Start of Main Content

What happens when healthcare systems go dark?

Jul 31st, 2026

By Ethan Popowitz 6 min read
what-happens-when-healthcare-systems-go-dark

These days, nearly every business depends on technology to keep its daily operations running smoothly. Healthcare is no different. Clinicians rely on computers and electronic health records to review patient medical histories, send prescriptions, communicate with other practitioners, and coordinate care. Meanwhile, patients use digital systems to schedule appointments, access portals, pay bills, and receive updates.

But when those systems go offline, break down, or are compromised, the impact is immediate.

A cyberattack, vendor outage, natural disaster, or supply chain disruption can suddenly cut staff off from the tools and information they rely on. This kind of incident is sometimes called a “digital darkness” event—a period when critical systems are unavailable, inaccessible, or too unreliable to support normal operations.

Digital darkness events harm healthcare providers and patients alike. They can delay care, disrupt clinical workflows, place additional burdens on staff, interrupt revenue, and potentially put the safety of patients and practitioners at risk.

Not every disruption can be prevented or avoided, but healthcare organizations can prepare for them. By strengthening operational resilience, provider leaders can put guard rails and safety nets in place that help their teams deliver care with minimal impact to patients, practitioners, and communities.

Cyberattacks can bring care to a standstill

Hospitals and healthcare providers are often attractive targets for cybercriminals. Some facilities rely on legacy systems and older software which can be expensive to replace and time-consuming to integrate and train clinicians on.

But what really makes healthcare organizations one of the most common targets of cyberattacks is because they hold large volumes of valuable patient information. Electronic health records typically contain names, addresses, and other personal information hackers can use to commit identity theft, fraud, or blackmail.

Data, however, is only one part of what makes healthcare vulnerable. Cybercriminals also understand how much pressure an outage places on a provider. In a ransomware attack, hackers encrypt data or lock users out of critical systems, then demand payment to restore access. The Department of Health and Human Services (HHS) warns that ransomware can prevent providers from delivering timely care and can put patients in danger.

The scale of the threat can be difficult to ignore. According to the HHS Breach Portal, there have been more than 1,100 reported data breaches from the beginning of January 2025 to June 30, 2026, potentially affecting more than 160 million individuals.

Fig. 1 Types of healthcare data breaches, from January 2025 through June 2026. Data is from the HHS Breach Portal. Accessed July 2026.

Hacking and IT incidents were the most common type of breach during that period, accounting for more than 82% of all healthcare-related cyberattacks. They were not the only concern. Phishing emails can trick employees into sharing login credentials or give attackers an unauthorized entry point into the organization’s network.

Fig. 2 Common sources of healthcare data breaches from January 2025 through June 2026, sourced from the HHS Breach Portal. Accessed July 2026.

Network servers and email were also among the most frequently reported locations of breached information. For provider leaders, that reinforces the need to modernize aging infrastructure, patch known vulnerabilities, strengthen email and authentication controls, and prepare staff to recognize suspicious communications. These measures not only protect sensitive patient data but also reduce the likelihood of an interruption that places patients at risk or subjects the organization to a costly recovery.

The Definitive Healthcare HospitalView product tracks IT hacks and data breaches, along with data on technology installations for network and security systems, connected medical devices, and more. Software and IT leaders and healthcare consultants can use this data to better understand potential vulnerabilities and opportunities when engaging with hospital technology decision makers.

Building operational resiliency during data breaches and cyberattacks

The first step hospitals should take to build operational resiliency is to develop a detailed procedure plan should a cyberattack or software-related problem causes system outages. These plans should explain how teams will provide care, from registering new patients and communicating orders to dispensing medications and reporting lab test results. Be sure to test these procedures regularly across the organization. Simulating the loss of the core systems like the EHR or the phones can reveal gaps in staffing, decision making, and communication that you can proactively address.

Artificial intelligence and predictive analytics are also being employed to fight cyber threats. These tools use historical data and real-time inputs to forecast potential vulnerabilities. AI is also being used for its ability to automate and execute aspects of incident response. When AI tools identify a security incident, such as a ransomware infection or unauthorized access, they can automatically execute predefined actions. This may include isolating compromised devices, disabling accounts, or alerting IT teams to the threat.

