European Commission JRC Report Examines Health Consequences of Cyber Incidents in Healthcare

The European Commission Joint Research Centre, JRC, has published a report titled “Cyber security in the health and medicine sector: a study on available evidence of patient health consequences resulting from cyber incidents in healthcare settings.”

The report was published in 2024 and investigates whether cyber incidents in healthcare settings have been associated with patient health consequences.

Background

The report notes that the health and medicine sector is increasingly digitized, a trend expected to accelerate with wider adoption of artificial intelligence, wearables and Internet of Things-based healthcare.

However, this digital transformation also brings cybersecurity threats. While there is substantial evidence of cyberattacks affecting the health sector, the report highlights that information on whether these incidents cause direct health impacts remains inconsistent.

Cybersecurity Risks in Healthcare

According to the report, cyberattacks on healthcare facilities can affect not only the quality and timeliness of healthcare services, but also the health and life of patients.

The report gives examples of potential worst-case scenarios, such as an urgent operation being prevented because imaging files are inaccessible or because a robotic surgery tool is affected by a cyberattack.

The authors also highlight several reasons why the healthcare sector remains vulnerable, including lack of preparedness, insufficient cybersecurity investment, use of legacy information systems and other sector-specific cybersecurity gaps.

Difficulty Assessing Patient Health Consequences

The report emphasizes that characterising cyber incidents in healthcare and assessing effects on patient health is difficult.

Possible health effects may occur after delays, making causality hard to establish. Hospitals may also be reluctant to disclose detailed information because of reputational concerns or other conflicts of interest. In addition, the report notes that there are no agreed methodologies for characterising health cybersecurity incidents or monitoring possible causal links with adverse health effects.

Study Methodology

To address this evidence gap, the authors used the Europe Media Monitor, EMM, to retrieve media reports on cyber incidents in healthcare settings across several European languages over a one-year period.

The study focused on cyber incidents with reported potential impact on patient health, using selected keyword combinations and exclusion criteria.

The monitoring covered media reports from 1 May 2022 to 30 April 2023 and included English, German, Italian, French and Spanish. The authors note that the study did not cover all EU languages and may therefore underestimate the number of incidents.

Use of Europe Media Monitor

The report explains that EMM monitors a large set of media sources, applies categorisation and extracts metadata such as entities, quotes, sentiment and geolocation.

At the time described in the report, the publicly accessible instance of EMM monitored more than 44,000 RSS feeds and HTML pages, from almost 13,000 media websites, in more than 70 languages, processing around 300,000 news articles per day.

The authors used EMM because it can detect news on cyber incidents through keyword-based categories across multiple languages.

Search Categories and Keywords

The researchers initially created several categories focused on medical devices, cybersecurity, privacy and ransomware.

After testing, they moved to a single category named MedicalDevices-Cybersecurity-Health, designed to capture cyber incidents in healthcare with possible health impacts such as therapy disruption or delayed treatment.

The report’s figures show how keyword lists were structured and refined, including healthcare and medical device terms, cybersecurity terms, health impact terms and exclusion terms. The final category was built across English, Italian, French, German and Spanish.

Main Results

The study identified 21 cyber incidents affecting European healthcare or medicine infrastructure and facilities that could potentially impact patient health.

Based on the information retrieved, none of the selected incidents appeared to have caused direct adverse health consequences in patients, such as injury, illness or death.

The main reported impacts on healthcare services and patients were:

  • therapies postponed;

  • surgeries delayed;

  • ambulances diverted away from affected facilities;

  • limited access to emergency rooms.

Types of Incidents

The report found that hospitals were the main targets, accounting for 20 of the selected incidents, while one incident affected a distributor of medicine.

Most incidents were reported in Italy and France, although the report notes that the reasons for this distribution are difficult to determine.

The report also states that ransomware was the most frequently used type of cyberattack among the selected incidents. The chart on page 14 illustrates the distribution of incident types by country and shows ransomware as the dominant category.

Examples of Reported Impacts

The report’s incident table includes examples of disrupted healthcare services.

These include limited access to emergency rooms, lack of access to patient records, radiology exams and blood sampling, cancelled consultations, cancelled non-emergency operations, inaccessible medical imaging systems, delayed surgeries, use of pen-and-paper procedures, postponed chemotherapy and radiotherapy, and disruption to pharmacies’ online systems.

One example described in the table concerns a cyberattack affecting four hospitals in Milan, with limited emergency room access and no access to patient medical records, radiology exams or blood sampling.

Another example concerns the Hôpital André-Mignot of the Versailles hospital centre, where patient reception was limited, operations were partially deprogrammed and the hospital had still not returned to usual functioning more than two weeks after the attack.

Conclusions

The report concludes that there is a notable discrepancy in the available evidence on whether and to what extent cyberattacks affect patient health.

Using EMM and consistent search criteria, the study identified 21 incidents with potential health impacts related to deteriorated care provision, but no direct adverse consequences on patient health were reported for those incidents.

The authors also highlight that ransomware was the most frequently used attack type and that attacks to hospitals can become more than a local issue, potentially functioning as a regional disaster when patients must be redirected or relocated.

Need for Cyber Resilience

The report emphasizes the importance of cyber resilience, including preparedness, fall-back plans and mitigation measures to maintain healthcare services during cyber incidents.

The authors state that response actions and mitigation measures should be identified in advance and that there is no one-size-fits-all preparedness plan, as hospitals and departments may have different vulnerabilities, technologies and resources.

The report also notes that technical measures such as encryption and network segmentation should be complemented by non-technical measures such as awareness, training, exercises and contingency planning.

Gaps in Monitoring and Causality Assessment

The report identifies a need for better tools to describe, monitor and assess cyber incidents in the health and medicine sector.

It highlights the lack of consistent evaluation and reporting criteria and calls for tools such as cybersecurity ontologies and frameworks to assess potential causal connections between cyber incidents and adverse health effects.

Impact on Healthcare, Medical Device and Digital Health Stakeholders

For healthcare providers, medical device manufacturers, digital health companies and cybersecurity teams, the report is relevant because it links cybersecurity preparedness with patient safety and continuity of care.

Stakeholders should pay particular attention to:

  • cyber resilience planning;

  • contingency plans for clinical service disruption;

  • cybersecurity risks affecting medical devices and healthcare infrastructure;

  • ransomware preparedness;

  • legacy system vulnerabilities;

  • supply-chain and vendor access risks;

  • staff awareness and training;

  • network segmentation, encryption and MFA;

  • incident reporting and impact assessment;

  • continuity of care during ICT downtime;

  • frameworks for assessing patient health consequences.

For organisations operating in increasingly digital healthcare environments, the key message is that cybersecurity incidents may disrupt care pathways even when direct adverse patient outcomes are not immediately reported. Robust preparedness, monitoring and causality assessment frameworks are essential to protect patient safety.

Anterior
Anterior

Swiss Federal Council Announces Measures on IVD Supply and Medical Device Transparency

Próximo
Próximo

FDA Draft Guidance Explains Drug Master File Submission and Review Expectations