Hospitals Warned To Prepare For Weeks-Long Tech Outages As AI Cyberattacks Intensify

corporate lawyer attorney US legal bankruptcy contract case

Healthcare cybersecurity experts have issued a stark warning to hospital leaders: traditional disaster-recovery planning is no longer sufficient to protect patients and systems.

Speaking at a healthcare summit hosted by data management and cybersecurity firm Rubrik, based in Palo Alto, California, industry leaders stressed the urgency of preparing for prolonged technology outages lasting 30 days or more.

The summit brought together senior voices in healthcare cybersecurity to address what they described as an escalating and increasingly sophisticated threat landscape targeting hospitals and health systems.

Experts warned throughout the event that AI-driven cyberattacks represent an entirely new level of risk, with the potential to disrupt clinical operations for weeks and leave patients waiting for critical care.

John Riggi, national adviser for cybersecurity and risk at the American Hospital Association, described cyberattacks on healthcare organisations as a “threat to life,” warning of their capacity to derail every step of the healthcare delivery workflow.

“When technology fails due to some design failure because it wasn’t designed securely, but which the bad guys have exploited or found today at machine speed — when those systems go down, there is an immediate disruption and delay to healthcare delivery,” Riggi warned.

Nicole Perlroth, bestselling author and host of the To Catch a Thief podcast, also addressed the summit, sharing her concerns about the growing danger posed by AI-powered cyberattacks on critical healthcare infrastructure.

The timing of the summit coincides with renewed legislative pressure, as senators recently reintroduced the Health Infrastructure Security and Accountability Act, which would impose baseline minimum cybersecurity requirements on healthcare organisations and allocate $1.3 billion to help hospitals strengthen their defences.

The urgency of that legislation was underscored in August, when a cyberattack on Boston Scientific disrupted manufacturing and supply chains, illustrating how a single breach can send shockwaves across broader healthcare operations.

Speakers at the summit recommended that hospitals regularly test downtime and continuity plans, strengthen backup systems, and ensure they can function entirely without IT infrastructure for extended periods.

Despite the grim assessment of the current threat environment, some experts expressed cautious optimism that mounting pressure could finally force long-overdue reforms in how healthcare technology is designed and secured.

“Long term, I hope that we basically get to a place we’ve never been before,” Perlroth said. “That this forces us to do the things we have talked about to death over the past few years in terms of secure-by-design, formal methods, patching, backups, real time backups, backup intelligence, et cetera.”

The message from the summit was clear: as healthcare organisations grow more dependent on network-connected technology, the cost of complacency in cybersecurity planning could ultimately be measured in human lives.