Dark cover tile reading 34-38% more deaths, with a subtitle noting the figure is for Medicare patients already admitted to a US hospital when the ransomware attack began, across attacks from 2016 to 2021.
|

Ransomware Raises In-Hospital Deaths by a Third. The Case That Made It Famous Was Investigated as a Homicide, and Cleared.

Key takeaways · 14 min read

  • 374 ransomware attacks on US health care delivery organisations were identified between 2016 and 2021, more than doubling annually over the period, exposing the health information of nearly 42 million patients. About three-quarters disrupted patient care.
  • 3.7% of US short-term acute care hospitals were attacked — but they sat in 23.5% of hospital markets.
  • Attacked hospitals were larger, more profitable and more likely to run trauma, emergency and obstetric services. Measures of IT sophistication did not differ from non-attacked hospitals.
  • Volume falls 17–24% in the attack week and recovers within three weeks. Rural hospitals lost more outpatient volume than urban ones.

On the night of 9 September 2020, ransomware called DoppelPaymer encrypted thirty servers at University Hospital Düsseldorf. The hospital cancelled hundreds of operations, stopped accepting new patients and spent the following fortnight running at about half capacity. A woman with an aortic aneurysm was turned away and driven 32 kilometres to Wuppertal instead. She died shortly after arriving.

German prosecutors opened a negligent homicide investigation. It was reported worldwide as the first death caused by a cyberattack. Two months later the investigation was dropped. The chief public prosecutor, Markus Hartmann, put it plainly: the delay was of no relevance to the outcome, and the medical condition was the sole cause of death, entirely independently of the attack. Two further details had already emerged. The ransom note was addressed to Heinrich Heine University, not the hospital — the attackers appear to have hit the wrong target — and when police told them what they had encrypted, they handed over the decryption key without asking for money. The way in was a Citrix VPN vulnerability that had been publicly documented since January.

So the case that made hospital ransomware famous did not, on examination, kill anyone. What has happened since is that researchers stopped looking for individual deaths and started measuring populations instead. What they found is smaller than a homicide and much larger than a single case: measurable disruption at the attacked hospital, measurable harm to patients already inside it, and measurable spillover onto hospitals that were never attacked at all.

A pointillist illustration of a hospital corridor at night, doors receding towards a single lit station at the end.
Everything reverts to paper.

How often this happens, and to whom

The first systematic count came from Hannah Neprash and colleagues at Minnesota, published in JAMA Health Forum at the end of 2022. Using a purpose-built database, they identified 374 ransomware attacks on US health care delivery organisations between 2016 and 2021. The annual number more than doubled over that period. The attacks exposed the personal health information of nearly 42 million patients, and roughly three-quarters of them disrupted patient care in some way — ambulance diversion, electronic system downtime, cancelled appointments.

A companion paper by Claire McGlave and colleagues asked which hospitals get hit. The answer is not the one most people would guess.

Which hospitals ransomware actually hits

US short-term acute care hospitals, 2016–2021. Comparison of attacked and non-attacked hospitals.

LARGERAttacked hospitals had higher net operating revenue and were more likely to be financially profitable. The authors read this as targeting: criminals selecting on perceived ability to pay.
MORE ACUTEMore likely to provide trauma, emergency and obstetric services, and more likely to be urban. The services with the least tolerance for downtime.
NOT LESS SOPHISTICATEDMeasures of information technology sophistication did not differ between attacked and non-attacked hospitals. Being more advanced did not protect them.
3.7% AND 23.5%3.7% of US short-term acute care hospitals were attacked over the six years — but those hospitals sat in 23.5% of hospital markets. Nearly one market in four contained a victim.

McGlave, C. et al., Health Affairs Scholar, 2023, using American Hospital Association Annual Survey and Healthcare Cost Report Information System data.

That last pair of numbers is the one to hold on to. A three-in-a-hundred chance that your own hospital is attacked sounds tolerable. A one-in-four chance that some hospital in your city is attacked, and that its patients arrive at yours, is a different proposition entirely.

