Health economists linked six years of hospital attack records to Medicare claims and measured what happened to patients who were already admitted when systems went down.

 

What happened

In-hospital mortality among patients already admitted when a ransomware attack begins increases by 34% to 38%, according to peer-reviewed research by Hannah Neprash, Claire McGlave, and Sayeh Nikpay of the University of Minnesota School of Public Health, published in American Economic Journal: Economic Policy in February 2026. The team built a database of hospital ransomware attacks and linked it to Medicare fee-for-service claims, comparing outcomes at attacked hospitals against a control group of hospitals that would experience attacks at least five weeks later. Restricting the mortality measure to patients admitted before the attack began removes the possibility that the hospital was receiving a different mix of cases during the disruption. The same analysis found hospital volume falling 17% to 24% during the initial attack week, with recovery taking about three weeks.

 

Going deeper

The operational numbers explain how the mortality effect reaches patients who never touched a computer. Volume declines across emergency, inpatient, and outpatient settings at once, and Medicare revenue drops between 19% and 41% depending on setting, according to the study's supplemental materials. A hospital running at three-quarters of capacity is diverting ambulances, postponing procedures, and working without imaging and laboratory systems while staff reconstruct medication histories on paper. Neighboring facilities absorb that displaced volume without warning or additional staffing. An earlier working version of the analysis estimated that ransomware attacks killed between 42 and 67 Medicare patients between 2016 and 2021.

 

What was said

The authors state in the published abstract that ransomware attacks decrease hospital volume during the initial attack week "with recovery occurring within 3 weeks," and that mortality rises among patients already admitted. The framing treats ransomware as an operational disruption with clinical consequences rather than as a data security problem, which is what separates the finding from survey-based claims about patient harm.

 

In the know

The same research group produced the count that puts the mortality figure in context. Between January 2016 and December 2021, 374 ransomware attacks on US healthcare delivery organizations exposed the protected health information of nearly 42 million patients and caused electronic health record downtime, cancellations, and ambulance diversions, according to their JAMA Health Forum analysis cataloged by HHS. The authors noted the real number runs higher, since no reporting requirement captures attacks that never trigger breach notification. A companion study in the Journal of Rural Health measured the additional travel distance and time patients face reaching the next facility when a rural hospital goes down.

 

The big picture

The regulatory response has moved slower than the evidence. The proposed HIPAA Security Rule update that would make encryption, multifactor authentication, and network segmentation mandatory rather than addressable now targets July 2027 after being moved to the long-term actions list. Organizations weighing security investment against operating margin have generally framed the calculation around breach notification costs, regulatory penalties, and downtime revenue, all of which are recoverable in a way a mortality effect is not. Boards and clinical leadership reviewing cyber risk now have a peer-reviewed number to put alongside the financial ones, which changes what a delayed patch or an unsegmented network represents on a risk register. The security research community has started treating the clinical dimension as a subject of its own, with Black Hat USA and the Healthcare Information and Management Systems Society holding their first joint healthcare summit this month around clinical disruption rather than data theft.

 

FAQs

Why use Medicare claims rather than hospital records?

Claims data covers every facility on a consistent basis and is not controlled by the organizations being studied, so attacked hospitals cannot influence what it shows. The tradeoff is that it captures only Medicare fee-for-service patients, meaning the findings describe an older population rather than all admissions.

 

Why does hospital volume fall during an attack?

Emergency departments activate diversion protocols that route ambulances elsewhere, elective procedures get postponed, and transfers into the facility stop. The decline is largely a deliberate safety response rather than a collapse in demand, which is why volume recovers once systems come back.

 

What makes the three-week recovery window dangerous?

Systems restored does not mean workflows restored, since backlogged imaging, delayed lab results, and reconciliation of paper records continue well past the technical recovery. Clinical decisions made with incomplete information during that period carry risk that no security dashboard measures.

 

Does downtime planning address this?

Partially. Most hospitals maintain paper downtime procedures for hours or a day, which is a different problem from operating on them for weeks. Planning that assumes short outages leaves gaps in medication reconciliation, allergy verification, and result tracking once the duration extends.