
Share
Cybersecurity experts warn that AI-powered attacks could knock hospital systems offline for a month or more, and traditional disaster recovery plans aren't built for that kind of sustained crisis.
Imagine a hospital's electronic health records, imaging systems, and medication orders all going dark, not for a few hours, but for 30 days straight. For patients waiting on test results or surgery schedules, that's not an inconvenience. It's a matter of life and death.
That's the scenario cybersecurity experts say hospital leaders now need to plan for. At a healthcare summit hosted last week by Rubrik, a Palo Alto-based cybersecurity and data management company, the message from speakers was consistent: the old playbook for disaster recovery, built around outages measured in hours, no longer fits the threat landscape. AI has changed the math.
The timing matters. Last month, senators reintroduced the Health Infrastructure Security and Accountability Act, legislation that would set baseline minimum cybersecurity requirements for healthcare organizations and allocate $1.3 billion to help hospitals strengthen their defenses. In August, a cyberattack on Boston Scientific disrupted manufacturing and supply chains, a reminder that these attacks don't stay contained to IT departments. They ripple outward into the physical systems that keep care moving.
Nicole Perlroth, a bestselling author and host of the To Catch a Thief podcast, laid out why AI is such a game-changer for attackers. Think of a hospital's security setup like a house with dozens of doors and windows. In the past, a burglar had to walk the perimeter, checking each one by hand. Now, AI tools can check every single entry point simultaneously, and instantly.
"What we can really expect is that any vulnerability or any misconfiguration or any human error that you have in managing your security estate will be discovered at machine speed and exploited at machine speed," Perlroth said.
That shift matters because human error is unavoidable. Every hospital network has some misconfigured server or outdated patch sitting somewhere in its system. For years, that gap might sit unnoticed for months. Now, AI-powered scanning tools can find it in minutes.
John Riggi, national adviser for cybersecurity and risk at the American Hospital Association, put the stakes in even starker terms. He called cyberattacks on healthcare organizations a "threat to life." It's not hyperbole. Riggi walked through how a single successful breach can cascade through every step of care delivery, from scheduling to diagnostics to medication dispensing, delaying treatment at each stage.
"When technology fails due to some design failure because it wasn't designed securely, but which the bad guys have exploited or found today at machine speed, when those systems go down, there is an immediate disruption and delay to healthcare delivery," Riggi warned.
That delay is where the real danger lives. A delayed lab result might mean a missed diagnosis. A locked-out pharmacy system might mean a patient doesn't get medication on time. None of these are abstract IT problems. They're clinical ones.

Part of what makes this threat so unpredictable is its source. Riggi noted that attacks can come from foreign state actors based in Russia, China, North Korea, and Iran, groups with the resources and motivation to target healthcare infrastructure specifically. But AI has also lowered the barrier to entry. Attackers who once lacked the technical sophistication to breach a hospital network can now rent or build AI tools that do the heavy lifting for them. The pool of potential attackers has grown even as the tools available to them have gotten sharper.
So what should hospitals actually do? Speakers at the summit pointed to a few concrete steps. First, hospitals need to assume they could lose IT functionality for 30 days or longer, not just a few hours, and build continuity plans around that timeline. Second, those plans need regular testing, not just a binder that sits on a shelf until an emergency hits. Third, backup systems need real investment and strengthening, since backups are often the last line of defense when primary systems go down.
This is a meaningful departure from how most hospitals have traditionally approached disaster recovery. A plan built for a short outage, maybe triggered by a storm or a server failure, looks very different from one built to sustain operations for a month without reliable digital infrastructure. Staff need paper-based backup workflows. Supply chains need manual contingencies. Communication systems need redundancy that doesn't depend on the very network that's been compromised.
There's a financial and regulatory dimension here too. The reintroduced Senate bill signals that lawmakers see this as a systemic risk, not just a hospital-by-hospital problem. The $1.3 billion allocation reflects a recognition that many healthcare organizations, particularly smaller or rural ones, don't have the budget to implement the kind of layered defenses that larger health systems can afford. Baseline cybersecurity requirements could help close that gap, though implementation details and funding mechanisms will matter as much as the headline numbers.
There's a note of cautious optimism buried in all this warning. Perlroth suggested that the severity of the AI threat might finally force the healthcare sector to adopt practices that have been discussed for years but rarely implemented with urgency.
"Long term, I hope that we basically get to a place we've never been before," she said. "That this forces us to do the things we have talked about to death over the past few years in terms of secure-by-design, formal methods, patching, backups, real time backups, backup intelligence, et cetera."
That's the hope: that necessity finally drives action where years of warnings haven't. Secure-by-design principles mean building security into systems from the ground up rather than bolting it on afterward. Formal methods refer to rigorous, mathematically-grounded approaches to verifying that software behaves as intended, reducing the kind of misconfigurations that attackers exploit.
For patients, none of this is abstract. A hospital's ability to withstand a prolonged outage without compromising care depends on decisions being made right now in boardrooms and IT departments. The stakes aren't measured in data breach notifications or regulatory fines alone. They're measured in whether a patient gets the care they need when they need it. As AI reshapes both the offense and the defense in healthcare cybersecurity, that basic promise, reliable, timely care, is what's genuinely on the line.
Tags
Original Sources
Cybersecurity Experts to Hospital Leaders: Think Beyond Traditional Disaster-Recovery Planning - MedCity News
↗ https://medcitynews.com/2026/10/cybersecurity-experts-to-hospital-leaders-think-beyond-traditional-disaster-recovery-planning
About the author
Amara's entry point into AI was an epidemiology role at a London research hospital, where she spent five years studying how digital health tools reached — or conspicuously failed to reach — underserved communities. Watching early algorithmic systems in healthcare quietly entrench existing inequalities, she redirected her career toward the systemic consequences of AI at scale. She covers AI through an unflinching lens: who benefits, who bears the cost, and what evidence actually says versus what the press release claims. Her writing is calm and precise, but she doesn't mistake balance for neutrality.
More from The Steward →This Week's Edition
7 October 2026
34 articles
Related Articles

Cisco's Edge Intelligence Tackles the Unsexy Problem of Getting IoT Data Out of the Field
Tools & Engineering · 5 min

The 2026 Nobel Prizes, and the Persistent Gap Science Still Hasn't Closed
Policy & Regulation · 5 min

Trump Declares Anyone Who Says "AI" Instead Of "Super Intelligence" An Enemy
Policy & Regulation · 5 min
Related Articles

Cisco's Edge Intelligence Tackles the Unsexy Problem of Getting IoT Data Out of the Field
Tools & Engineering · 5 min

The 2026 Nobel Prizes, and the Persistent Gap Science Still Hasn't Closed
Policy & Regulation · 5 min

Trump Declares Anyone Who Says "AI" Instead Of "Super Intelligence" An Enemy
Policy & Regulation · 5 min
More Stories
© 2026 Cedar & Bloom. All rights reserved.