Desk live·
ForensicPost
Breaches/Analysis/File 25-0715

One Hospital in Three Says It Affected Patient Care

Benchmark findings have one in three hospitals confirming that cyber incidents directly impacted patient care. That is the measurement this database has been missing.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetUS hospitals
ActorMultiple
D. Kennedy & S. Rosler12 min readConfidence: medium2 sources reviewed

Benchmark research reports that one in three hospitals confirm cyber incidents have directly impacted patient care.

Almost everything else in this database measures data. This measures harm, and it is the number this desk has repeatedly noted nobody publishes.

The Files Support It

Chemotherapy infusions cancelled at Brockton in 26-0407. Appointments cancelled and a laboratory closed at Frederick Health in 25-0127. Six hundred applications withdrawn at Kettering in 25-0520. Ambulances diverted. Finals cancelled, in a different sector, at 26-0516.

Individually each is an anecdote. A third of hospitals reporting the same category converts them into a rate.

What "Directly Impacted" Is Doing

It is worth being careful. Self-reported impact is a judgement by the affected organisation, and "impacted care" spans a rescheduled appointment and a delayed emergency intervention — outcomes separated by orders of magnitude in seriousness.

The figure establishes that care disruption is common. It does not establish that patient harm is common, and reporting that conflates the two would be exactly the error this desk criticises elsewhere.

Why It Still Changes The Argument

Every funding case in this sector has had to be made on regulatory penalty and reputational risk, because those were the quantifiable consequences. Care impact was assumed, asserted, and unmeasured.

A rate — even a rough, self-reported one — moves the conversation from data protection to clinical risk management, which is a category hospitals already know how to fund. That is a more useful lever than anything in the breach statistics.

How we reported this

This is an analysis file built on published benchmark research, listed below, read against incidents in this database. The finding is self-reported by participating institutions; we do not treat it as a measure of patient harm. Corrections: corrections@forensicpost.com.

Sources
  1. One in three hospitals confirm cyber incidents directly impacted patient careCensinet
  2. Hospitals under attack: ransomware in healthcare in 2025CyberGlobal
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary