“Building secure devices and leaving them alone is outdated,” warn experts behind a new, integrated cybersecurity approach. “We need real-time oversight and continuous interaction across systems to monitor and manage threats”
Author: Diego Giuliani
Data visualization: Lorenzo Cannella, Giacomo Destro, Daniele Di Fini
On the night between 9 and 10 September 2020, a critically ill patient was rushed to the emergency department of Düsseldorf University Hospital. But the facility could not receive her: emails and operational systems were down, patient information was inaccessible, and emergency admissions were suspended. The 78-year-old woman was redirected to a hospital in Wuppertal: only an hour’s detour, that yet proved fatal. The cause was a ransomware attack, a type of cyber-attack “where threat actors take control of a target’s assets and demand a ransom in exchange for the return of the asset’s availability and confidentiality.” The definition comes from ENISA, the European Union Agency for Cybersecurity. “There are multiple risks,” confirms Maria Papaphilippou, a cybersecurity officer at their Resilience of critical sectors unit. “Hospitals can no longer access digital records, appointments may be postponed, surgeries canceled. And at the individual level, patients may lose access to their medical data, be unable to receive the care they need, or they may be sent to other hospitals.”
Reported healthcare cyber-incidents (2019–2024):
The Düsseldorf case is far from isolated. Out of 215 publicly reported cyber incidents targeting the health sector between January 2021 and March 2023, ENISA recorded 53% against healthcare providers and 42% specifically against hospitals. Between 2023 and 2024, over one in five ransomware attacks targeted healthcare organisations, an 18% increase from the previous year. The reason why may surprise. When placed in a broader context, healthcare is not the most frequently targeted sector. At just 6.3% of total global cyberattacks, it ranks well behind industries like finance, which alone accounts for 25%. But no other sector pays a higher price when hit. With the median cost of a major incident estimated €300,000 for the target of the attack, the same successful cyberattack can earn cybercriminals, on average, nearly $11 million—almost twice as much as in the financial sector. This is partly because of the life-critical nature of services affected, but also due to the unique value of the data involved. A single electronic health record can sell for over $1,000 on the dark web. By comparison, stolen credit card details are often sold for less than $3. Health data is complete, sensitive, and difficult to change—making it extremely attractive to cybercriminals.
Economic impact of cyberattacks: healthcare vs other industries:
Stephen Gilbert, Professor of medical device regulatory science at the Dresden University of Technology (DUT), researches how to develop and effectively implement safe AI-based medical devices within health systems. “The biggest challenge is the current siloed approach to cybersecurity, where responsibility is placed on individual device manufacturers, with little systemic coordination,” he says. “When a cyber incident occurs, the standard response is often to disconnect the device or shut down the network, which is not viable for modern healthcare models, especially remote care.”
That’s why the European project CYMEDSEC, which Gilbert coordinates, is working to go beyond the current cybersecurity approach in medical devices and digital health systems by adopting a more holistic view. “A key focus is on moving beyond fragmented, device-by-device risk assessments toward a system-wide understanding of vulnerabilities, including how devices interact in practice. The strategy involves building monitoring tools, creating safer-by-design technologies, and ensuring that cybersecurity is not just a regulatory hurdle but an embedded and ongoing responsibility shared by manufacturers, hospitals, and care providers,” explains Gilbert. His project’s focus reflects the evolution health systems have undergone since the COVID-19 pandemic, and that is being further accelerated by demographic trends. “According to Eurostat, in the next 75–80 years we can expect a demographic decline in Europe, which will result not only in fewer healthcare workers in absolute terms, but also in a 10% increase in the population over 65 in the next 50 years, that is unfortunately, the age group that places the greatest demand on healthcare services” says Francesco Ricciardi, an executive engineer at the Casa Sollievo della Sofferenza Foundation in the southern Italian town of San Giovanni Rotondo.
How an attack works:
Besides enabling more personalised and at-home care, that’s where telemonitoring and telemedicine can help increase efficiency and at least partially compensate for the shortage of human resources. But as healthcare becomes more digital, it also expands the so-called “attack surface”, the number of entry points hackers can exploit. How do these attacks actually work? There are several methods. The most common include hijacking, where attackers take control of systems, sometimes exploiting them directly (“without misuse”); disruption, which interferes with normal hospital operations, delaying treatments and services; data theft, where sensitive medical records are stolen and often sold illegally; ransomware, which locks systems until a ransom is paid; and data theft combined with doxing, where stolen information is publicly exposed to cause harm. Often, a single attack combines different methods.
Types of attack against health systems:
We often don’t realize these attacks are happening—unless they disrupt essential services. Nevertheless, once the cyberattack starts, it can go on for hours or days, silently impacting systems and delaying critical care.
