Over the past decade, healthcare has become one of the most targeted sectors for cyberattacks. From the 2017 WannaCry ransomware attack that disrupted the UK’s National Health Service to recent large-scale breaches affecting millions of patients in Europe and the United States, cyber incidents have increasingly compromised patient safety, disrupted essential services, and caused significant financial losses.
A new article, entitled “Are we heading towards a cybersecurity crisis in health care and are actions needed?” and published on the prestigious journal Lancet, examines the rapid escalation of cyber threats affecting hospitals, medical infrastructure, and health-care supply chains, calling for urgent and coordinated action at policy, organisational, and technical levels.
Authored by Oscar Freyer, Stephen Gilbert, and Max Ostermann, from Dresden University of Technology – also coordinators of the CYMEDSEC project – together with Kunal Rajput, and Saira Ghafur from Imperial College, the article highlights how rapid digitalisation including the adoption of artificial intelligence, hospital-at-home models, and the Internet of Medical Things has significantly expanded the attack surface of healthcare systems. At the same time, outdated IT infrastructures, older cyber-physical systems not designed with modern cybersecurity requirements , limited resources, and a general low cybersecurity awareness continue to expose critical vulnerabilities.
Recent policy initiatives in both the United Kingdom and the European Union aim to strengthen cyber resilience, improve incident reporting, and address risks across healthcare supply chains. Within this evolving policy landscape, the CYMEDSEC project focuses on enhancing the cybersecurity and resilience of connected medical devices and in vitro diagnostics. CYMEDSEC seeks to support industry growth, improve patient safety, and enable clearer and more accessible regulatory pathways for enterprises operating in the EU medical technology sector.
However, the article on Lancet cautions that policy frameworks alone are not sufficient: without sustained investment, clear accountability, and practical support for frontline healthcare organisations, compliance risks becoming a box-ticking exercise rather than a driver of real cyber resilience.
Read the full article here!
Cover photo credit: Photo by Karolina Grabowska