Security Guides
The hospitals stayed open; what stopped was everything connecting them to the outside — four 2026 hospital cyberattacks and what patients and providers should do
Four hospitals whose care was disrupted by cyberattacks in 2026 (UMMC, AZ Monica, Signature Healthcare, Nippon Medical School Musashi Kosugi), compared from their own statements: what patients should do when their hospital announces an outage, and how to plan downtime procedures.
For: patients and families worried because their hospital has announced a "system outage" or "cyberattack", and the people who run IT at hospitals and clinics. This article compares the hospitals' and health authorities' own statements as primary sources and does not cover attack techniques.
First: if your hospital announces an outage (patients and families)
If you searched for a hospital's name, you probably want to know what happens to your care. These steps are based on what these hospitals actually told patients.
Check the official website or social media for what continues and what has stopped
The scope differs by hospital. UMMC's published updates repeatedly stated that its hospitals and emergency departments remained open while clinics were closed. Signature Healthcare said inpatient care and walk-in emergency services continued, but ambulances were diverted and chemotherapy was cancelled. AZ Monica lost its own website and, according to reporting, set up an emergency website with a general phone number and FAQs. Check the hospital's official site, or a main phone number you looked up yourself.
Wait for the hospital to call about appointments; use the designated line for urgent needs
Each hospital said it would contact patients to reschedule cancelled appointments. AZ Monica, according to reporting, phoned every patient whose appointment was cancelled, and UMMC said clinics would run extended hours and days to catch up. Some needs cannot wait: UMMC opened an automated triage phone line for time-sensitive needs and said it would prioritize medication refills and post-operative care visits.
If your medication is running low, ask early, and keep a list
Signature Healthcare's retail pharmacies stayed open for consultation but were unable to fill prescriptions; the hospital announced on April 24 that pharmacy operations had reopened (in the meantime, it gave a phone number for medication questions). When a hospital's systems are down, its own staff may not be able to see your prescription history quickly. As this site's own suggestion: keep a list (or a photo) of your current medications, doses and allergies. It speeds things up if you have to see another doctor or pharmacy.
If you need emergency care, call emergency services as usual
All four hospitals kept an emergency department open. But Signature Healthcare diverted ambulance traffic for a time, and at AZ Monica, according to reporting, the mobile emergency team stopped going out and other hospitals covered under the provincial emergency plan. Ambulance crews handle where you go. There is no reason to hesitate to call because your usual hospital is down.
Beware of calls, texts and letters claiming to be the hospital
Nippon Medical School Musashi Kosugi Hospital states that it never asks patients for credit card numbers or passwords by phone, and warns patients about suspicious calls, text messages and postcards. After an incident, messages using the hospital's name can follow. For anything about refunds, re-registration or identity checks, hang up and call back on a number you looked up yourself (background: What is phishing?).
Four hospitals whose care stopped in 2026
The following is based on each hospital's statements (for AZ Monica, reporting by Belgian public broadcaster VRT that quotes the hospital). The word "ransomware" is used only for Musashi Kosugi Hospital, which described the attack that way itself.
| Hospital (country) | Started / found | What stopped | What continued | Back to normal |
|---|---|---|---|---|
| AZ Monica (Antwerp, Belgium) | January 13, 2026 | All servers shut down as a precaution; planned surgery cancelled; about 70 patients sent home and 7 transferred; imaging such as MRI; mobile emergency team | Emergency department (reduced), consultations, day hospital, oncology unit and more | About 30% of planned care the next day, then 50% for the time being; electronic records restarted about three weeks later |
| Nippon Medical School Musashi Kosugi Hospital (Kawasaki, Japan) | Discovered February 9, 2026 | Nurse-call system (3 servers, 1 ward terminal); personal data of about 130,000 patients leaked | Outpatient, inpatient and emergency care as usual | Nurse-call system back to normal as of the fifth notice (February 27) |
| University of Mississippi Medical Center (US) | February 19, 2026 | All network systems shut down as a precaution; electronic health record, clinics statewide, elective procedures, phones and email | Hospitals and EDs in four locations; one dialysis clinic | EHR back February 28; clinics reopened March 2 |
| Signature Healthcare / Brockton Hospital (US) | April 6, 2026 | Ambulance intake, chemotherapy (April 7), pharmacy dispensing, patient portal, medical records requests | Inpatient care, walk-in emergency, surgery and endoscopy, physician practices (with delays) | Ambulances again from April 15; pharmacies reopened April 24 |
Don't rank the four by 'which was worst'
The four differ in size, in how much they shut down, and in how much detail they published. UMMC and AZ Monica shut down their own networks or servers as a precaution. A wider shutdown looks like a bigger impact, but it is also a decision to stop the damage from spreading. What this site compares is not the size of the damage but what stopped and what continued on paper.
