When a ransomware attack takes down a hospital's network, the first casualty is rarely the data. It is the assumption that the recovery plan is going to work.
Most healthcare disaster recovery plans were built for physical disruptions like hurricanes, power failures, and floods. They assume that backup systems in a geographically separate location will be clean and available, that staff will be able to reach an alternative site, and that the problem is fundamentally about restoring physical access to infrastructure that was not itself compromised. Ransomware attacks work differently; they don’t destroy buildings. They destroy trust in systems, and in healthcare, where care depends entirely on the integrity of those systems.
An organization with a fully functioning geographically dispersed backup site may find that it matters very little if both are compromised. The recovery environment is not separate from the attack if it shares authentication with the systems that were hit.
What patient harm actually looks like
A study published by the American Economic Association estimated that in-hospital mortality among already-admitted patients increases by 34% to 38% during the initial phase of a ransomware attack. A JAMA Network Open study published in May 2025, which analyzed ransomware attacks on US health care systems from 2010 through 2024, found that since 2020, ransomware has affected more than half of all patients annually, reaching 69% in 2024. The same study noted that findings likely underestimate the frequency of data breaches due to underreporting, reluctance to disclose ransom payments, and the exclusion of breaches affecting fewer than 500 records from public OCR reporting.
A JMIR systematic review of media portrayals of ransomware impacts, published in April 2025, found a recurring pattern across documented incidents where single points of failure in health informatics systems produce cascading impacts across clinical workflows, with imaging, lab distribution, medication dispensing, scheduling, and patient records all going down simultaneously when any one connected system fails. The review noted that paper-based fallbacks, which most continuity plans assume, are not realistic substitutes for modern clinical workflows, there is no paper-based fallback for radiation oncology treatment planning, and nurses cannot manually replicate the monitoring and alerting functions of clinical information systems that have been running for decades.
According to Paubox's 2025 Healthcare Email Security Report, ransomware attacks on healthcare have surged 264% since 2018. The FBI's 2025 Internet Crime Report confirmed healthcare as the most targeted critical infrastructure sector for the second consecutive year. These numbers represent a problem that is both growing and becoming more operationally severe with each year.
Read more: What is ransomware?
Why traditional disaster recovery fails against ransomware
Disaster recovery planning in IT developed over decades in response to physical failures, like hardware that breaks, data centers that flood, power that fails. The assumptions embedded in those plans include clean backups that can be restored from an unaffected location, a known timeline for getting systems back up, and staff who are experienced in the recovery process because they have drilled it repeatedly.
Ransomware attacks violate several of those assumptions at once. Modern ransomware groups spend time inside networks before deploying encryption. Microsoft Threat Intelligence analysis of The Gentlemen ransomware documented how the malware specifically targets backup software and services, terminating Veeam, Acronis, and other enterprise backup agents before encryption begins. The Verizon 2026 Data Breach Investigations Report found that three out of four ransomware victims had a prior credential leak, often within 95 days of the attack, with infostealers providing the validated credentials that gave attackers the access they needed to reach backup infrastructure.
The distinction matters because an organization that has invested in backup systems is not protected against ransomware if those backup systems share authentication with the production environment and the attacker obtained domain administrator credentials weeks before triggering encryption. After an attack, forensic teams must determine not just which systems were encrypted but which backups are clean, which restore points contain the attacker's foothold, and whether the recovery environment itself can be trusted. That process takes considerably longer than restoring from a geographically dispersed backup in the ordinary IT disaster scenario.
Read also: FAQs: All things malware
What the Cyber Resilience Readiness program addresses
In May 2026, the American Hospital Association and the Joint Commission launched the Cyber Resilience Readiness program, a voluntary certification initiative specifically designed to help hospitals assess their ability to maintain clinical operations during extended cyber-related technology outages. The program's framing is deliberately patient-centered rather than IT-centered. It measures whether organizations can sustain clinical care for 30 days or longer during a major cyber incident, not just whether they can restore systems within a target recovery time objective.
The 30-day benchmark is not arbitrary. It proves how long recovery actually takes in severe incidents, particularly those where forensic analysis must precede restoration to ensure that compromised restore points are not used to rebuild systems that reintroduce the attacker's access. Organizations that plan for 48-hour recoveries and find themselves managing week-long or multi-week outages discover that the gap between plan and reality produces exactly the patient safety risks, financial losses, and reputational damage that a faster recovery was supposed to avoid.
The program assesses capabilities including coordinated clinical and operational response during downtime, staff preparedness to work together during a significant cyber incident, and whether recovery plans identify clinical applications in priority order based on patient impact. Identity and directory services need to come back first, before any clinical application, because without trusted authentication the rest of the recovery cannot proceed. Internal communications infrastructure needs to be functional to coordinate the process. Clinical applications can then be restored sequentially based on patient care priority, rather than IT convenience.
The distinction between automated recovery drills and consultant-led tabletop exercises is central to the program's approach. Tabletop exercises reveal planning gaps and build shared understanding, but they do not prove that the recovery process works under real operational conditions. Repeated automated drills inside an isolated recovery environment, where staff actually execute the recovery process against real infrastructure under time pressure, are the only way to produce confidence that is grounded in evidence rather than planning.