What the attacked hospital stops doing

Neprash and colleagues then linked the attack database to Medicare fee-for-service claims and ran a stacked event study, comparing week-by-week volume at attacked and non-attacked hospitals. The collapse is immediate and the recovery is quick.

Change in volume during the first week of a ransomware attack

Medicare fee-for-service volume at attacked hospitals versus non-attacked controls, 2016–2021.

Rural hospitalsUrban hospitals
−14.7%
−16.9%
−35.3%
−22.0%
−10.0%
—
Inpatient admissionsOutpatient visitsEmergency visits

Neprash, H.T. et al., Journal of Rural Health, 2024. Inpatient p = 0.04 rural, 0.01 urban; outpatient p < 0.01 rural, 0.03 urban. Volumes recovered to pre-attack levels within two to three weeks. The urban emergency estimate was not separately reported in the same form.

Rural hospitals were hit as hard as urban ones, and their outpatient services harder. This matters because a rural hospital’s catchment often has no second option within a reasonable drive, so the patients who disappear from those figures did not simply go somewhere else.

The mortality figure, and what it is not

The same team’s full analysis, published in the American Economic Journal: Economic Policy in early 2026, is the study that produced the number now being quoted everywhere. Hospital volume fell 17 to 24 per cent during the attack week and recovered within three weeks. And among patients who were already admitted when a ransomware attack began, in-hospital mortality increased by 34 to 38 per cent.

That is a large effect and it deserves careful reading. Three things constrain it.

Reading the 34 to 38 per cent correctly

IT IS RELATIVEA 34% increase on a baseline in-hospital mortality rate of a few per cent is an increase of roughly one to two percentage points, not thirty-four. The absolute risk to any individual patient is small; the population effect is not.
IT IS ONLY FOR THOSE ALREADY INSIDEThe estimate is for patients admitted before the attack started. They could not be diverted, they could not reschedule, and they were the only group whose exposure the study could cleanly identify.
THE DENOMINATOR MOVEDAdmissions fell by roughly a fifth in the same week. Any measure computed over hospital patients during an attack is computed over a differently composed group than the week before.

Neprash, H.T., McGlave, C. and Nikpay, S., American Economic Journal: Economic Policy, 2026, linking a hospital ransomware attack database to Medicare claims.

None of that makes the finding go away. A quasi-experimental design on national claims data, with non-attacked hospitals as controls, is about as good as evidence on this question is ever going to get, since nobody is going to randomise hospitals to be hacked. But the honest sentence is that ransomware raises the death rate among inpatients by a modest number of percentage points, not that it kills a third of them.

It is also worth noticing what the design cannot see. Patients who were never admitted because the hospital had stopped admitting — roughly a fifth of a normal week’s intake — leave no trace in that hospital’s mortality statistics at all. Some of them went elsewhere and were fine. Some of them had operations postponed by three weeks. Whatever happened to them is counted, if it is counted anywhere, in somebody else’s data. The 34 to 38 per cent figure is therefore a lower bound on the disruption and an upper bound on nothing.

The hospital that was not attacked

A pointillist illustration of an empty gurney standing in a dim side corridor beside a lit doorway.
Waiting where it was left.

In May 2021 a health system operating four acute hospitals in San Diego, accounting for about a quarter of the region’s inpatient discharges, spent a month under ransomware. Less than a mile away sat two academic hospitals belonging to a different system, accounting for about eleven per cent of discharges. They were never attacked. Two research groups measured what happened to them.

Christian Dameff and colleagues, in JAMA Network Open, examined 19,857 emergency department visits at the unaffected hospitals across three phases — 6,114 before the attack, 7,039 during it and the recovery, 6,704 after. During the attack and post-attack phases they recorded significant increases in patient census, ambulance arrivals, waiting room times, patients who left without being seen, total length of stay, county-wide emergency medical services diversion, and acute stroke care metrics.