What each hospital said
- What
- On January 13, 2026, both campuses were hit by a cyberattack and all servers were shut down as a precaution. According to what the hospital told VRT, staff could not reach patient data in the electronic records, so imaging such as MRI scans could not be done. The hospital's website was also unreachable
- Patients
- According to reporting, about 70 patients were sent home and 7 were transferred to other hospitals. Hospital management said only very urgent operations would go ahead. Patients whose appointments were cancelled were phoned. The mobile emergency team stopped going out and other hospitals covered under the provincial emergency plan; the emergency department kept running at reduced capacity
- Recovery
- About 30% of planned care went ahead on January 14. At a press conference the hospital announced it would run at 50% of normal capacity across both campuses for the time being. About three weeks later the electronic patient records were restarted, and reporting says the hospital began re-entering three weeks of paper records into them
- Data
- The hospital said it had no indication at the time that patient data had been taken
- What
- The hospital said part of its medical information systems was hit by a ransomware attack. It was discovered around 1:50 a.m. on February 9 when the ward nurse-call equipment malfunctioned; the affected systems and network were cut off
- Route (hospital's statement)
- "Unauthorized access exploiting a vulnerability in a VPN appliance used for medical device maintenance." The attackers entered through the VPN appliance on January 26, and on January 29 took the database on the nurse-call server via a ward terminal. The hospital says it confirmed that the data was later published on a site run by the attackers
- Leaked
- About 130,000 outpatients and inpatients (patient ID, name, sex, address, phone number, date of birth), and about 1,700 staff and clinical-training medical students. No leak of medical records, credit card data or My Number card data has been confirmed
- Why it spread
- The nurse-call server was designed so that basic patient data was sent and stored automatically whenever it was updated, whether or not the patient had ever been admitted, which the hospital says widened the scope
- Prevention
- Prompt application of VPN appliance updates, external connections changed to on-demand only in principle, source-address restrictions, new administrator passwords, settings that stop an intruder from moving sideways inside the hospital, and multifactor authentication
- What
- A cyberattack on its network on February 19, 2026 (a staff memo called it a "criminal attack"). As a precaution, all network systems were shut down, with risk assessments before bringing anything back. The Emergency Operations Plan was activated, working with the FBI, Homeland Security and other agencies
- Stopped
- All clinics statewide closed and elective procedures cancelled (one dialysis clinic stayed open). The electronic health record was down, and phones and email worked only intermittently
- Continued
- Hospitals and emergency departments in Jackson, Grenada, Madison County and Holmes County stayed open using downtime procedures. By February 20 the ED was off diversion and emergent surgeries were being performed
- Patients
- An automated triage line for time-sensitive needs, prioritizing medication refills and post-operative care visits. Patients receiving time-sensitive care such as chemotherapy were contacted by the hospital
- Recovery
- The EHR came back on February 28 and clinics resumed on Monday, March 2, with extended hours and days to reschedule cancelled appointments
- What
- On April 6, 2026, after identifying suspicious activity within a portion of its network, the health system activated its incident response protocols and moved to downtime procedures
- Stopped
- Ambulance intake (diverted), chemotherapy on April 7, pharmacy dispensing, the patient portal, and medical records requests. Lab work continued but could be delayed
- Continued
- Inpatient care, walk-in emergency services, surgery and endoscopy, physician practices and urgent care (with delays)
- Recovery
- Chemotherapy resumed for new patients and was phased in for existing patients under safety protocols. On April 15 at 8:00 a.m. the hospital lifted its Code Black status and began receiving ambulances again; pharmacies reopened on April 24
The pattern: the outer ring stopped
