Ransomware Has Become an Operating-Room Problem
A surgery center can have perfect sterile technique, outstanding surgeons and beautifully negotiated payer contracts and still become functionally useless because somebody clicked the wrong email.
Cybersecurity is now patient safety.
On July 29, HHS’s Office for Civil Rights announced its 21st ransomware enforcement action, settling a HIPAA investigation involving an Illinois-based healthcare system. Earlier in 2026, OCR announced four additional ransomware settlements involving breaches affecting more than 427,000 individuals. OCR’s repeated message has been remarkably consistent: healthcare organizations are expected to perform an accurate and thorough risk analysis and address vulnerabilities before an attack occurs, not explain afterward why they never knew the vulnerability existed.
This is especially relevant to surgery centers because our technology footprint has exploded. EHRs, anesthesia records, PACS, implant systems, medication dispensing, cloud scheduling, electronic claims, remote access and vendor portals all create entry points. The center may have only two operating rooms, but digitally it can have hundreds of doors.
HHS has also rolled out a 2026 cybersecurity module within its RISC 2.0 Toolkit. The tool scores an organization’s cyber posture against the NIST Cybersecurity Framework 2.0 and HHS Healthcare and Public Health Cybersecurity Performance Goals. HHS’s recommended fundamentals include vulnerability management, endpoint protection, strong encryption, prompt revocation of credentials for departing workers and better control of third-party vulnerabilities.
Here is the practical ASC test: if your computer network went dark at 7:00 tomorrow morning, could you safely operate at 7:30? Could you verify allergies? Access the medication list? Print the schedule? Document anesthesia? Identify implants? Contact every patient? Submit claims afterward?
If the answer is no, your disaster plan is incomplete.
We spend enormous amounts preparing for fires that may never occur. A cyberattack is a fire that can start in every computer simultaneously.