A second group, led by Thaidan Pham, then looked specifically at cardiac arrests at the same untargeted hospitals.

Cardiac arrests at two hospitals that were never attacked

Two academic hospitals within one mile of a ransomware-infected health system, San Diego, 2021. 78 cardiac arrests across three four-week phases.

Before (3–30 April)21
During (1–28 May)38
After (29 May–25 June)19
42.9% → 18.4%Survival to discharge after any cardiac arrest, before versus during (p = 0.04). It returned to 47.4% afterwards (p = 0.02).
40.0% → 4.5%Survival with a good neurological outcome after out-of-hospital cardiac arrest (p = 0.02). It returned to 41.2% afterwards (p = 0.01).

Pham, T. et al., Critical Care Explorations, 2024. An ARIMA model fitted to four preceding years forecast 27 arrests for May 2021 (95% CI 17.0–37.4) against 41 observed, and 12 out-of-hospital arrests (95% CI 6.0–18.8) against 24 observed. County-wide pre-hospital cardiac arrests did not differ between phases (225 versus 258, p = 0.13).

The authors of that study are more careful than the headline allows, and their caveat belongs in the article rather than a footnote. The number of arrests rose, but the rate per 1,000 admissions did not change significantly — 0.9 before, 1.6 during, 0.8 after, p = 0.20. The extra arrests arrived because the extra patients arrived. What did change, and did not have a volume explanation, was survival. And the authors state that they lack complete data on ambulance transit times, whether arrests were witnessed and whether bystander resuscitation was given, any of which could matter.

What survives that caution is the pattern of the three phases. Survival to discharge after a cardiac arrest was 42.9 per cent in the four weeks before the attack, 18.4 per cent during it, and 47.4 per cent in the four weeks after. A confounder that produced that shape would have to appear and disappear on exactly the attack’s schedule, at two hospitals a mile from the attacked one, while county-wide pre-hospital cardiac arrests stayed flat. The most economical explanation is the one the authors offer: emergency services were being diverted, the emergency department was fuller, admitted patients were boarding in it waiting for beds, and time-critical resuscitation is exactly the kind of care that degrades when a department is running above its designed load.

The remediation has a cost of its own

The obvious response to all of this is that hospitals should spend more on security. There is a study suggesting the response itself is not free.

Sung Choi, Eric Johnson and Christoph Lehmann merged the US Department of Health and Human Services database of hospital data breaches with Medicare Compare quality data for 2012–2016, producing a panel of 3,025 hospitals and 14,297 hospital-years, and ran a difference-in-differences analysis. Their outcome measures were the time from a patient walking through the door to receiving an electrocardiogram, and thirty-day mortality after acute myocardial infarction.

What happened to breached hospitals in the three years afterwards

Difference-in-differences estimates across 3,025 US hospitals, 2012–2016.

+2.7 minIncrease in door-to-electrocardiogram time, at the maximum of the estimated range, during the three-year window following a breach.
+0.36 ppIncrease in 30-day mortality after acute myocardial infarction, at the maximum of the estimated range, over the same window.

The authors attribute this to remediation rather than to the breach itself: new authentication steps, additional logging, changed workflows and re-trained staff all sit between a clinician and the record. Their conclusion is not that hospitals should skip security, but that breached hospitals and their regulators should evaluate remedial measures for their effect on care, which at present nobody systematically does.

Choi, S.J., Johnson, M.E. and Lehmann, C.U., Health Services Research, 2019.

Set that beside McGlave’s finding that measures of information technology sophistication did not differ between attacked and non-attacked hospitals, and the comfortable story — that hospitals get hacked because they are behind, and the fix is to catch up — does not survive contact with either dataset. What predicted an attack was being big, profitable and running an emergency department. What follows a breach is a security programme that measurably slows down cardiac care.

The Düsseldorf case, in full

It is worth returning to the case that started the alarm, because the way it is still cited is itself a small lesson in how risk numbers travel.

