Natalie Sullivan on What Happens When Hospital Goes Dark
Natalie Sullivan is an emergency medicine physician and Assistant Professor at George Washington University, where her academic work focuses on disaster and operational medicine—engineering systems that hold up under pressure. That work puts her at a rare intersection: she treats patients inside the systems cyberattacks are increasingly designed to break and has built her academic work around understanding what happens to a person's care in the minutes and hours after the network goes down.
“I would like to see people connect cyberattacks to potential failure of their healthcare system—to what it would actually be like to bring your father in with a heart attack and not be able to get the care you’d normally expect.”
As a non-cyber professional yourself, where do you see medicine having become so dependent on technology that an attack could actually change a patient’s outcome?
My background is in disaster and operational medicine—I’m an ER doctor focused on emergency management. What I see is that the entire delivery of healthcare now runs through what people call the medical internet of things. Historically there’s been a lot of focus on protecting data privacy, which is important. But when we talk about the outcomes we actually care about for our loved ones, it’s probably not whether their labs got exposed. It’s whether they’re going to die from a heart attack or a stroke.
What I’m interested in is how we use data to make medical decisions in real time. When you come into the ER, I’m looking through your chart to understand how I can help. The fidelity of that record matters for your care right now. Then there are the medical devices: cardiac monitors, IV pumps delivering medication, defibrillators, implanted devices like insulin pumps and pacemakers. On top of that, the diagnostic equipment—labs, CT, MRI, X-ray—all running through the same digital backbone. Almost every touch point in your care is affected by modern technology. That’s a great thing when everything is working normally. But if you’re used to operating that way and suddenly can’t, the downstream consequences for patients can be significant.
Walk me through the cascading effects. If a hospital isn’t the target itself, but the power grid or water system is, what actually breaks?
Any major attack on critical infrastructure like power or water is going to destabilize the healthcare system, because we are incredibly dependent on both. If an entire region is affected, our backup systems aren't going to hold for very long.
So much of how we operate depends on water. Without it, we can’t sterilize equipment, manage basic sanitation, run food services, or maintain fire suppression. Critically, we lose the system that controls temperature, humidity, and air circulation—imagine somewhere like Washington, D.C. in summer without air conditioning. You can’t have patients in a hospital environment like that. You can’t do dialysis without water. And if the whole community loses a safe water source, the hospital is also supposed to be the regional safety net—so now you have increased waterborne illness and dehydration walking through your door on top of everything else.
Electricity is different, because most hospitals have generator power for some period, whereas very few have a water reservoir beyond bottled supply. But if the entire region is out of power, how do you guarantee your hospital gets the diesel it needs to keep generating? Without electricity, we don’t have ventilators, balloon pumps, lighting, climate control, refrigeration, the pumping systems for water, or even reliable access control—a lot of hospital security runs on electronic badging. You can’t do dialysis, and you can’t do a lot of surgical procedures. It’s genuinely debilitating.
When a hospital goes dark, even for a short moment, I imagine the reactions from staff vary. How is it for those who came into healthcare only after the sector fully digitalized?
The new generation of residents I work with has never written a paper prescription, never used a traditional paper chart. There’s a real learning curve in case an attack impacts a hospital. Part of the plan might be “we’ll fax the lab orders down,” except no one’s used a fax machine in years. You end up realizing that a person physically running paperwork back and forth makes more sense than the fax machine you’d planned to fall back on.
You have published on the implications of cyber threats for clinical and hospital system emergency management. What types of cyberattacks are you seeing hit healthcare?
Ransomware is definitely the number one, most frequent type across the board—there are so many incentives to do that in healthcare, unfortunately. Direct attacks on individual medical devices are pretty rare. But it’s a real fear, not just a hypothetical one. Famously, Dick Cheney had a defibrillator while in office, and they had to put it on special settings to make sure no one could disturb it remotely. We know most devices can be hacked if someone really wants to—no device is perfect. That could happen to an individual, or, if devices are connected to the cloud, potentially to many at once.
When a cyberattack hits, hospital staff face a level of stress no tabletop exercise can replicate. From your disaster management background, what actually builds resilience for that moment?
You’re never going to react the same in an exercise as you do when your heart’s pounding and you’re full of adrenaline. In emergency medicine, for things like trauma, we build a very clear algorithm—you do trauma the same way every single time, so that when you’re anxious about a gunshot wound, you already know what to do because you’ve done it a thousand times. I think people get frustrated with cyber preparedness because the advice always comes back to “do a tabletop exercise,” and that’s true, but there’s a difference between a tabletop and a full-scale exercise—actually being in the environment, with real injects, physically writing on paper and carrying it to the lab. That’s the closest you’ll get to adrenaline-pumping decision-making.
Part of the problem is that some hospitals still don’t have cyber in the top three items on their hazard vulnerability analysis. Others have really internalized the threat and are doing far more. They are building it into their emergency operations plan, running tabletops, even working out the nitty-gritty of which paper forms they’ll use and how they’ll track patients without a computer system. At a higher, systems level, it’s about building resilience and mitigation with the assumption that these events are probably inevitable.
When you run a full-scale exercise, it shouldn’t just be the clinicians in the room. There’s always a disconnect: if you’re in IT trying to get systems back up, how do you know what's most clinically urgent? You’re not an ER nurse, and vice versa. That collaboration, between the technical and clinical sides, is fundamental to generating a response that actually holds up.
Does a crisis situation change how dependent care is on technology—for instance, in field or disaster medicine?
If you’re practicing austere or field medicine, you’re probably a little better protected, because you usually have a contained system. If we’re deploying somewhere, we’ll use Starlink and our own internal Wi-Fi. Because less of what we’re doing clinically involves electronic equipment, we’re somewhat better off—though what we’re able to do is also more limited. I can’t really do diagnostic imaging in the field, beyond maybe a portable ultrasound in some situations. My ability to deliver care is limited to what I have on hand. There’s also less opportunity for an attack, but not zero. You could hack into our radio system fairly easily. Honestly, the most clinically impactful thing you could do is build and actually practice a robust downtime system, one that makes people genuinely comfortable operating without an electronic device.
If you had one thing you’d want to see change in the next 12 months, what would that be?
I think people underappreciate how deeply the healthcare sector relies on water, power, and connectivity, and how tightly those three things are intertwined. That’s the shift I’d want to see: real public understanding of that interdependence. If people understood it clearly, they could extrapolate on their own that the failure of one will impact the others. I would like to see people connect cyberattacks to potential failure of their healthcare system—to what it would actually be like to bring your father in with a heart attack and not be able to get the care you’d normally expect. Closing that gap in understanding is the single most important thing we could do this year.