Could Your Healthcare Organization Recover From a Cyberattack? 7 Questions Healthcare Leaders Should Ask Their IT Team
Most healthcare leaders assume their cybersecurity strategy is working until a cyberattack takes critical systems offline. The real question is not whether defenses exist. It is whether your organization can still operate when those defenses fail.
Prevention still matters. But mature healthcare providers and care delivery organizations also ask a second question: If an attacker gets through anyway, can we still operate?
In 2025, the healthcare and public health sector experienced 460 reported ransomware attacks, more than any other critical infrastructure sector, according to the American Hospital Association citing the FBI Internet Crime Report.
For healthcare organizations, a cyberattack can disrupt far more than data. It can take down EHR access, scheduling, phones, billing, pharmacy connections, email, lab interfaces, and other systems staff depend on every day.
That is why cybersecurity has to include cyber resilience: the ability to maintain essential operations, recover critical systems, and make informed decisions during disruption. Healthcare leaders do not need to become cybersecurity engineers, but they should be able to get clear answers to these seven questions.
What Downtime Really Costs
Cyber downtime is not only an IT problem. Even a single day without access to clinical, scheduling, revenue cycle, and communication systems can create consequences across the organization.
• Patient care operations, including delayed documentation, medication decisions, and care coordination
• Revenue collection, including billing delays, claim submission interruptions, and slower payment processing
• Staff productivity, as teams move to manual workflows and spend time recreating information after systems return
• Regulatory reporting and documentation responsibilities that may be harder to complete when source systems are unavailable
The longer systems remain unavailable, the more those effects compound. Recovery planning therefore has to consider both how quickly technology can be restored and how the organization will continue operating until restoration is complete.
1. If Our Systems Went Down Tomorrow, What Would We Restore First?
Not every system has the same operational importance.
A strong disaster recovery plan identifies which systems must return first and what dependencies they require. The EHR may be critical, but it cannot function effectively if authentication, network infrastructure, or necessary devices are still unavailable.
Leadership should know the restoration sequence before an incident occurs, not discover it during one. Recovery priorities should reflect patient safety, essential operations, revenue, and the dependencies required to bring critical systems back online.
2. When Was the Last Time We Actually Restored Something From Backup?
Having backups is not the same as having proven recovery.
Backups can be incomplete, corrupted, inaccessible, or compromised during a ransomware attack. Healthcare providers and care delivery organizations should maintain protected backups and regularly test whether data and systems can actually be restored.
Ask when your organization last performed a successful restoration, what was recovered, how long it took, and whether problems were found.
A backup that has never been tested is an assumption. A backup that has been successfully restored is a capability.
3. How Long Could We Operate Without Our EHR?
Healthcare organizations are deeply dependent on technology. The important question is not only how quickly the EHR can be restored, but how long clinical and administrative teams can safely operate without it.
If the EHR is unavailable for a few hours, downtime procedures may be manageable. If the outage lasts a day or longer, the consequences can quickly expand. Teams may be:
• Unable to access medication history when making care decisions
• Unable to process refill requests through normal workflows
• Forced to delay or manually manage patient scheduling
• Missing lab interfaces or unable to view incoming results in the normal system
The organization also needs clear procedures for documentation, prescriptions, patient communication, billing, and reconciling information after systems return.
Disaster recovery focuses on restoring technology. Business continuity focuses on keeping the organization functioning while technology is unavailable. Healthcare providers and care delivery organizations need both.
4. If Email, Teams, or Our Phones Were Down, How Would We Communicate?
Most incident response plans assume communication tools will still work. A major cyberattack may make email, collaboration platforms, networks, or phone systems unavailable or untrustworthy.
Organizations should have secure alternative communication methods, current emergency contact information, and a clear process for validating instructions during an incident. Recovery is not only a technology challenge. It is also a coordination challenge.