What was reported, and what was established

As reportedA ransomware attack on a German hospital caused a woman’s death after she was diverted 32 kilometres to another city. Prosecutors opened a negligent homicide investigation, described at the time as the first of its kind.
As establishedThe investigation closed after about two months. The chief public prosecutor stated the delay was of no relevance to the outcome and that her medical condition was the sole cause of death, independently of the attack.
Also establishedThe hospital was probably not the intended target: the ransom note was addressed to Heinrich Heine University. When police told the attackers they had encrypted a hospital, they supplied the decryption key and dropped the demand.
Still trueThe entry point was a Citrix VPN vulnerability publicly documented since January 2020. Thirty servers were encrypted, hundreds of operations were cancelled and the hospital ran at roughly half capacity for about two weeks.

Both halves are worth keeping. The specific causal claim failed. The disruption was entirely real, it lasted a fortnight, and it was made possible by a patch that had been available for eight months. The strongest evidence that hospital ransomware harms patients does not come from that case or any case like it; it comes from counting thousands of admissions and comparing them with a control group.

What a patient can do, which is not much

This article sits in the category of risks you do not control, and it belongs there honestly. There is no consumer product, subscription or precaution that changes your exposure to a hospital being encrypted. What the evidence does support is a short and unglamorous list.

What follows from the evidence

KNOW THE SECOND HOSPITALSpillover is the best-documented effect. If the nearest emergency department is under attack or crowded because a neighbour is, knowing where the next one is, and how far, is worth more than anything you can buy.
KEEP YOUR OWN SHORT RECORDA current medication list, allergies, implanted devices and recent procedures, on paper or on your phone. During downtime, clinicians work from what the patient can tell them, and the studies describe exactly that reversion to manual processes.
TREAT DELAYS AS THE SIGNALThe measured harm runs through time: longer waits, longer stays, diverted ambulances, slower stroke and cardiac pathways. If care is being deferred for a system reason, that is the moment to ask what the alternative is.
EXPECT THE BREACH LETTER42 million people’s health information was exposed in six years. Health data cannot be re-issued like a card number. Freezing credit addresses a different problem, and mostly not this one.

The rest is a policy problem, and the research points at it fairly precisely: attacks concentrate in markets rather than in single hospitals, the harm spreads to institutions that did nothing wrong, and regional disaster planning — which exists for earthquakes and mass casualties — largely does not exist for this. Both San Diego papers end with the same recommendation, which is that a cyberattack on a hospital should be treated as a regional disaster rather than as one organisation’s IT problem.

A pointillist illustration of an empty ambulance bay at dusk, painted lines receding under a dark canopy.
The ambulances go somewhere else tonight.

Questions people ask

Has anyone actually died because of a hospital ransomware attack?

No individual death has been established in court or by a coroner as caused by a ransomware attack. The Düsseldorf investigation, the most prominent attempt, concluded the opposite. What has been established, statistically, is that in-hospital mortality among patients already admitted rises by 34 to 38 per cent during an attack, and that survival after cardiac arrest fell sharply at two hospitals adjacent to an attacked system. Those are population findings, and they cannot be traced back to a named patient.

Should hospitals pay the ransom?

That is a policy and law-enforcement question rather than a clinical one, and the research cited here does not answer it. What the research does show is that recovery took two to three weeks in the US claims data and about a fortnight in Düsseldorf, where the key was ultimately handed over for nothing. Payment does not restore systems instantly; decryption is itself a slow process.

Is my own hospital likely to be attacked?

Over 2016 to 2021, 3.7 per cent of US short-term acute care hospitals were. That is the wrong question, though. 23.5 per cent of hospital markets contained an attacked hospital, and the spillover evidence says the patients of an attacked hospital become the problem of its neighbours within days.

Does this happen outside the United States?

Yes — Düsseldorf, the 2017 WannaCry disruption of the English NHS and a long list since. But almost all of the quantitative evidence on patient outcomes comes from US data, because US Medicare claims and breach reporting make the analysis possible. Whether the effect sizes transfer to systems with different capacity, different diversion practices and different reporting is untested.

