AndDDoS All articles
Threat Intelligence & Business Risk

Flatlined Defenses: The DDoS Threat Overwhelming American Hospitals Before Anyone Is Ready

AndDDoS
Flatlined Defenses: The DDoS Threat Overwhelming American Hospitals Before Anyone Is Ready

Photo: hospital cybersecurity network threat healthcare IT infrastructure digital, via api.coarchitects.com

In October 2023, a coordinated DDoS campaign struck multiple US hospital systems simultaneously, forcing several facilities to revert to paper-based workflows, divert emergency patients to alternative locations, and suspend elective procedures for days. The attackers—a pro-Russian hacktivist group operating under the banner Killnet—did not breach patient records or encrypt a single file. They simply flooded networks until the digital infrastructure supporting modern clinical care became unusable.

The incident received significant press coverage for approximately seventy-two hours. Then the news cycle moved on. The hospitals, quietly, began the slow work of rebuilding confidence in systems that had failed them. The structural vulnerabilities that made those attacks possible remained almost entirely intact.

This is the quiet crisis in American healthcare cybersecurity: not a dramatic breach, not a single catastrophic event, but a persistent, widening gap between the threat environment and the defensive capabilities of an industry that has been chronically under-resourced for exactly this moment.

Why Healthcare Lags So Far Behind

The comparison to financial services is instructive and uncomfortable. Major US banks began investing seriously in DDoS mitigation infrastructure following the Operation Ababil campaigns of 2012 and 2013, when Iranian-linked actors targeted Bank of America, JPMorgan Chase, and others with sustained volumetric floods. The attacks were damaging, but they catalyzed a sector-wide response: dedicated scrubbing capacity, upstream provider relationships, sophisticated traffic analysis platforms, and coordinated threat intelligence sharing through FS-ISAC.

No comparable catalyst and no comparable response emerged in healthcare.

The reasons are structural rather than attitudinal. Hospital systems in the United States operate under margin pressures that most industries would find unsustainable. The American Hospital Association reported that more than half of US hospitals operated at a financial loss in 2022. Capital expenditure decisions in that environment are dominated by clinical equipment, facility maintenance, and staffing—not network security infrastructure.

IT departments at many regional and community hospital systems are staffed at levels that would be considered inadequate for a mid-sized law firm. Security operations functions, where they exist at all, are frequently handled by generalist IT staff without dedicated cybersecurity training. The concept of a 24/7 security operations center, standard in financial services, is a distant aspiration for the majority of US healthcare institutions.

The Operational Stakes Are Different Here

In most industries, a successful DDoS attack is a business continuity problem. In healthcare, it is a patient safety problem. That distinction is not rhetorical—it is clinically documented.

A 2023 study published in the Journal of the American Medical Association examined outcomes at hospitals that had experienced significant ransomware-related outages and found measurable increases in in-hospital mortality during disruption periods. While the study focused on ransomware rather than DDoS specifically, the operational disruptions are functionally similar: clinical staff lose access to electronic health records, imaging systems go offline, medication dispensing systems become unavailable, and communication infrastructure degrades.

Anonymized incident reports reviewed for this article describe DDoS events at US hospital systems that resulted in the following: emergency department physicians manually tracking patient vitals on whiteboards; pharmacists unable to verify drug orders against patient allergy records in real time; radiology departments operating on delayed or unavailable imaging; and ambulance diversion protocols activated for facilities that remained physically operational but digitally incapacitated.

None of these outcomes appear in the DDoS attack statistics that security vendors publish. They appear, weeks later, in quality review processes and, occasionally, in adverse event reports filed with state health departments.

The Regulatory Framework Has Not Caught Up

The Health Insurance Portability and Accountability Act (HIPAA) security rule, the primary federal framework governing healthcare cybersecurity, was written in an era when DDoS was not a significant clinical threat. Its requirements center on confidentiality and integrity of protected health information—not on the availability of operational systems under volumetric attack.

The Department of Health and Human Services has issued guidance and voluntary performance goals related to cybersecurity, and the HHS Office for Civil Rights has increased enforcement activity around general security posture. But no federal requirement currently compels hospital systems to maintain minimum DDoS mitigation capabilities, document their scrubbing arrangements, or report DDoS incidents within a defined timeframe.

