In the past month alone, foreign hackers disrupted care at hospitals, stole millions of health-care records, and attacked water systems in the United States, reminding Americans of how vulnerable critical systems can be to cross-border cyberattacks.
Today, U.S. health-care delivery is highly dependent on the availability of internal network and internet-connected technology, devices, and data. The use of advanced technologies in health care, such as for electronic medical records and three-dimensiona; imaging, has no doubt saved countless lives, but it has also created new risks for providers and patients.
Many providers depend on technology for delivering care, such as for creating admission records, using tools to aid in making diagnoses, or performing complex surgeries. Yet when these technologies become suddenly unavailable during a cyberattack, it can create logistical nightmares at minimum, and, in the direst situations, life-threatening care delays for patients.
Foreign adversaries of the United States recognize and mercilessly exploit the vulnerabilities in these technologies, raising fears of "digital darkness," a worst-case scenario when hospital computer screens go dark and health-care delivery is disrupted. Daily, foreign cyber gangs who are directly or indirectly supported by nation-states such as China, Iran, North Korea, and Russia target U.S. health-care organizations and mission-critical third parties with data theft, data extortion, and ransomware attacks, in which cyber attackers demand payment for stolen data.
In 2025, the FBI reported that the health-care sector suffered more ransomware attacks [PDF] than any other critical infrastructure sector: there were 460 reported attacks, compared to 355 attacks against the next most attacked sector, critical manufacturing. The situation is only getting worse as nation-states and criminal hackers begin to use artificial intelligence (AI) to quickly identify software vulnerabilities and to rapidly develop and deploy malware to exploit weaknesses. Cyberattacks on health care have become so popular that HBO's hit show The Pitt made it a centerpiece of their plot in season two.
Ransomware attacks against health care have become a preferred battleground in global cyber warfare because they have the potential to create significant risks for both patient and community safety. When hospitals and health systems are attacked, clinicians don't just lose access to their computers—ambulances carrying stroke, heart attack, and trauma patients may have to be diverted to other hospitals farther away, delaying potentially lifesaving treatment.
These attacks also create a regional cascading effect, creating a strain on hospitals that were not targeted as they take on increased numbers of patients. This regional and clinical impact is what I call the ransomware blast radius, and it is one of the primary reasons that health care has become such a high-value target. In addition, time-sensitive oncology treatments, diagnoses, lab reports, and surgeries can also be delayed. These effects place enormous pressure on the victim organizations to pay the ransom.
Cyberattacks on Health Care as a Political and Intelligence Tool
Cyberattacks not only provide illicit profits for these ransomware gangs; they also serve the interests of noncooperative foreign jurisdictions like China, Iran, North Korea, and Russia that, at a minimum, provide safe harbor for ransomware gangs to launch their attacks against the West. Ransomware attacks against health-care institutions led by these countries not only impact care delivery; they also achieve a separate goal of simultaneously diverting limited federal law enforcement and intelligence resources as they aid victims and investigate the perpetrators.
There are several drivers for nations to support these hackers. One is that cybercriminals are pursuing not only data but also immediate and future disruption that can be used in times of potential future conflict, making cyberattacks on health-care institutions more attractive. Furthermore, these adversarial nation-states may use ransomware groups as proxies to further their own national security, military, intelligence, and economic interests.
For example, China could steal highly sensitive U.S. taxpayer–funded medical research data for their own scientific and economic advantage. Spy agencies from these nations could also use the stolen health data of millions of Americans [PDF] for intelligence exploitation, meaning they could store, analyze, and actively leverage the health data of Americans who have security clearances, along with the health information of policymakers, business leaders, and people of influence seeking opportunities for access and compromise. For example, the 2015 Anthem health-care insurance breach in combination with the Office of Personnel Management breach provided suspected Chinese government–affiliated hackers the ability to identify government employees who have security clearances and match them with their stolen health-care records.
Cyberattacks in Recent Years
Since 2020, the Department of Health and Human Resources Office of Civil Rights has reported that more than more than 700 million health-care records have been affected by hacking incidents. This is an astonishing number, especially considering that the U.S. population is only about 330 million. To put this in perspective, statistically speaking, every American has had their health-care records stolen, in part or full, at least once, and many have had their records hacked multiple times.
In March 2026, the cyberattack on U.S. health-care technology provider and medical device manufacturer Stryker by an Iranian intelligence–backed hacking group known as Handala reinforced what many in national security have known for some time now—nation-states are using U.S. health care as a high-value target for cyber operations. The Stryker cyberattack demonstrated the potential for Iran and its cyber actors to cause disruption to U.S. health care. Thankfully, the disruption did not extend to Stryker's surgical robots, surgical implants, or medical supply chain, so the impact to patient care was minimal. However, this incident had the potential to have severe global consequences should it have succeeded in causing the intended care delays.