Would better hospital IT prevent this?

Measures of information technology sophistication did not differ between attacked and non-attacked hospitals in the one study that looked. What differed was size, revenue, profitability and the presence of trauma, emergency and obstetric services. And in a separate analysis, the security remediation that follows a breach was associated with slower door-to-electrocardiogram times and higher heart-attack mortality for three years. Security is necessary; it is not costless and it is not obviously protective in the way the phrase suggests.

The short version

  • 374 ransomware attacks on US health care delivery organisations were identified between 2016 and 2021, more than doubling annually over the period, exposing the health information of nearly 42 million patients. About three-quarters disrupted patient care.
  • 3.7% of US short-term acute care hospitals were attacked — but they sat in 23.5% of hospital markets.
  • Attacked hospitals were larger, more profitable and more likely to run trauma, emergency and obstetric services. Measures of IT sophistication did not differ from non-attacked hospitals.
  • Volume falls 17–24% in the attack week and recovers within three weeks. Rural hospitals lost more outpatient volume than urban ones.
  • In-hospital mortality among patients already admitted rises by 34–38%. That is a relative increase on a low base, for a specific group, in a week when the denominator also moved.
  • The harm spreads. At two hospitals a mile from an attacked system, cardiac arrests rose from 21 to 38 and survival to discharge fell from 42.9% to 18.4%; the rate per 1,000 admissions, however, did not change.
  • Breach remediation itself was associated with door-to-electrocardiogram times up to 2.7 minutes longer and 30-day heart-attack mortality up to 0.36 percentage points higher, for three years afterwards.
  • The most famous case — Düsseldorf 2020 — was investigated for negligent homicide and cleared. The prosecutor found the delay irrelevant to the outcome. The disruption was real; the death was not caused by it.

This article describes population-level research on hospital operations. It is not medical advice and cannot tell you anything about the care you or anyone else received. If you believe a delay in your own treatment caused harm, that is a matter for your clinicians and, if necessary, a lawyer — not for an article about averages.

Further reading: the two San Diego papers are the most readable entry point and both are open access — Dameff et al. in JAMA Network Open and Pham et al. in Critical Care Explorations. The Health Affairs Scholar paper on which hospitals get attacked is also free.

Three books
  • Sandworm, Andy Greenberg (2019). Reporting on how infrastructure attacks actually unfold, including the ones that reached hospitals by accident.
  • A Hacker’s Mind, Bruce Schneier (2023). On why systems never meant to be safety-critical keep becoming safety-critical anyway.
  • Doom, Niall Ferguson (2021). On why institutions built to prevent catastrophe so often fail to.

