Benchmark research reports that one in three hospitals confirm cyber incidents have directly impacted patient care.
Almost everything else in this database measures data. This measures harm, and it is the number this desk has repeatedly noted nobody publishes.
The Files Support It
Chemotherapy infusions cancelled at Brockton in 26-0407. Appointments cancelled and a laboratory closed at Frederick Health in 25-0127. Six hundred applications withdrawn at Kettering in 25-0520. Ambulances diverted. Finals cancelled, in a different sector, at 26-0516.
Individually each is an anecdote. A third of hospitals reporting the same category converts them into a rate.
What "Directly Impacted" Is Doing
It is worth being careful. Self-reported impact is a judgement by the affected organisation, and "impacted care" spans a rescheduled appointment and a delayed emergency intervention — outcomes separated by orders of magnitude in seriousness.
The figure establishes that care disruption is common. It does not establish that patient harm is common, and reporting that conflates the two would be exactly the error this desk criticises elsewhere.
Why It Still Changes The Argument
Every funding case in this sector has had to be made on regulatory penalty and reputational risk, because those were the quantifiable consequences. Care impact was assumed, asserted, and unmeasured.
A rate — even a rough, self-reported one — moves the conversation from data protection to clinical risk management, which is a category hospitals already know how to fund. That is a more useful lever than anything in the breach statistics.
This is an analysis file built on published benchmark research, listed below, read against incidents in this database. The finding is self-reported by participating institutions; we do not treat it as a measure of patient harm. Corrections: corrections@forensicpost.com.