By Mary C. Mayhew

Healthcare organizations are the number one target for hackers and cyberterrorists, including nation-state actors, such as Russia. These attacks often involve theft of patient data and medical research but also include high-impact ransomware attacks that shut down critical medical systems, creating barriers for patients to access the care and treatment they need, when they need it.

In 2025, there were more than 460 ransomware attacks targeting the healthcare sector, more than any other critical infrastructure sector. These attacks resulted in an average of 17 days lost to downtime and a cumulative cost of $21.9 billion over the last six years, according to the Healthcare Financial Management Association. Downtime means hospitals and other sites of care are shutdown or forced to limit available medical services.

Cyberattacks of all kinds significantly affect timely patient care. Nearly 90 percent of healthcare organizations experiencing a supply chain attack reported it disrupted patient care, according to the 2025 Ponemon Healthcare Cybersecurity Report. Patients were primarily impacted by delays in procedures and tests that resulted in poor outcomes (51 percent) and an increase in complications from medical procedures (49 percent). Nearly 70 percent of entities experiencing a ransomware attack reported negative impacts on timely patient care, with 56 percent reporting delays in procedures and tests.

Even when hospitals themselves are not the primary target of a cyberattack, as was the case with the Change Healthcare attack in 2024, access to care can be compromised. The attack against one of the country’s largest healthcare companies had significant consequences for patients and the hospitals, health systems, and other clinicians who care for them. In some communities, patients struggled to obtain essential prescriptions or experienced delays in scheduling care. Results from an American Hospital Association survey representing nearly 1,000 hospitals found that 74 percent reported direct patient care impact, including delays in authorizations for medically necessary care.

Likewise, the March cyberattack by Iranian cyberterrorists against Stryker, a global medical technology company, disrupted the global supply chain for essential medical devices and hospital equipment. With its systems offline, production lines stopped, electronic ordering systems were down, and fulfilment operations stalled. U.S. hospitals reported being unable to order surgical supplies, and hospitals in the United Kingdom were ordered to consolidate orders through the National Health Service’s supply chain platform and not order directly.

From ransomware and phishing scams to e-mail bombing and malware, the threats are significant and are so much more than an IT security issue. They represent real clinical risk to Florida’s patients.

Florida’s hospitals are taking extensive prevention and protection measures against cybercrime, while enhancing their response plans and actions with a focus on continuity of care. Identifying and prioritizing the risk to essential services, like pharmacy, medical records, laboratories, and radiology and imaging services, is mission-critical to enhance safeguards and operational continuity. Hospitals have designated response team members to develop clinical continuity procedures, tools, and resources, and to train their employees how to best function through extended downtimes.

In addition, through the Florida Hospital Association, hospitals are represented in the University of South Florida’s Center for Cybersecurity (CyberFlorida). FHA chairs the Senior Advisory Group whose members represent state agencies and partner organizations responsible for preventing, responding to, mitigating, and recovering from a cyberattack. Likewise, FHA established a Chief Information and Chief Information Security Officers Council to advise on how best to support hospital threats and cybersecurity.

This commitment is resource-intensive, but for Florida’s hospitals, the cost of not investing in that security is far greater because robust cybersecurity is no less essential for high-quality patient care than highly trained clinicians, sophisticated equipment, and the most advanced medications and treatments.

Mary Mayhew is President and CEO, Florida Hospital Association.