How long healthcare cyberattacks last:
“Data breaches and leaks are among the top risks in remote care, which relies on continuous connectivity between patients and providers. Sensitive medical information is exchanged, and if even one party isn’t in a secure environment, it puts both sides—and the data—at risk,” explains Papaphilippou. “Yet, one of the biggest issues is that patients and healthcare workers may not be fully aware of these risks or have the resources to address them.” The “hospital at home” model introduces a new set of cybersecurity challenges, stresses Gilbert, because it moves clinical care beyond the hospital’s controlled environment. “Patients are monitored and treated via connected devices, often using home Wi-Fi or personal mobile phones as communication hubs. This creates vulnerabilities due to weaker network security, inconsistent device management, and shared usage of consumer devices for non-medical purposes.”
Hospitals should be viewed as interconnected ecosystems where cybersecurity must be addressed across infrastructure, software, systems, and devices, ENISA warned in its 2020 report “Procurement Guidelines for Cybersecurity in Hospitals”. Yet, they pointed out that some of the most critical threats often come from procurements where the IT department isn’t typically involved. To tackle these challenges, CYMEDSEC is testing its approach in two pilot hospitals coordinated by Ricciardi: the Hospital do Espírito Santo in Évora, Portugal, and the Casa Sollievo della Sofferenza, where he works. “Here in Italy, we will be mainly testing devices for the telemonitoring of patients with diabetes, such as glucometers and blood pressure monitors. From a cybersecurity perspective, we will examine their entire lifecycle from the procurement phase, including the definition of security requirements, through to their integration with existing systems, use in clinical practice, and eventual decommissioning,” he explains.
Where they happen
It is not by chance that a pilot site of the CYMEDSEC project is located in Italy. Within Europe, Germany, France, and Italy have seen the highest number of incidents—likely a reflection of the scale of their healthcare systems, but also of their strategic importance. Analysis of attack origins shows that many can be traced to Russia and China, where well-resourced groups operate either for financial gain, geopolitical advantage, or both.
Geography of reported healthcare incidents in Europe:
Highlighting the need to move past a siloed approach is also the fact that clinical information systems are usually made up of components from different suppliers. These interact and share data, meaning that the vulnerability of one piece can compromise the whole system. “A particularly important area is supply chain cybersecurity,” points out Gilbert. “People often assume that the hardware components such as chips and sensors are inherently safe. But that’s a dangerous assumption. If we don’t know exactly what’s in our hardware, it becomes nearly impossible to guarantee system security. This is why we’re also exploring eSIM-like approaches embedded directly in hardware, offering a new layer of traceability and protection. These kinds of innovations are becoming increasingly critical.” One of the key recommendations of the “European action plan for cybersecurity in hospitals and healthcare providers”, released in January, is to conduct risk assessments on medical devices. “It’s a critical area that remains largely uncharted,” admits Papaphilippou. “There is a wide variety of devices, each with its own vulnerabilities and suppliers, making this a complex but necessary task.”
Weak attack, great damages
A lack of awareness is a vulnerability in itself, she stresses, because “if we’re not conscious of the threats, we won’t invest in reducing the risks.” Along with the urgent need for investment, informing patients, healthcare professionals, and all users of telemedicine apps and devices is currently one of the major challenges, confirms Ricciardi. “Many people may feel that it doesn’t concern them, but from now on cybersecurity is just as essential as road or workplace safety. It is everyone’s responsibility, and we could all start to play our share simply by not choosing weak passwords or skipping two-factor authentications,” he warns.
Again, the point is the public awareness of the issue. To understand the impact of these attacks, an intensity scoring system has been introduced, ranging from 1 (low impact) to 15 (maximum impact). This score, developed by EuRepoc, evaluates the duration of the incident and its effects, along with the scope and type of targets involved.
Intensity of incidents (EuRepoc scale 1–15): distribution and typical severity:
At first glance, the data may seem counterintuitive: although cyberattacks are increasingly frequent and financially profitable, most fall into the medium-intensity range. In reality, cyberattacks in the healthcare sector tend to be of moderate intensity because attackers prioritize financial gain over immediate disruption. They often exploit outdated and fragmented IT infrastructures, which are easier to breach without sophisticated techniques. Furthermore, many healthcare organizations operate with limited cybersecurity resources, making them easy targets for attacks that are impactful yet not highly complex or destructive.
This gap in resources and preparedness highlights the urgent need for stronger governance frameworks, as highlighted by Gilbert, adding that “Regulation plays a central role, but we need to fundamentally rethink how it works in the context of modern, connected healthcare delivery,” he exhorts. “The traditional ‘fire-and-forget’ model of building secure devices and leaving them alone is outdated. Instead, we need real-time oversight and continuous interaction across systems to monitor and manage risks. This shift demands a strategic commitment to building integrated partnerships and enabling systemic, real-time coordination, with particular emphasis on contextual security, ensuring that devices are assessed not in isolation, but within the realities of their operational environments,” concludes Gilbert.