Center: continued under downtime procedures
Inpatient care, walk-in emergency, urgent surgery (paper records)
↓ everything outside this stopped
Outpatient and scheduling
Clinic closures, appointment phones, patient portal
Medication and ongoing treatment
Pharmacy dispensing, chemotherapy schedules
Link to ambulance services
Ambulance intake, mobile emergency team
Data-dependent diagnostics
Imaging such as MRI, returning results
Easily missed entry points and data stores
VPN appliances for device maintenance / a nurse-call server that quietly collects patient data
What continued on paper
- Inpatient care: paper records and orders (UMMC, Signature Healthcare)
- Walk-in emergency care: the ED stayed open at all four
- Surgery: emergent surgery (UMMC), scheduled surgery and endoscopy (Signature)
What was hard to run on paper
- Scheduling and contact: the list of who to call and when lives inside the system
- Medication: prescription history, stock and dispensing records
- Chemotherapy: treatment plans (regimens) and previous-cycle records
- Imaging: both acquisition and results are tied to the EHR
This site's view: patient data also piles up outside the 'clinical systems'
What this site weighs most in the Musashi Kosugi case is not the entry point but why the damage spread. The hospital explains that the nurse-call server was designed to receive and store basic patient data automatically, whether or not the patient had ever been admitted. Basic data on about 130,000 patients had accumulated on a device outside the electronic medical record that few would think of as a place where patient data is kept.
The same thing happens when downtime procedures are written. Most hospitals have "if the EHR goes down, switch to paper". But the appointment call lists, chemotherapy schedules, pharmacy prescription history and the line to ambulance services live in other systems and other departments. That is exactly what stopped in these four cases. This site believes both what to protect and what to run on paper should be decided from a map of where patient data actually flows.
Japan has seen the same pattern
In Japan, Tsurugi Town Handa Hospital (2021) and Osaka General Medical Center (2022) lost their electronic medical records and had care restricted for a long time. The investigation reports in both cases pointed to internet-facing VPN equipment as the way in; in Osaka it was a remote-maintenance VPN device used by the hospital's meal-service contractor (details: Tsurugi Handa Hospital ransomware (2021) and Osaka General Medical Center ransomware (2022)). In 2026, Musashi Kosugi Hospital's entry point was again a VPN appliance for medical device maintenance. Across five years, the recurring way in is not the hospital's core systems but a connection opened for maintenance or a contractor. How to defend VPN appliances in general is covered in Why VPN appliances are a top entry point and how to defend them.
What hospital and clinic IT teams can do today
In June 2026, Japan's Ministry of Health, Labour and Welfare (MHLW) revised its Guidelines for the Security Management of Medical Information Systems to version 7.0 (succeeding version 6.0 of May 2023). Its checklist for medical institutions and pharmacies (FY2026 edition) asks institutions to work toward "yes" on every item within FY2026 and says it will be checked during on-site inspections. In the US, the Department of Health and Human Services (HHS) publishes the healthcare and public health Cybersecurity Performance Goals (HPH CPGs) and, with industry, the 405(d) Health Industry Cybersecurity Practices (HICP). The steps below map those official items onto what stopped in the four cases.
Write downtime procedures for the outer ring
Go beyond "record on paper instead of the EHR". Write who does what, with what, for notifying patients of cancellations, chemotherapy schedules, pharmacy dispensing, telling ambulance services whether you can accept patients, and what patients see when the portal is down. MHLW publishes a checklist, guide and template for a business continuity plan (BCP) that assumes a cyberattack, and its overview of the revision calls for preparing "alternatives such as paper operation" and regular drills. A first step: ask outpatient, pharmacy and oncology, "If every system were down tomorrow morning, what would you need to look at in the first hour?" Any answer that exists only inside a system is a procedure you need to write.