Sources

  • Neprash, H.T., McGlave, C., Cross, D.A., Virnig, B.A., Puskarich, M.A., Huling, J.D. et al., “Trends in Ransomware Attacks on US Hospitals, Clinics, and Other Health Care Delivery Organizations, 2016–2021”, JAMA Health Forum, December 2022. (374 ransomware attacks identified; annual number more than doubled over the period; personal health information of nearly 42 million patients exposed; approximately 75% of attacks on hospitals disrupted patient care, including ambulance diversion, system downtime and delays to scheduled care.)
  • McGlave, C., Nikpay, S., Henning-Smith, C., Rydberg, K. and Neprash, H.T., “Characteristics of short-term acute care hospitals that experienced a ransomware attack from 2016 to 2021”, Health Affairs Scholar, August 2023. (Ransomware attacks affected 3.7% of US short-term acute care hospitals and 23.5% of hospital markets. Attacked hospitals had larger operating revenue, were more likely to be financially profitable, and more likely to provide trauma, emergency and obstetric services in urban areas. Measures of information technology sophistication did not differ between attacked and non-attacked hospitals.)
  • Neprash, H.T., McGlave, C. and Nikpay, S., “Hacked to Pieces? The Effects of Ransomware Attacks on Hospitals and Patients”, American Economic Journal: Economic Policy, February 2026. (Hospital ransomware attack database linked to Medicare claims. Hospital volume decreased 17–24% during the initial attack week, recovering within three weeks. Among patients already admitted when an attack began, in-hospital mortality increased by 34–38%.)
  • Neprash, H.T., McGlave, C., Rydberg, K. and Henning-Smith, C., “What happens to rural hospitals during a ransomware attack? Evidence from Medicare data”, Journal of Rural Health, March 2024. (Stacked event study, 2016–2021. First attack week: inpatient admissions fell 14.7% at rural hospitals, p = 0.04, and 16.9% at urban hospitals, p = 0.01; outpatient visits fell 35.3% rural, p < 0.01, and 22.0% urban, p = 0.03; emergency room visits fell 10.0% at rural hospitals. Volumes recovered within two to three weeks.)
  • Dameff, C., Tully, J., Chan, T.C., Castillo, E.M., Savage, S., Maysent, P. et al., “Ransomware Attack Associated With Disruptions at Adjacent Emergency Departments in the US”, JAMA Network Open, May 2023. (Two academic urban emergency departments adjacent to a health care delivery organisation under a month-long ransomware attack; 19,857 ED visits evaluated — 6,114 pre-attack, 7,039 attack and recovery, 6,704 post-attack. Significant increases in patient census, ambulance arrivals, waiting room times, patients leaving without being seen, total length of stay, county-wide EMS diversion and acute stroke care metrics.)
  • Pham, T., Loo, T., Malhotra, A., Longhurst, C., Hylton, D.J., Dameff, C. et al., “Ransomware Cyberattack Associated With Cardiac Arrest Incidence and Outcomes at Untargeted, Adjacent Hospitals”, Critical Care Explorations 6(4), April 2024. (Attacked system: four acute hospitals, 25% of regional discharges. Untargeted adjacent system: two academic hospitals, 11% of discharges, under one mile away. 78 cardiac arrests: 21 pre-attack, 38 attack, 19 post-attack, p = 0.03 and p = 0.01. Mean daily incidence per 1,000 admissions 0.9 versus 1.6 versus 0.8, p = 0.20, not significant. Survival to discharge 42.9% versus 18.4%, p = 0.04, and 47.4% post-attack, p = 0.02. Favourable neurologic outcome after out-of-hospital arrest 40.0% versus 4.5%, p = 0.02, and 41.2% post-attack, p = 0.01. ARIMA forecast for May 2021: 27 arrests, 95% CI 17.0–37.4, against 41 observed; 12 out-of-hospital arrests, 95% CI 6.0–18.8, against 24 observed. County pre-hospital arrests 225 versus 258, p = 0.13.)
  • Choi, S.J., Johnson, M.E. and Lehmann, C.U., “Data breach remediation efforts and their implications for hospital quality”, Health Services Research, September 2019. (HHS hospital data breach database merged with Medicare Compare quality data, 2012–2016; panel of 3,025 hospitals and 14,297 hospital-year observations; difference-in-differences. Time from door to electrocardiogram increased by as much as 2.7 minutes and 30-day acute myocardial infarction mortality by as much as 0.36 percentage points during the three-year window following a breach.)
  • Public prosecutor’s office, Cologne, and reporting on the University Hospital Düsseldorf DoppelPaymer incident, September–November 2020. (Attack detected 9–10 September 2020 via a Citrix VPN vulnerability publicly documented since January 2020; 30 servers encrypted; hundreds of operations cancelled; hospital operated at approximately 50% capacity during a recovery of about two weeks. Ransom note addressed to Heinrich Heine University; the decryption key was supplied without a ransom demand once police informed the attackers that a hospital had been affected. A patient with an aortic aneurysm was diverted 32 kilometres to Wuppertal and died. Chief public prosecutor Markus Hartmann stated that the delay was of no relevance to the final outcome and that the medical condition was the sole cause of death, independently of the cyberattack; the negligent homicide investigation was closed after approximately two months.)

Similar Posts