The disruption to care delivery is also not limited to direct attacks on hospitals themselves but also to when mission critical third-party providers are targeted. In February 2024, Change Healthcare, a subsidiary of UnitedHealth Group, was the victim of a ransomware attack by the Russian ransomware gang known as BlackCat or ALPHV. Change Healthcare, which processes 15 billion health-care transactions annually and touches 1 in every 3 patient records, would become the epicenter of the most consequential cyberattack on the U.S. health-care system in history, causing significant disruption to patient care and hospital finances lasting months. In this attack alone, the health-care records of more than 192 million Americans were stolen. There are countless other examples of such third-party targeting.
Previously, the Russian government was accused of globally propagating the destructive malware known as NotPetya, which significantly affected U.S. health care. North Korea routinely uses their own ransomware groups to raise money for their regime priorities, including potentially their nuclear weapons program. In 2024, a North Korean government hacker was charged with conducting ransomware attacks against U.S. hospitals.
"Rim Jong Hyok and his co-conspirators deployed ransomware to extort U.S. hospitals and health care companies, then laundered the proceeds to help fund North Korea's illicit activities," said Deputy Director Paul Abbate of the FBI in a press release announcing Hyok's indictment. "These unacceptable and unlawful actions placed innocent lives at risk," he continued.
How Does the United States Respond?
Hospital efforts alone are not enough to defend against nation-state-level cyberattacks. Cyber risk to the health-care sector is now directly influenced by geopolitical tensions. As such, the effort to protect hospitals and patients should include involving law enforcement and legislative, military, and intelligence assets in their defense and for the federal government and allied nations to defend forward—to conduct sequenced and sustained offensive cyber operations to degrade cyber adversaries' capability to conduct these attacks and provide appropriate consequences.
The FBI's current aggressive offensive cyber campaign, known as Operation Riptide, is an excellent example of this concept, as it has resulted in the dismantling of certain hackers' technical infrastructure, seizure of illicit proceeds, and a number of hacker arrests and extradition to the United States.
However, despite these efforts, one of the challenges for holding perpetrators responsible is that the laws that are typically used to prosecute cybercrimes are not commensurate with the level of harm that cyberattacks on hospitals can cause. For example, the Computer Fraud and Abuse Act, passed in 1986, is used to prosecute hacking activity and other crimes related to computers. It carries a maximum sentence of 20 years in prison but, due to sentencing guidelines, often results in prison time that is far less. This is not enough of a deterrent for an international ransomware criminal who has a low probability of apprehension and a high probability of reaping millions of dollars in illegal profits.
The U.S. response to cyberattacks against health-care infrastructure should use existing statutes to deliver comparable consequences. For example, the authorities provided under U.S. Code Titles 10, 31, and 50 should all be used in a more sustainable way to provide more effective and robust options to deter and disrupt foreign-based adversaries that attack U.S. hospitals and health systems.
Title 31 allows the Treasury Department, through the Office of Foreign Asset Control (OFAC), to impose financial sanctions on foreign entities that have conducted or facilitated cyberattacks against U.S. organizations. OFAC sanctions also make it a crime for any other entity or person to conduct business with an OFAC-designated entity.
Titles 10 (military authorities) [PDF] and 50 (intelligence authorities) can improve domestic cyber defenses by putting the United States on the offensive. They could be invoked to take an active or forward defensive posture to proactively disable and disrupt foreign-based cyber threats. The vast resources, knowledge, and capabilities of the U.S. Cyber Command, National Security Agency (NSA), CIA, and the rest of the intelligence community could be used to augment and support law enforcement actions.
Leveraging the entire law enforcement, intelligence, and military capabilities of the U.S. government is necessary to achieve swift and certain consequences against these attackers.
Prepare for Clinical Continuity and Increase Operational Collaboration
Hospital leaders can also take a more direct role in strengthening the sector's cyber defenses and "bracing for impact" by developing hospital and regional clinical-continuity plans to provide high-quality care during an extended technology outage. The question is not whether a cyberattack will occur; it is how well prepared an organization is when the cyberattack does occur.
Operational collaboration and sharing of information, expertise, and resources between the private sector and federal government has increased over the last several years. But to keep pace with the perpetrators in the age of AI, government and private sector alike should greatly expand and accelerate that collaboration to improve cybersecurity for all. To defend against foreign cyber threats is a whole-of-nation imperative and a societal obligation in which everyone should participate.
In the realm of cyber defense, there is no competitive advantage between organizations, especially in health care. Everyone faces the same threats and the same potential consequences, providing the same incentive to exchange threat information freely. Doing so not only helps protect organizations and patients—it helps protect the United States. A phrase I used while in the FBI applies now more than ever, "to defend one is to defend all."













