03 FEB 2026

IS HEALTHCARE FACING A CYBERSECURITY CRISIS? A CALL FOR URGENT ACTION ARE WE HEADING TOWARDS A CYBERSECURITY CRISIS IN HEALTH CARE?

Healthcare is increasingly targeted by cyberattacks, putting patient safety, essential services, and health systems at risk. A recent article on The Lancet by researchers from the Technical University of Dresden—coordinators of the CYMEDSEC project - warns of a looming cybersecurity crisis and calls for urgent, coordinated action across policy, organisational, and technical domains.

Over the past decade, healthcare has become one of the most targeted sectors for cyberattacks. From the 2017 WannaCry ransomware attack that disrupted the UK’s National Health Service to recent large-scale breaches affecting millions of patients in Europe and the United States, cyber incidents have increasingly compromised patient safety, disrupted essential services, and caused significant financial losses.

A new article, entitled “Are we heading towards a cybersecurity crisis in health care and are actions needed?” and published on the prestigious journal Lancet, examines the rapid escalation of cyber threats affecting hospitals, medical infrastructure, and health-care supply chains, calling for urgent and coordinated action at policy, organisational, and technical levels.

Authored by Oscar Freyer, Stephen Gilbert,  and Max Ostermann, from Dresden University of Technology – also coordinators of the CYMEDSEC project – together with Kunal Rajput, and Saira Ghafur from Imperial College, the article highlights how rapid digitalisation including the adoption of artificial intelligence, hospital-at-home models, and the Internet of Medical Things  has significantly expanded the attack surface of healthcare systems. At the same time, outdated IT infrastructures, older cyber-physical systems not designed with modern cybersecurity requirements , limited resources, and a general low cybersecurity awareness continue to expose critical vulnerabilities.

Recent policy initiatives in both the United Kingdom and the European Union aim to strengthen cyber resilience, improve incident reporting, and address risks across healthcare supply chains. Within this evolving policy landscape, the CYMEDSEC project focuses on enhancing the cybersecurity and resilience of connected medical devices and in vitro diagnostics. CYMEDSEC seeks to support industry growth, improve patient safety, and enable clearer and more accessible regulatory pathways for enterprises operating in the EU medical technology sector.

However, the article on Lancet cautions that policy frameworks alone are not sufficient: without sustained investment, clear accountability, and practical support for frontline healthcare organisations, compliance risks becoming a box-ticking exercise rather than a driver of real cyber resilience.

Read the full article here!

Cover photo credit: Photo by Karolina Grabowska