Three Hospitals, Three Attacks
Kristin has worked in healthcare since 2005, starting on an X-ray machine she had to develop film for by hand. She went on to work as a radiology technologist at two hospital systems in North Carolina, each hit by a ransomware attack. A third attack reached her differently: as a new mother, she learned about a breach of her four-week-old daughter’s information from a postcard-sized paper in the mail.
“I’ve always enjoyed working with people. I enjoyed the medical side of things, but I also liked having less paperwork than the nurses did, and I got to have the fun interactions with people. I’d go to a maybe not-so-joyful patient’s room, and I knew that I had about 10 minutes to bring them back smiling.
The first hospital I worked at was a small rural hospital. We worked very closely: it had an emergency department and an imaging side. Everybody was on CPR call, everybody would help out doing IVs, and we worked as a team together, not like a large hospital where everybody had their own turf.
The moment the hospital was attacked, everything just went down. We weren’t informed about the attack. We thought it was another system reboot, or the system was down. The outage went on for roughly three weeks. When I later spoke to a coworker who was there during all that, she remembered it as ‘21 days of hell.’
Without the system, patient identification reverted entirely to paper—and this happened with every patient who came in after the system went down, not just new patients. If someone had already been roomed and checked in before the shutdown, we still had their identification; that was maybe a handful of people.
“John Smith is just a piece of paper at this point. When you have 60 people throughout a shift, that’s a lot of random medical record numbers and a lot of random John Smiths.”
But once the system went down, we had no way to pull up an existing patient’s medical record number or electronic identifiers, even if they’d been treated at our hospital many times before. All we had was a name, a date of birth, and whatever we were collecting manually, so everyone was assigned a temporary, made-up medical record number for the downtime—something like ‘John Smith 000.’ The nurses would write that down on a piece of paper, and that paper goes in a basket. We would go over to the emergency department, pick up John Smith, bring him over to imaging, take his images, upload them to our system, and then hope that we had the correct identifiers to get him back over to the emergency department.
PACS, our radiology imaging system, never actually went down during the attack—we could still take images and put them into PACS—but PACS normally relies on the main hospital system for the patient information that connects those images to a medical record. During the outage, the images had to be entered into PACS under that temporary identity instead. So John Smith is just a piece of paper at this point. When you have 60 people throughout a shift, that’s a lot of random medical record numbers and a lot of random John Smiths.
Someone from hospital leadership eventually came to explain what was happening. They were doing the best they could. Nobody really knew how to fix it, and we were just there doing our best. As for the patients, they had no idea. Our makeshift pile of paperwork was all they knew. We didn’t want to stress them—they shouldn’t have to worry about it.
Four years later, a second hospital where I worked was hit. This time, the response looked very different. That hospital system had already seen a breach elsewhere in the region, and they were expecting to get hit at some point. When it happened, there was an immediate call. Their process was smoother—I think because they had time to plan for their turn. They had color-coordinated items for which area each patient was being pulled out of. They had designated people after the attack to actually go through and put the patients’ medical record numbers and information into the system. It was a shorter outage, only a couple of days.
“You really have to stay focused for the patients, and cyberattacks add an extreme pressure to readiness.”
Even so, working through it required a specific focus. I think when you work in a hospital, you’re kind of used to the trauma effect. The minute that the code bells go off, or the minute that you get a call, you’re just like, ‘All right, let's go.’ You become desensitized in a lot of ways. You really have to stay focused for the patients, and cyberattacks add an extreme pressure to readiness.If I mess up anything, the consequences are real. If I have a patient who comes in and I see a tumor on his scan and then I accidentally link that tumor to a different patient, now that other patient is going to go in to get checked. But the one with the tumor who got the opposite one that was cleared is going to go home and live their life. And we may never find that patient because of that simple error—a mix-up.
Every hospital I’ve ever worked at was short-staffed. You get used to being overworked and overrun. And nothing is ever anyone else’s fault—it always falls on the low man on the totem pole. So in these scenarios, that pressure, to pretend that you were the computer system and act as though you were perfect in that way, while still being human—that was completely exhausting.
Each hospital handled crisis communication differently, and none truly answered for what happened. The increased pressure after the attack was put on the staff. We got sent training phishing emails, and if you opened the email then you got in trouble. I think what needed to change were two things: the accountability, for the leadership saying we allowed this to happen and making a very loud statement about that being their fault—and then, being proud about keeping people’s information private rather than about what tools you’re using to deliver medical information from one system to another. You’re taking that patient’s life into your hands. I don’t want my information leaked, and I don’t want my patients’ either.
Even after the hospital’s system came back online, the damage didn’t go away immediately. Computers being ‘back up’ didn’t mean our work was finished. For every patient who’d come in during the outage, we still had to go back to the paper documentation to identify them, find or create the correct patient and medical record number in the main record, and reconcile the temporary patient we’d created in PACS with the correct patient in the main record. The identifying information had to match exactly so that the two systems could actually communicate with each other and the imaging could be connected to the right medical record.
Yes, the computers were up. Yes, they were working. But none of it worked unless the paperwork matched exactly: the same spelling, the same details, on both sides. If a patient’s name was entered slightly differently in one place than the other, the two records would never link. The computers looked fine, but the people in them weren’t necessarily connected.
“That—at four weeks I couldn’t protect my kid—that part hit me the hardest. The fact that she’s starting off her life on somebody’s computer somewhere, and her information is leaked—that hurt.”
The third attack I lived through reached me as a patient, and a new mother. It was the personal side of it that got to me. I’ve come to accept that all of my personal information is out there, and they can use my social security number at some point. I’ve accepted my fate. But by then, I had my daughter, and about three weeks later we got a letter in the mail for her, and a little postcard from the hospital that said ‘your information has been leaked and you need to sign this stating that you’re aware of it.’ For myself, I didn’t really care. My daughter was four weeks old. That—at four weeks I couldn’t protect my kid—that part hit me the hardest. The fact that she’s starting off her life on somebody’s computer somewhere, and her information is leaked—that hurt. You do everything you can to protect your kids, and then there’s something completely out of your control that you entrusted to someone else for the first time in that child’s life, and it gets stripped away from you. Looking back on all three attacks, that’s what I keep coming back to—it sounds intimidating and technical, but the consequences are human, and it’s on us to put it back together properly.”
Kristin, United States