Keep the information needed to continue care offline
Item 3-2 of the MHLW checklist asks whether you have "considered the information needed to continue care during an incident, secured backups of it, and confirmed the recovery procedure". The revision overview lists offline backups and recovery drills as ransomware measures. Concretely: regularly export the inpatient list with medications and allergies, today's and next week's appointments, and chemotherapy schedules to a place disconnected from the network. Backup basics are in Backup and recovery essentials.
Budget time for re-entering what was written on paper
After restarting its electronic records, AZ Monica, according to reporting, began re-entering three weeks of paper records. Downtime does not end the day systems return. Decide in advance who does the back-entry, how long it may take, and which record — paper or electronic — is authoritative until it is done.
Inventory remote-maintenance connections and end always-on access
MHLW checklist item 2-2 asks whether you have confirmed with vendors which devices use remote maintenance; item 2-14 asks for connection-source restrictions on network devices. As prevention measures, Musashi Kosugi Hospital switched external connections to on-demand only in principle and applied source-address restrictions. The maintenance lines to target first are those installed for medical devices, catering or lab equipment without going through the IT department. For every VPN appliance you find, assign someone to receive update notices and patch it, in line with checklist item 2-6 (apply security patches) and the HHS goal "Mitigate Known Vulnerabilities".
Separate medical devices and departmental systems from office IT
The MHLW overview calls for layered defense through network separation, multifactor authentication and access control, and the HHS goals include "Network Segmentation". Musashi Kosugi Hospital also listed settings that stop an intruder from moving sideways inside the hospital. A practical target: allow only necessary traffic from the zones holding nurse-call, patient monitors and imaging equipment to office PCs and the internet. At the same time, check which patient data is stored on the servers in those zones, device by device.
Switch it off once a year
UMMC told its staff that its fast recovery was the result of its security environment and measures already in place. Written procedures do not run themselves. A half-day "no systems" drill in one outpatient department will surface missing contact lists and paper forms before a real incident does.
For patients and families: the most immediate risk is the follow-on 'call from the hospital'
In the Musashi Kosugi case, names, addresses, phone numbers and dates of birth were leaked. With those, someone can make convincing calls, texts or postcards. The hospital states that it does not ask for card numbers or passwords by phone. If you are asked about refunds, re-registration or identity checks, hang up and call back on a number you looked up yourself — that alone stops most of it.
Sources (public record)
The facts in this article come from the hospitals' and government agencies' statements below, and from reporting that quotes the hospital. Undisclosed attackers and intrusion methods are not speculated on.
- Nippon Medical School Musashi Kosugi Hospital, report and apology regarding the personal data leak from a cyberattack (fifth notice, February 27, 2026, Japanese) — nms.ac.jp
- University of Mississippi Medical Center, Campus Memo, "Update on UMMC cyberattack" (February 19, 2026) — umc.edu
- UMMC, "UMMC Cyberattack Update" (February 20, 2026) — umc.edu
- UMMC, "UMMC Cyberattack Update" (February 21, 2026) — umc.edu
- UMMC, "Cyberattack Update" (February 23, 2026: patient triage line) — umc.edu
- UMMC, "Feb. 25 Cyberattack Update" (February 25, 2026) — umc.edu
- UMMC, "Cyberattack Update" (February 27, 2026: EHR and clinics resuming) — umc.edu
- Signature Healthcare, "Alert Announcements" (updates from April 6 to April 24, 2026) — signature-healthcare.org
- VRT NWS (Belgian public broadcaster, Dutch), January 13, 2026: first report including the hospital's statements — vrt.be
- VRT NWS, January 14, 2026: 50% capacity announced at a press conference — vrt.be
- VRT NWS, February 5, 2026: electronic patient records restarted — vrt.be
- MHLW, Guidelines for the Security Management of Medical Information Systems, version 7.0 (June 2026), with checklist and BCP materials (Japanese) — mhlw.go.jp
- MHLW, cybersecurity checklist for medical institutions and pharmacies (June 2026, Japanese) — mhlw.go.jp
- MHLW, overview and main changes of guideline version 7.0 (Japanese) — mhlw.go.jp
- US Department of Health and Human Services, "HPH Cybersecurity Performance Goals" — hhscyber.hhs.gov
- HHS 405(d), "Health Industry Cybersecurity Practices (HICP) 2023 Edition" highlights — 405d.hhs.gov
Update history
2026-09-30: First version, based on the four hospitals' statements (for AZ Monica, VRT reporting that quotes the hospital), MHLW guideline version 7.0 and its FY2026 checklist, and public HHS materials.
