Already a member or subscriber? Sign in now

Cybersecurity Preparedness and Resiliency in a Family Medicine Clinic

MARSHALL FRIEDEN, MD
ISABEL STRAW, MD, BMBS, MPH, PhD
NICOLAS KAHL, MD
NATHAN YUNG, MD
GRANT MADDEN
CHRISTIAN DAMEFF, MD, MS
JEFFREY TULLY, MD

FPM. 2025;32(3):26-30.

Author disclosures: no relevant financial relationships.

With ransomware attacks increasingly targeting health care institutions, practices must protect themselves by developing a cybersecurity response plan.

cybersecurity prep

Cyberattacks targeting health care organizations have increased in scope and impact over the last decade. These include “ransomware” attacks in which hackers lock organizations out of their own internet-connected files, systems, or networks until they pay a ransom. These attacks disrupt patient care and stress regional health care ecosystems.1,2

The February 2024 cyberattack on Change Healthcare, a UnitedHealth Group subsidiary, demonstrated how such attacks can not only impact one hospital or health system but also ripple across all health care sectors due to consolidation in the industry. While much of the literature focuses on cyberattacks disrupting care for acute emergencies such as heart attack, stroke, or sepsis, they can also cause serious problems for patient health and clinic finances in primary care.3,4 Family medicine clinics increasingly rely on systems connected to the internet — EHRs, pharmacy portals, laboratory systems, clinical image viewers, etc. — and the abrupt absence of these tools can drastically disrupt workflows if the practice is not prepared. Scheduled downtime intended for brief updates to computer systems is not sufficient preparation for cyberattacks, which can affect multiple technological systems for weeks or even months with no warning.5,6

Preventing cyberattacks requires a detailed, multipronged approach that is beyond the scope of this article (for that, we recommend this 2023 federal report. Below, we offer guidance on how practices can keep patient care and revenue flowing even if a cyberattack causes prolonged tech outages.

KEY POINTS

  • Cyberattacks on health care organizations are increasing, and family medicine clinics should prepare for the possibility of prolonged technological outages.
  • Practices should create a cybersecurity plan that identifies work-flows with tech vulnerabilities and outlines technology-independent backup plans.
  • Practices should test their cybersecurity plan each year with a simulated cyberattack and update the plan as they introduce new technology.

CREATING A CYBERSECURITY RESPONSE PLAN

Clinics should prepare for the possibility of cyberattacks by creating a cybersecurity response plan, which involves the following:

1. Identify workflows with tech vulnerabilities. List the key workflows your practice follows before, during, and after a patient visit, and identify those that rely on internet-connected systems. This includes scheduling patients, accessing their contact information, checking patients in and out, processing orders (for referrals, labs, imaging, medications/refills, etc.), documenting visits, billing payers and patients, and reporting quality metrics.

Dr. Frieden is a family physician and clinical informatics fellow at UC San Diego Health.

Dr. Straw is an emergency physician and assistant professor of healthcare artificial intelligence and cybersecurity at University College London.

Dr. Kahl is an emergency physician and clinical informatics fellow at UC San Diego Health.

Dr. Yung is an internal medicine physician at UC San Diego Health.

Grant Madden is emergency manager at the UC San Diego Center for Healthcare Cybersecurity.

Dr. Dameff is an emergency medicine physician and assistant professor in the Department of Medicine Division of Biomedical Informatics at UC San Diego Health.

Dr. Tully is an associate clinical professor of anesthesiology at the UC San Diego School of Medicine and co-director of the UC San Diego Center for Healthcare Cybersecurity.

Send comments to fpmedit@aafp.org, or add your comments to the article online.

Author disclosures: no relevant financial relationships.

  1. 1.Neprash HT, McGlave CC, Cross DA, et al. Trends in ransomware attacks on U.S. hospitals, clinics, and other health care delivery organizations, 2016–2021. JAMA Health Forum. 2022;3(12):e224873.
  2. 2.Dameff C, Tully J, Chan TC, et al. Ransomware attack associated with disruptions at adjacent emergency departments in the U.S. JAMA Netw Open. 2023;6(5):e2312270.
  3. 3.Pham TT, Loo TM, Malhotra A, et al. Ransomware cyberattack associated with cardiac arrest incidence and outcomes at untargeted, adjacent hospitals. Crit Care Explor. 2024;6(4):e1079.
  4. 4.Turner N. Family physicians: first point of contact, last line of defence. Can Fam Physician. 2023;69(7):490-491.
  5. 5.Abbou B, Kessel B, Ben Natan M, et al. When all computers shut down: the clinical impact of a major cyber-attack on a general hospital. Front Digit Health. 2024;6:1321485.
  6. 6.Neprash HT, McGlave CC, Rydberg K, Henning-Smith C. What happens to rural hospitals during a ransomware attack? Evidence from Medicare data. J Rural Health. 2024;40(4):728-737.
  7. 7.Alder S. HIPAA encryption requirements. The HIPAA Journal. Jan. 9, 2025. Accessed Feb. 25, 2025. https://www.hipaajournal.com/hipaa-encryption-requirements/
  8. 8.Romanovs A, Sultanovs E, Buss E, Merkuryev Y, Majore G. Challenges and solutions for resilient telemedicine services. Proceedings of the 2020 IEEE 8th Workshop on Advances in Information, Electronic and Electrical Engineering. Vilnius, Lithuania. https://www.researchgate.net/publication/351795369_Challenges_and_Solutions_for_Resilient_Telemedicine_Services
  9. 9.Duffy C, Murray C, Boran G, Srinivasan R, Kane A, Leonard A. Survey of Laboratory Medicine’s national response to the HSE cyberattack in the Republic of Ireland. Ir J Med Sci. 2024;193(2):889-896.
  10. 10.NHS England. Weekly data on the impact of the Synnovis cyber-attack. Accessed Jan. 15, 2025. https://www.england.nhs.uk/london/synnovis-ransomware-cyber-attack/weekly-data/
  11. 11.Nelson CJ, Soisson ET, Li PC, et al. Impact of and response to cyberattacks in radiation oncology. Adv Radiat Oncol. 2022;7(5):100897.
  12. 12.Vasco N. Offline credit card processing: how to accept payments offline. Gravity Payments. July 5, 2023. Accessed Feb. 21, 2025. https://gravitypayments.com/blog/offline-credit-card-processing/
  13. 13.Straw I, Brass I, Mkwashi A, Charles I, Soares A, Steer C. Insights from a clinically orientated workshop on health care cybersecurity and medical technology: observational study and thematic analysis. J Med Internet Res. 2024;26:e50505.
  14. 14.Maggio LA, Dameff C, Kanter SL, Woods B, Tully J. Cybersecurity challenges and the academic health center: an interactive tabletop simulation for executives. Acad Med. 2021;96(6):850-853.

Copyright © 2026 by the American Academy of Family Physicians.

This content is owned by the AAFP. A person viewing it online may make one printout of the material and may use that printout only for his or her personal, non-commercial reference. This material may not otherwise be downloaded, copied, printed, stored, transmitted or reproduced in any medium, whether now known or later invented, except as authorized in writing by the AAFP. See permissions for copyright questions and/or permission requests.