Curie Brief
Turn on cookies to sign in
Signing in saves your progress to your Curie account. We can only do that with cookies on — turn them on to continue.

Ransomware attacks on hospitals aren't just IT headaches — they're killing patients. A urologist who lived through one argues that the federal government needs to step in with mandatory standards, funding, and centralized ransomware negotiations, because individual hospitals simply don't have the tools to fight back.
When a ransomware attack hit her hospital, urologist Elizabeth Dray, MD, watched staff scramble without electronic records, allergy lists, or imaging access for three weeks. It's a scenario playing out across the country with deadly consequences — and she argues the current regulatory framework is dangerously inadequate.
Right now, hospitals are classified as critical infrastructure but largely left to fend for themselves. HIPAA requires only "reasonable and appropriate" safeguards, HHS's cybersecurity performance goals are voluntary, and law enforcement reporting remains optional. A proposed HIPAA security overhaul floated in December 2024 has stalled amid industry pushback over its projected $20B+ cost, with final action now pushed to July 2027.
Dr. Dray calls for a fundamental shift: mandatory cybersecurity standards with federal subsidies (especially for rural hospitals), required clinical continuity planning, and — most strikingly — centralized federal ransomware negotiations, much like how law enforcement handles hostage situations.
By the Numbers:
Why it matters: As AI tools make large-scale ransomware attacks cheaper and easier to launch, the gap between hospital cyber-readiness and criminal sophistication is widening. Without federal intervention, patients — not just data — will continue to pay the price.