5. Who Has the Authority to Make Decisions During a Cyber Incident?
A cyberattack quickly creates business decisions. Should systems be disconnected? Should appointments continue? Who contacts cyber insurance? When should legal counsel or law enforcement become involved? Who communicates with employees, residents, patients, and families?
Those responsibilities should be defined before an incident. A mature response plan gives IT, leadership, compliance, clinical operations, and other stakeholders clear roles so critical decisions are not delayed by uncertainty.
6. How Much of Our Recovery Depends on a Third Party?
Healthcare providers and care delivery organizations rely on EHR vendors, cloud providers, billing companies, laboratories, pharmacy systems, telecommunications providers, cybersecurity vendors, and other third parties.
The lesson from major healthcare disruptions is not to avoid third party technology. It is to make third party dependencies part of the recovery plan.
Leadership should know which vendors are essential, what happens if they become unavailable, who is responsible for escalation, and what alternative workflows exist.
7. Have We Practiced This, or Have We Only Written It Down?
A written plan is not the same as a tested plan.
Tabletop exercises can reveal outdated emergency contacts, unclear decision making, missing vendors, gaps in downtime procedures, and other problems that may not be obvious on paper.
The purpose of testing is not to prove the organization is perfectly prepared. It is to find weaknesses before a real attack exposes them and to use what the organization learns to improve future response and recovery.
Cyber Resilience Is a Leadership Issue
Cyber resilience changes the cybersecurity conversation from asking only how to stop every attack to asking how the organization will prevent what it can, limit the impact of what gets through, and recover safely.
That distinction matters in healthcare. OCR continues to emphasize the importance of accurate and thorough HIPAA Security Rule risk analysis in ransomware related enforcement. The message for healthcare leaders is clear: organizations are expected to understand their risks before an incident occurs, not only respond after one.
A resilient organization knows which systems matter most, tests its backups, maintains downtime procedures, understands vendor dependencies, and exercises its response plan.
Could your organization recover from a cyberattack today? DAS Health can help evaluate your backup strategy, disaster recovery readiness, critical system dependencies, and cybersecurity controls to identify gaps before an incident puts them to the test.
Schedule a Cyber Resilience Assessment: Contact DAS Health today.
Frequently Asked Questions About Healthcare Cyberattack Recovery
What is cyber resilience in healthcare?
Cyber resilience is a healthcare organization’s ability to prepare for cyberattacks, continue essential operations during disruption, restore critical systems, and improve its security program after an incident. It goes beyond prevention by addressing what happens when systems or data become unavailable.
Is having backups enough to recover from ransomware?
No. Backups are essential, but healthcare providers and care delivery organizations also need tested restoration procedures, defined recovery priorities, protected backup copies, and a plan for operating while systems are being restored.
What should a healthcare organization restore first after a cyberattack?
Organizations should restore systems according to predefined priorities based on patient safety, essential operations, and system dependencies. The EHR may not always be first if identity services, networking, or other infrastructure must be restored before it can function.
What is the difference between disaster recovery and business continuity?
Disaster recovery focuses on restoring technology and data. Business continuity focuses on keeping the organization operating while those systems are unavailable. Healthcare providers and care delivery organizations need both capabilities.
Why are third party vendors part of cyber resilience?
Healthcare providers and care delivery organizations depend on third parties for EHRs, cloud services, billing, telecommunications, labs, pharmacy systems, and other critical services. A cyberattack against one of those vendors can disrupt operations even if the organization’s own systems were not directly compromised.
What should healthcare leaders ask their IT provider about ransomware preparedness?
Leaders should ask about recovery priorities, tested backups, EHR downtime procedures, alternate communications, decision making authority, vendor dependencies, and when incident response plans were last exercised. The answers should be specific, documented, and tested.
How DAS Health Helps Build Cyber Resilience
Cyber resilience depends on more than one security product. It requires cybersecurity controls, backup and disaster recovery, identity management, infrastructure, vendor coordination, and responsive IT support working together.