Read next
- Japanese hospital cases: Tsurugi Handa Hospital ransomware (2021) / Osaka General Medical Center ransomware (2022)
- The entry point: Why VPN appliances are a top entry point and how to defend them
- Preparing for downtime: Backup and recovery essentials
- Terms: What is ransomware? / What is phishing?
- Other 2026 incidents: list of breaches and cyberattacks (Japan and worldwide)
- For organizations: The minimum security baseline for organizations
FAQ
QWhich hospitals had care disrupted by cyberattacks in 2026?
According to the hospitals' statements and reporting, they include AZ Monica in Antwerp, Belgium (January 13, 2026: servers shut down as a precaution, surgeries cancelled), Nippon Medical School Musashi Kosugi Hospital in Japan (discovered February 9: its nurse-call system was hit and personal data of about 130,000 patients leaked), the University of Mississippi Medical Center in the US (February 19: clinics statewide closed for more than a week), and Signature Healthcare in Massachusetts (April 6: ambulances diverted, chemotherapy and pharmacy dispensing paused).
QWhat should patients do if their hospital is hit by a cyberattack?
1) Check the hospital's official website or social media to see which services continue and which have stopped. 2) Wait for the hospital to contact you about appointments, and use the hospital's designated line for urgent needs such as medication refills or post-operative visits (UMMC set up a phone line that prioritized exactly those). 3) Call emergency services (911 in the US, 112 in Europe, 119 in Japan) as usual if you need them. 4) Do not give card numbers or passwords to callers or texts claiming to be the hospital (Musashi Kosugi Hospital states it never asks for them by phone).
QCan a hospital keep its emergency department and wards running during a cyberattack?
In these four cases, according to the hospitals' statements and reporting, inpatient and emergency care continued. UMMC and Signature Healthcare said they kept inpatient and emergency services running under downtime procedures — paper and other alternative methods. However, Signature Healthcare diverted ambulances for a time, and at AZ Monica, according to reporting, the mobile emergency team stopped going out and other hospitals covered under the provincial emergency plan. Walk-in patients may still be seen while ambulances go elsewhere, which is worth knowing.
QHow did the attackers get into Musashi Kosugi Hospital?
According to the hospital's fifth notice (February 27, 2026), the route was 'unauthorized access exploiting a vulnerability in a VPN appliance used for medical device maintenance'. The attackers entered through the VPN appliance on January 26 and, on January 29, took the database on the nurse-call server via a ward terminal. The hospital says the nurse-call server was designed to receive and store basic patient data automatically whenever it was updated, regardless of whether the patient had ever been admitted, which widened the scope. It confirmed there was no unauthorized access to core systems such as the electronic medical record.
QWhere should a hospital or clinic start?
Official checklists are a practical starting point. Japan's Ministry of Health, Labour and Welfare checklist for medical institutions and pharmacies (FY2026 edition) asks whether you have confirmed with vendors which devices use remote maintenance, restricted connection sources on network devices, applied security patches, secured backups of the information needed to continue care with a tested recovery procedure, and written a business continuity plan that assumes a cyberattack; it is checked during on-site inspections. In the US, HHS publishes the healthcare Cybersecurity Performance Goals and the 405(d) HICP practices. On top of those, this site recommends writing paper workflows for outpatient clinics, the pharmacy, chemotherapy and appointment phones, not only the wards.