TL;DR
Get everyday helpers delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
A physician writing in MedPage Today describes a hospital that spent three weeks using paper records during a malware attack, then argues that hospitals need stronger federal support to manage future incidents. The commentary calls for required clinical continuity plans, federal funding and assistance with ransom negotiations; these are proposals, not newly announced government measures.
A physician writing in MedPage Today argues that federal agencies should help hospitals prepare for and respond to ransomware attacks, after describing a facility that relied on paper charts for three weeks while its electronic record system was down. The proposal is an argument in an opinion piece, not a government policy announcement; it raises questions about who should coordinate responses when cyberattacks disrupt patient care.
The physician said the hospital’s electronic health record system had returned by the time of a weekend shift, but recovery was incomplete: only one in four computers was working, access to information from the attack was limited, and the imaging system remained unavailable. A doctor directed the writer to radiology to view images in person. The account does not identify the hospital or give a date for the attack.
The commentary describes how ransomware can affect more than medical records, potentially disrupting phones, email and building access. It says criminals may demand payment both to restore encrypted data and to prevent release of stolen health information. The writer portrays the resulting decisions as urgent because staff may need patient records and working communications to respond to emergencies.
As evidence of possible harm, the article cites a study of Medicare claims data that found a 34% to 38% relative increase in mortality among patients already admitted to a hospital during an attack. The source does not provide the study’s title, publication date or details about the comparison group in the supplied material. It also says emergency department diversions and canceled surgeries can shift pressure onto nearby hospitals.
Patient Care During System Outages
Cyber incidents can affect whether clinicians can access records, coordinate emergencies and provide time-sensitive care. The commentary’s central concern is that a hospital’s recovery plan must account for clinical continuity, not only restoring networks or protecting stored information.
The author argues that hospitals carry much of the responsibility for their own defenses even though regulators designate them as critical infrastructure. A federal role in setting standards, funding improvements and coordinating incident response could, in the author’s view, reduce differences in preparedness across health systems. Those steps remain recommendations in the commentary; the source does not report that federal assistance with negotiations has been adopted.
Rules and Proposals for Hospital Security
The commentary says HIPAA requires covered hospitals to use “reasonable and appropriate” safeguards to protect the confidentiality and availability of protected health information, but does not prescribe particular technologies. HHS’s Healthcare Cybersecurity Performance Goals offer more specific recommendations, including offline backups, multifactor authentication and incident response planning. The article characterizes those goals as voluntary.
A proposed HIPAA security overhaul put forward in December 2024 would make some recommended measures part of updated rules, according to the source. The proposal has faced industry opposition over costs that the commentary says are projected to exceed $20 billion in its first three years. Final action is targeted for July 2027, the article says.
The author also points to reporting requirements and gaps. Hospitals must notify affected patients and HHS when protected health information is exposed; breaches involving more than 500 people also require notification to the media, according to the commentary. It says law enforcement involvement is currently voluntary. The Cyber Incident Reporting for Critical Infrastructure Act of 2022 would require reporting cyber incidents to CISA within 72 hours and ransom payments within 24 hours, but the article says the law had not been implemented at the time of writing.
““You have to pull up the images here, like the old days,””
— The physician and MedPage Today commentary author
The source does not identify the hospital, date of the attack or the attacker, and it does not say whether a ransom was demanded or paid in the incident described. It also does not provide the underlying Medicare study’s full citation, so readers cannot assess its methods from the supplied account alone.
The timing and final content of the proposed HIPAA overhaul remain unsettled in the article’s account, as does implementation of the 2022 incident reporting law. The commentary advocates federal participation in ransom negotiations, but it gives no proposed agency, legal framework or operational details for such a system.
HIPAA Rulemaking and Reporting Deadlines
The next policy milestone identified by the commentary is the targeted July 2027 final action on the HIPAA security overhaul. The article also points to implementation of the Cyber Incident Reporting for Critical Infrastructure Act as a pending step, without giving a revised start date.
For hospitals, the author urges adoption of plans that keep essential clinical work functioning during outages, backed by clear standards and federal subsidies. Whether regulators or lawmakers take up those proposals, and whether federal agencies assume a role in ransom negotiations, remains open.
Key Questions
What happened at the hospital described?
The physician says the hospital used paper charts and written orders for three weeks during a malware attack. After its electronic record system returned, only one in four computers was working and its imaging system was still down.
Is the government taking over hospital cyberattack response?
No such change is reported. The MedPage Today article is a physician’s commentary advocating greater federal involvement, including support with preparedness and ransom negotiations.
What does the commentary say hospitals are required to do?
It says HIPAA requires covered hospitals to use “reasonable and appropriate” safeguards to protect health information. The article says HHS cybersecurity goals offer more detailed recommendations but are voluntary.
When could the proposed HIPAA security changes be finalized?
The source says final action on the proposal is targeted for July 2027. It does not establish that the proposal will be finalized by that date or specify its eventual requirements.
Source: rss
Fall Picks
fall essentials
As an affiliate, we earn on qualifying purchases.
