Lead

When calls started streaming into Romania's national cyber-security centre about hospitals being hit by ransomware, officials faced a stark choice. Cyber-chief Dan Cimpean ordered more than 100 hospitals to disconnect from the internet, a move that halted the attackers' spread but forced medical staff to revert to pen and paper.

The attack, which began on 10 February 2024, targeted a widely used medical software system called Hippocrates, which was breached through Bucharest-based firm RSC. The ransomware strain, known as BackMyData, infected 26 hospitals and demanded a ransom of €160,000 in bitcoin, according to multiple reports.

Coverage comparison

The BBC's reporting, which was the sole source for this article, describes the incident as one of the worst healthcare cyber-attacks globally. The coverage focuses on the rapid response by Romanian authorities and the subsequent reliance on manual procedures.

Key claims

  • Attack scope: The ransomware hit at least 26 hospitals, with more than 100 hospitals intentionally disconnected from the internet as a containment measure.
  • Software breach: The Hippocrates medical system, used for patient management and clinical workflows, was compromised via the software provider RSC.
  • Ransom demand: Attackers sought €160,000 in bitcoin; Romanian authorities decided not to pay, a choice that was widely reported.
  • Recovery and impact: No deaths or serious patient harm were reported. The use of regular backups allowed some organisations to recover more quickly, though this claim was noted by only one source.

Perspectives

Official and institutional viewpoint

Romania's DNSC co-ordinated the response, and its director Dan Cimpean was central to the decision to cut off hospitals. Officials have emphasised that the move bought critical time and contained the spread.

Medical staff perspective

Surgeons like Oana Goidescu described the disruption as deeply challenging, as all digital records—from lab requests to medication orders—were suddenly inaccessible. Despite the difficulties, staff improvised and adapted.

Broader security context

The FBI has highlighted healthcare as the most targeted critical national infrastructure sector. This incident underscores the growing threat and the importance of contingency planning.

Analysis

While the BBC's reporting is detailed and credible, it is the only source used in this analysis. The claim about backups aiding recovery was mentioned by a single source and carries medium confidence. The broader assessment of the attack's significance, however, appears well-supported.

The decision to go offline, though drastic, has been widely praised. It highlights a practical tension: disconnecting systems can stop attackers, but it also halts digital healthcare operations. The Romanian experience offers lessons for other countries, but it also raises questions about the sustainability of such measures in longer crises.

As cyber threats to healthcare grow, the incident serves as a reminder that robust backup systems and manual fallback procedures are not just best practice—they can be essential in an emergency.