The Cybersecurity and Infrastructure Security Agency (CISA) also recommend creating encrypted backups of critical data to limit the damage a hacker can cause and accelerate the recovery process. Importantly, they emphasize maintaining the backups offline, as many ransomware attacks attempt to find accessible backups and either delete or encrypt them to make restoration impossible unless a ransom is paid.

Of course, training your employees to recognize and report phishing attacks goes a long way, too. According to Dialog Health, 75% of employees across the healthcare ecosystem report receiving cybersecurity awareness training, but gaps remain. Only 41% of organizations reported that they conduct phishing simulations to educate staff about cybersecurity risks, and 34% of employees said they were unsure if their workplace even had a cybersecurity policy in place. While many resources are available across the internet, HHS offers a number of awareness and phishing training modules that can serve as a foundation.

Supply chain disruptions can leave providers without essential resources

The healthcare supply chain is arguably one of the most complex systems in the world. Every day, thousands of manufacturers, storage facilities, distributors, pharmacies, and healthcare providers work together to move essential medications and devices to the patients that need them.

But a disruption at any point in that chain can have far-reaching consequences for healthcare practitioners and patients alike. For example, shortages of personal protective equipment (PPE) during the COVID-19 pandemic left many providers without adequate supplies and vulnerable to getting infected and infecting others. More recently, Hurricane Helene devastated the state of North Carolina in 2024. The damage to a major IV fluid production facility led to supply rationing, postponed surgeries, delayed dialysis treatments, and other challenges.

Tactics for maintaining operations during supply chain disruptions

To help keep operations running during a supply chain disruption, there are several steps healthcare providers can take to improve visibility into the market, enhance coordination and communication between teams, and respond more quickly when challenges arise.

One place to start is by diversifying your suppliers, distributors, and even delivery routes whenever possible. Putting all your eggs in one basket can create a critical point of failure should drug shortages occur. The FDA outlines risk management plans to mitigate the risk of supply chain disruptions, which includes a framework for stakeholders to consider a “dual sourcing” approach to securing a supply of needed medications. While sourcing every product from multiple suppliers may not be practical, establishing backup options for high-priority items can give organizations more flexibility when shortages occur.

AI can further strengthen supply chain planning by helping organizations anticipate demand and identify potential disruptions earlier. By analyzing historical data, patient volumes, scheduled procedures, and current inventory, AI-powered tools can forecast supply needs and alert teams when shortages are likely to occur.

Cloud-based enterprise resource planning systems can support these efforts by connecting supply chain, inventory, procurement, and financial information in one place. When data is spread across separate facilities, spreadsheets, and disconnected platforms, leaders may struggle to understand what supplies are available and where risks are emerging.

And finally, it’s important to keep up and comply with regulatory requirements. Be sure to conduct regular audits among suppliers, warehouses, and distributors to uncover vulnerabilities, identify safety concerns, and prevent legal issues before they attract the attention of the FDA or other regulatory bodies.

Being proactive is your best strategy

The reality is that the best time to prepare for a disruption to your facility’s operations is before one ever happens. That means looking for vulnerabilities, building backup options, testing contingency plans, and giving your teams the data they need to respond quickly.

You may not be able to prevent or predict every period of downtime, but stronger preparation will help immensely in protecting patients and providers, reducing strain and medical errors, and recovering faster.

That preparation begins with getting clarity into your market, from the software and healthcare IT vendors who can upgrade your network infrastructure to the medical and facility suppliers available to keep shipments coming in smoothly. Our solution for healthcare providers can also help you create more informed strategies around expanding service lines, preventing patient leakage, and outpacing your competitors. Book a demo with Definitive Healthcare today to see how we can help you adapt to changes in the market and grow.

Ethan Popowitz

About the Author

Ethan Popowitz

Ethan Popowitz is a Senior Content Writer at Definitive Healthcare. He writes data-driven articles about telehealth, AI, the healthcare staffing shortage, and everything in…

Author profile