This regulatory gap has consequences. Without mandatory disclosure, the true frequency and severity of DDoS attacks against US healthcare systems is unknown even to federal agencies tasked with protecting critical infrastructure. CISA's healthcare sector advisories reflect the intelligence that is voluntarily shared—which security professionals across the sector describe as a fraction of what actually occurs.

Proposed updates to the HIPAA security rule, published in late 2024, introduce more prescriptive technical requirements and would establish stronger baseline expectations for healthcare cybersecurity. Whether those requirements will adequately address availability threats—as distinct from confidentiality threats—remains an open question among healthcare security practitioners.

What Threat Actors Know That Administrators Don't

Hacktivist groups and ransomware operators have demonstrated, through their targeting patterns, a sophisticated understanding of healthcare's defensive weaknesses. Hospitals are attractive targets for DDoS campaigns for several compounding reasons: their operational tolerance for network disruption is extremely low, creating immediate pressure to comply with demands or accept devastating operational consequences; their IT teams are typically not staffed for sustained incident response; and their public-facing infrastructure—patient portals, scheduling systems, telehealth platforms—is often hosted on infrastructure with minimal DDoS protection.

Additionally, the reputational and regulatory consequences of a healthcare DDoS event can be severe enough to generate extortion leverage even without any data exfiltration. Attackers have learned that a hospital willing to pay to avoid ransomware encryption may also be willing to pay to restore clinical operations after a sustained flood—particularly if the alternative is patient diversion and regulatory scrutiny.

What Healthcare Leaders Must Demand Right Now

The path forward is not a single investment or a single policy change. It is a sustained, prioritized commitment to closing a gap that has been allowed to widen for years. Healthcare security leaders and hospital administrators should be pressing their security vendors and internal teams on the following:

Upstream DDoS Mitigation Contracts: Hospital systems should have explicit contractual arrangements with their internet service providers or dedicated DDoS mitigation providers—not assumptions that upstream providers will handle volumetric attacks on a best-effort basis. The distinction matters enormously during an active attack.

Clinical System Segmentation: Networks supporting electronic health records, imaging, and medication management should be architecturally separated from internet-facing systems in ways that limit the blast radius of a volumetric attack on public-facing infrastructure.

Incident Response Planning That Includes DDoS: Most hospital incident response plans address ransomware and data breach scenarios. Far fewer include specific runbooks for DDoS events—including clinical downtime procedures, communication protocols, and escalation paths to ISP and mitigation provider contacts.

Participation in Health-ISAC: The Health Information Sharing and Analysis Center provides sector-specific threat intelligence that is directly relevant to the DDoS threat landscape. Membership and active participation represent among the highest-return security investments available to healthcare organizations operating under budget constraints.

Board-Level Visibility: The DDoS threat to healthcare operations is a patient safety issue and a fiduciary issue. Hospital boards that are not receiving regular briefings on network availability threats are operating with an incomplete picture of institutional risk.

The Time for Quiet Crisis Has Passed

American healthcare has absorbed DDoS attacks with a combination of improvised resilience and public silence. That approach is not sustainable. The threat actors targeting hospitals are not reducing their ambitions, and the operational consequences of successful attacks are not diminishing as clinical systems become more deeply networked and more operationally critical.

The financial services sector did not build its DDoS defenses out of altruism. It built them because regulators demanded it, because customers expected it, and because the operational and reputational consequences of failure were deemed unacceptable. Healthcare needs to arrive at the same conclusion—before the next campaign makes the decision for it.

All Articles

Related Articles

Signal or Noise: The Forensic Science of Distinguishing Nation-State DDoS From Criminal Opportunism

Signal or Noise: The Forensic Science of Distinguishing Nation-State DDoS From Criminal Opportunism

Double Tap: How Cybercriminals Are Weaponizing DDoS Floods to Smuggle Ransomware Past Your Defenses

Escalation Protocol: Tracing Five Years of DDoS Evolution From Protest Tool to Geopolitical Weapon