Close

New Research from CDW on Workplace Friction

Learn how IT leaders are working to build a frictionless enterprise.

Jul 28 2026
Security

Following a Clear Roadmap to Clinical Care Resilience

Healthcare organizations can’t prevent every breach, but they can recover.

Healthcare organizations are under pressure from every direction: more cyberattacks, shrinking operating margins, staffing shortages and complex technology environments that cannot be easily patched or replaced.

A path to cyber resilience reduces risk for healthcare by building the capabilities to recover faster when attacks happen and reducing impacts to patient care.

DISCOVER: Ensure healthcare business continuity when IT fails.

Making Recovery Readiness a Part of Patient Safety

When cyberattacks disrupt hospitals and the healthcare supply chain, the effects reach patients fast. Delayed lab results, interrupted monitoring, postponed surgeries and crowded emergency departments create risk. A UC San Diego study found that a ransomware attack on one hospital can overwhelm nearby emergency rooms, increasing wait times for hours. A 2026 study published in American Economic Journal: Economic Policy found that in-hospital mortality increased up to 38% among patients already admitted when a ransomware attack began. 

However, healthcare organizations are not without recourse. Drawing lessons from previous attacks creates a roadmap for how an organization can build cyber resilience.

Click the banner below for a cyber resilience strategy that supports success.

 

Start With the Question That Matters Most: Did the Data Survive?

Adversaries target backups because backups determine whether an organization can recover after an attack. In fact, research has shown that attackers were at least partially successful in compromising backup environments in about 74% of ransomware cases.

Every data protection vendor claims immutability. But organizations should pressure-test whether it holds against a skilled adversary with domain admin credentials already inside the network. 

Know Where To Recover Before the Crisis

Cyberattacks often don’t create physical damage. Instead, attacks destroy trust in the security context. Because production and disaster recovery sites are tightly integrated, a compromise at one site often means the DR site can’t be trusted either. For this reason, cyber recoveries can require a new construct: an isolated recovery environment. An IRE gives organizations a clean, separate place to restore critical systems, test recovery and avoid reinfecting the environment they are trying to rebuild.

Thankfully, an IRE does not require another physical site, nor does it need to host the entire hospital application fleet. What’s important is that it can support the applications supporting urgent clinical and operational functions.

READ MORE: Build clinical care resilience when your EHR goes down.

Recover What Matters First

Health system IT teams already have a clear picture of their most critical applications. 

A practical recovery sequence starts with identity, Domain Name System, Dynamic Host Configuration Protocol and other critical services without which applications will not function. Then come internal communications, which help coordinate the organization’s response. Next come clinical applications in priority order, based on how care is delivered.

The “minimum viable hospital” concept can help frame that work. By repeatedly drilling these recoveries into an IRE, the organization develops cyber resilience, assuring the ability to quickly restore care for patients.

Test the Plan Before Patients Depend on It

Orchestrated application recovery, as a tactic, lets teams run automated drills on a schedule. Weekly testing can reveal what breaks, what takes too long and what must be fixed before an attack.

That matters financially too. A five-day reduction in recovery time can save a health system tens or even hundreds of millions of dollars.

The message for organizations is clear: Start building, automating and testing now with the resources you have.

Build Clinical Continuity, Not Just IT Recovery

When a hospital goes dark, the mission must continue. Stroke patients still arrive. Labs still need results. Surgeries must go on. Clinical recovery should be planned alongside IT recovery. 

Legal, regulatory, financial, operational and clinical decisions converge in the first hours of a cyberattack. Cross-functional simulations help organizations see what a coordinated response looks like. They also expose gaps in staffing, communications, manual workflows and decision-making before those gaps affect patient care.

Click the banner below to sign up for HealthTech’s weekly newsletter.

 

Remember the People Doing the Work

A 30-day post-attack response can exhaust IT teams, clinicians and administrators. Fatigue leads to errors. Repeated attacks can push already strained workers out of the field.

Human resilience should be part of cyber resilience.

Health systems should plan staff rest rotations, division of roles during a recovery, manual workflows, extra runners, rehearsed downtime procedures and redeployment strategies in peacetime. Protecting people is part of protecting care.

Make Recovery a Shared Commitment

Building toward real risk reduction requires infrastructure, security and contingency planners to work together with a wide range of teams, including legal, finance, supply chain and operations. Security helps prevent and contain attacks. Resilience helps organizations recover when prevention is not enough.

That is the path forward: truly immutable data protection that won’t need to be rebuilt, having working IREs and orchestrated application recovery to repeatedly run regular drills that prove the plan works.

Healthcare organizations cannot prevent every breach. But they can transform how they recover, and in doing so, protect the mission every hospital exists to serve: patient care.

The views expressed in this article are those of the author and do not necessarily reflect the official policy or position of Rubrik. These views are for informational purposes only and do not constitute business or legal advice. Organizations should consult with legal and compliance professionals to ensure their cybersecurity strategies meet all applicable federal, state and international requirements.

Tempura/Getty Images