scientific later added in its SEC filing that its own cybersecurity incident was impacting manufacturing and processing and shipping of customer orders. During these scenarios, HIPAA compliant email allows hospitals to coordinate requests for higher-priority equipment, desired implant characteristics, revised procedure dates, alternate-product decisions, and delivery confirmations. Staff can prevent unnecessary exposure by only including the minimum patient information necessary to make these decisions. This can help clinicians and supply-chain professionals weigh risks when vendors cannot supplement their normal ordering tools.
Paubox also covered how the TriMed cyberattack potentially exposed files containing patient identifiers and information about implanted hardware. Device manufacturers can retain data linking named patients to implanted devices, vendor-specific surgical components, and ordering clinicians. Because this information could be considered protected health information under HIPAA, sharing entire patient histories via routine supply-chain messages can become an exposure risk. Providers can prevent unnecessary exposure by using secure email only for the information needed to solve the order or continuity issue.
The effects can spread to other healthcare organizations
Instead of receiving care at the impacted hospital, patients may be redirected to other providers. A JAMA Network Open study of a ransomware attack in San Diego County found that an emergency department which was not attacked still experienced “significant increases in patient census, ambulance arrivals, waiting room times, patients left without being seen, total patient length of stay, county-wide emergency medical services diversion, and acute stroke care metrics were seen in the unaffected ED.”
The study found significant increases in emergency-department census, ambulance arrivals, waiting-room times, admissions, and patients leaving without being seen at an unaffected hospital. HIPAA compliant email allows hospitals to share referrals, transfer documents, capacity information, and follow-up responsibilities while knowing that the message was received. Clinicians at the accepting facility will have more information to work with, and they will not have to log into the affected hospital’s systems.
Secure email must also be protected from attack
Paubox’s 2026 Healthcare Email Security Report notes that healthcare suffered 170 email-related breaches during 2025. This put over 2.5 million people at risk of exposure, and business associates and vendors were responsible for 28% of the incidents we analyzed. Before choosing to work around affected servers, healthcare organizations should ensure that their approved email environment was not impacted by the attack, confirm there was no unusual mailbox or administrator activity, enable multifactor authentication, and prepare users to recognize phishing emails. Working with a verified HIPAA compliant email service can then prevent clinicians from moving sensitive data to consumer email accounts or other inappropriate software.
FAQs
Can providers share patient information with another healthcare provider during an emergency?
Yes, providers may disclose protected health information without patient authorization when necessary to treat, refer, or coordinate care for the patient.
Is written authorization required before contacting a patient’s family?
Written authorization is generally unnecessary for notification purposes when the patient agrees, does not object, or the provider can reasonably infer that the patient does not object.
Can healthcare organizations share information with disaster-relief organizations?
Yes, they may share necessary information with authorized organizations such as the American Red Cross to coordinate notifications about a patient’s location, general condition, or death.