How organization culture can get in the way
Healthcare board members and senior leaders often understand ransomware as an IT problem rather than a patient safety problem, and that framing shapes the resources and attention that resilience planning receives. When cybersecurity competes for budget against clinical equipment, staffing, and direct care infrastructure, the argument that resilience investment pays for itself through avoided harm is harder to make in real time than in retrospect.
A JAMA Health Forum analysis of the Change Healthcare attack noted that facilities without sufficient cash reserves to manage the disruption to claims processing may be forced to close permanently, a direct connection between cyber resilience and organizational survival that extends well beyond the IT team's sphere of concern. The same analysis found that the attack incurred $2.4 billion in response costs, a figure that no single-organization recovery plan had been sized to address.
According to Paubox's 2026 Healthcare Email Security Report, 41% of breached healthcare organizations in 2025 were classified as high risk based on their email configuration alone, up from 31% in 2024. The organizations still getting breached are the ones with the most foundational ground to cover, and most of them are not organizations that have received insufficient warning. They are organizations where the warning did not translate into resource allocation, and where the gap between acknowledged risk and completed remediation has been sustained by competing priorities.
Where prevention and resilience connect
Resilience planning addresses what happens after a ransomware attack succeeds. Prevention addresses whether the attack succeeds in the first place, and the two are more connected than most organizations treat them.
Phishing remains the most consistently documented initial access vector across healthcare ransomware incidents. Paubox's 2025 Healthcare Email Security Report puts the employee reporting rate at just 5% of known phishing attacks in healthcare, which means the email that gives an attacker their first foothold is going undetected by staff in the overwhelming majority of cases. The 30-day recovery that the Cyber Resilience Readiness program is designed to sustain, the forensic analysis that must precede safe restoration, and the clinical harm that accumulates during downtime all trace back to an initial access event that, in most healthcare ransomware cases, arrived through an inbox.
Pre-delivery filtering that removes phishing attempts before clinical and administrative staff encounter them addresses the attack chain at its earliest point. According to Paubox's 2026 Healthcare Email Security Report, attacks avoiding native email defenses rose 47% in 2025, which says default filtering in Microsoft 365 and Google Workspace is not catching what it needs to catch. Paubox Inbound Email Security uses AI to analyze sender behavior, message intent, and contextual signals across every inbound message, stopping the phishing attempts that bypass signature-based systems before they reach clinical staff who are working under the time pressure that makes consistent security decision-making difficult.
The organizations that will spend 30 days restoring systems, managing patient diversions, and navigating OCR investigations are largely the ones whose prevention infrastructure failed at the entry point. Cyber resilience planning matters enormously, and the AHA and Joint Commission are right to make it a formal organizational priority. The organizations that need it least are the ones that did not let the attacker in.
Learn more: Paubox Inbound Email Security
FAQs
Why does traditional disaster recovery planning fail against ransomware in healthcare?
Traditional disaster recovery plans assume that backup systems in a geographically separate location will be clean and available. Ransomware attackers spend time inside networks before deploying encryption, often targeting backup infrastructure specifically to eliminate clean restore points. When an attacker has domain administrator access, backup systems that share authentication with production may be compromised alongside the production environment, leaving no trusted recovery baseline.
What is the Cyber Resilience Readiness program and what does it measure?
The Cyber Resilience Readiness program is a voluntary certification from the AHA and the Joint Commission that assesses whether healthcare organizations can maintain safe patient care during extended cyber-related technology outages lasting 30 days or longer. It focuses on clinical continuity rather than IT recovery metrics, measuring whether organizations have coordinated clinical and operational response plans, staff who are prepared to execute those plans under real conditions, and recovery priorities sequenced by patient impact rather than technical convenience.
Why does the mortality data matter for how healthcare organizations approach cybersecurity investment?
The American Economic Association study finding that in-hospital mortality rises 34% to 38% during the initial phase of a ransomware attack connects cybersecurity investment directly to patient safety rather than data protection. Organizations that frame ransomware as an IT problem competing for budget against clinical equipment are making the resource allocation decision on an incomplete picture of the harm. Mortality data makes the case that cyber resilience is a clinical capability, not an IT one.
What is an isolated recovery environment and why is it important?
An isolated recovery environment is a clean infrastructure environment, separate from the production network and not sharing authentication with it, where organizations can restore operations after an attack without the risk that the recovery environment itself was compromised. The goal is to have a minimally viable working hospital operating from the isolated environment while forensic analysis of the production environment continues. Without one, recovery depends on determining which restore points are clean while attempting to restore clinical operations simultaneously.
What is the connection between email security and ransomware resilience planning?
Ransomware resilience planning addresses what happens after an attack succeeds. Email security addresses whether the attack succeeds in the first place, since phishing is the most documented initial access vector across healthcare ransomware incidents. The 30-day recovery capability that resilience planning is designed to sustain traces back in most cases to an initial access event that arrived through an inbox. Organizations with strong pre-delivery email filtering that removes phishing before staff encounter it are less likely to need their resilience plans in the first place.
