06 Aug Ransomware Is Now a Patient-Safety Issue: What a 38% Hospital Mortality Study Means for Your Dental Practice
For years, the case for healthcare cybersecurity was made in dollars and disruption: fines, breach-notification costs, downtime, reputational harm. That framing is now out of date. In February 2026, peer-reviewed research reframed the entire problem by measuring something no spreadsheet had captured before – ransomware’s cost in human lives. When an attack takes a hospital offline, the patients already inside the building die at measurably higher rates. It is a sobering finding, and while a dental practice is not an emergency department, the mechanism behind it should change how every healthcare provider – including a small office – thinks about being knocked offline.

The finding: ransomware raises in-hospital mortality
The study, published in the American Economic Journal: Economic Policy, did not rely on a model or a survey. It linked Medicare claims data to confirmed ransomware incidents and found that in-hospital mortality for patients already admitted when an attack begins rises by roughly 34 to 38 percent. Separately, the Halcyon Ransomware Research Center, drawing on University of Minnesota data, estimated 42 to 67 preventable deaths over a five-year period, with mortality among hospitalized Medicare patients climbing from about three in 100 to four in 100 under attack conditions.
The reason is grimly practical. When systems go dark, clinicians work blind. Medication histories vanish, imaging systems go offline, allergy records become inaccessible, emergency departments divert incoming ambulances elsewhere, pharmacies revert to paper, and procedures are postponed. Every one of those is a clinical decision made without the data that would normally inform it. The harm is not caused by the encryption itself – it is caused by the sudden absence of the information that modern care depends on.

Why this matters for a dental practice
A dental office will never appear in a hospital mortality statistic, and it would be alarmist to suggest otherwise. But the finding is a warning about a mechanism, not just a body count – and that mechanism is present in every practice that has gone digital. Your practice runs on a chain of dependence: the practice-management database that holds every schedule and chart, digital radiography and imaging that inform diagnosis, and the medication and allergy histories you check before administering anesthetic or prescribing. Sever that chain in the middle of a clinical day and you are not merely inconvenienced – you are practicing without the information you rely on to practice safely.

Consider the ordinary morning that turns bad: a hygienist cannot pull a patient’s radiographs to compare against today’s exam, the front desk cannot confirm a medical-history flag before an extraction, and a sedation appointment has to be postponed because the chart documenting the patient’s conditions is encrypted and unreadable. None of that makes the evening news, but each is a patient-safety event in miniature. The hospital research simply makes visible, at scale, what a small practice experiences one anxious appointment at a time. Cybersecurity, in other words, is now inseparable from continuity of care.
Why the industry is treating this as an emergency
The mortality research did not land in a vacuum. It arrived after a run of attacks large enough to reshape the entire sector’s thinking. The February 2024 Change Healthcare ransomware attack – carried out by the ALPHV/BlackCat group, which exfiltrated more than six terabytes of billing and protected health information – ultimately affected approximately 192.7 million individuals, close to two-thirds of the US population, with total costs estimated between $2.5 and $3 billion. Ascension Health, hit separately in May 2024, exposed data for 5.6 million patients and reported a $1.1 billion net loss for the year, citing the attack as a material factor. In the UK, the Synnovis pathology attack in June 2024 exposed the data of nearly a million NHS patients and forced hospitals to cancel operations and appointments for weeks.
That pattern is why, for the first time in its 29-year history, Black Hat USA 2026 hosted a dedicated Healthcare Cybersecurity Summit – built in formal partnership with HIMSS, the Healthcare Information and Management Systems Society, in the first-ever collaboration between the two organizations. The full-day program, held August 4, 2026 in Las Vegas, brought hospital CISOs, healthcare IT professionals, and clinical leaders together around a single theme: resilience and clinical-disruption response. When the offensive-security community and the healthcare-IT establishment convene their first joint summit, the signal is clear – this is being treated as one of the most urgent problems in the sector.

Small providers are not too small to be a target
A common and dangerous assumption in small practices is that attackers only chase the big fish. The opposite is increasingly true. Modern ransomware campaigns are largely automated and opportunistic; they scan for exposed remote-access ports, unpatched systems, and reused credentials, and they do not check the size of your business before striking. Worse, small healthcare providers are frequently connected to the same shared vendors, billing platforms, imaging clouds, and managed-service tools as much larger organizations – which means a practice can be swept up in an attack aimed elsewhere, or targeted precisely because it is seen as a softer path into a larger network. Being small is not camouflage. It is often the reason you are chosen.
The rules are about to change: the HIPAA Security Rule update
Regulators have reached the same conclusion the researchers did, and the compliance landscape is shifting to match. In January 2025, the US Department of Health and Human Services published a Notice of Proposed Rulemaking – the first proposed update to the HIPAA Security Rule in more than a decade. It would convert several long-recommended safeguards from voluntary “addressable” guidance into enforceable requirements, including multi-factor authentication, encryption of patient data at rest and in transit, annual penetration testing, and network segmentation. As of August 2026 the final rule has not been issued, with the Office of Management and Budget now targeting July 2027 for finalization.

For Canadian practices, HIPAA is not the governing law – PHIPA is – but the direction of travel is identical, and the technical controls are simply modern security hygiene regardless of jurisdiction. The practices that treat this proposed rule as a preview rather than a distant American formality will be the ones that are ready, not scrambling, when their own regulators, insurers, and cyber-insurance underwriters ask the same questions. Cyber-insurance renewals, in particular, already demand MFA and tested backups as a condition of coverage.
What a dental practice should do now
The good news is that the safeguards that protect patients are the same ones that protect the business, and none of them require a hospital budget. Turn on multi-factor authentication everywhere it is available – email, remote access, practice-management logins, and cloud imaging – because it is the single most effective barrier against the stolen-credential attacks that start most incidents. Segment the network so that imaging devices, the front-desk workstations, guest Wi-Fi, and the server are not all sitting on one flat network where malware can move freely from a compromised laptop to your database. Keep backups offline or immutable and test that they actually restore, so an attack becomes a bad afternoon rather than a closed practice. Patch promptly, especially anything exposed to the internet. And build a simple downtime plan – a printed emergency protocol for how the office keeps patients safe if the systems are unavailable, so that being offline is a rehearsed contingency, not a crisis.
The reframing at the heart of this year’s research is the part worth keeping: in healthcare, cybersecurity is no longer just about protecting data. It is about protecting the continuity of care that patients depend on. A dental practice sits squarely inside that reality.
Compudent Systems helps dental practices across the GTA and Ontario get ahead of exactly these requirements – deploying multi-factor authentication, segmenting practice networks so imaging and workstations are properly isolated, hardening remote access, and building tested backup and downtime plans that keep a practice running through an incident. If you are not confident your office could keep patients safe and its records intact through an attack, contact Compudent Systems for a security and resilience assessment measured against the standards healthcare is now adopting. It is far better to prepare for this on your own schedule than on an attacker’s.
Sources & further reading: