Hospital Cyberattacks: Part XII: A Personal Encounter

EDITOR’S NOTE: Edward Roche, in association with RACmonitor, is writing a series of articles on the need for U.S. healthcare facilities to protect themselves from cybercriminals demanding ransoms for patient records. This is the twelfth installment in the series.

It all started innocently enough.

Dr. Wang said my EKG looked “a little off,” but she could not pin down anything specific. They ordered up my previous EKGs from six years ago. “There is a slight change,” she said. “I think you should have a cardio stress test.”

“What’s that?”

The medical community calls it a “stress test;” I call it the “radioactive rat track torture.” You are hooked up with so many wires you look like Robocop. Then, on command, you start running on the treadmill, just like a rat. There were encouraging words from the attending physician: “the treadmill always wins.”

I get going along at a brisk pace, and they inject radioactive dyes into my blood. “Don’t go near children for three days,” I’m told. “We will give you a pass in case you set off a bomb detector at the airport.” Comforting thoughts.

Then there was imaging, then more of the “radioactive rat track torture,” then more radiation injections and more imaging. 

“The test is not conclusive,” I am told. “Let us know what your cardiologist says.”

Back to Dr. Wang. “I suspect something, but nothing shows up,” she says. “I think you should go to the cath lab for an examination.” 

“What’s that?”

“Oh, it’s a simple procedure. They look into your heart with a camera and if something is wrong, they fix it. It is an outpatient procedure. Easy in, easy out.” She explained the procedure further. “They are going to do what?”

So, I start calling around. To my surprise, most of my buddies have had it done already. My high school friend Benny: “it’s nothing to worry about, I’ve had it done five or six times. The only problem is the mental effects, heh heh.”

With me sulking through similar feelings as an inmate on death row, the surgery day finally arrives. The hospital sends a car and driver for me. It is 5:50 a.m., but the Italian chauffeur from Jersey starts a cheerful conversation. “So you’re going to get your pipes blown out, right?”

I arrive at the hospital, but the information booth does not know where to direct me. “Our computer is slow today.” After wandering around the halls for a while like a medical refugee, I find the right place.

“Here, fill out this form.”

Then more waiting, then on to the next step, the preparation room. They ask me a few questions and log the data into paper forms. “We are having problems with our computers today,” I’m told. “Most people are working with a pencil.” I didn’t give it much thought.

They do an EKG, but the first one looks like modern art because the machine goes haywire and its needles seem to have a mind of their own. It resembled an original Jackson Pollock painting. “Perhaps we should try it again.”

“OK, wait and someone will call you.”

And they did.

Up to the next floor, all of your shoes and clothes go into a bag, and there’s the donning of those goofy hospital covers that leave your backside exposed. Hospital attire is in serious need of a makeover.

Then I’m in the holding pen. “We will move you into surgery as soon as a room is available.” They said that five times, each time with no effect.

Then the time comes. “Ready to go?”

They begin to roll the bed, then stop dead in their tracks. A physician’s assistant (PA) runs up. “There is no blood test!” 

No can believe it. “How could this happen?”

It’s the computer, stupid.

The hospital had been hit with a cyberattack. They were operating in paper mode. The prep team did not have a computer to tell them that a blood test was needed.

Then more delays. What should have been an “in and out” procedure turned into 48 hours.

The medical professionals continued to go about their work, but with less certainty than before.

We depend on computers too much of the time.

“If my case had been urgent,” I thought to myself, “the hacker would have killed me.”

This series on cyber security will return to its regular themes in the next issue of RACmonitor.

Yes, the author is still with us.

Facebook
Twitter
LinkedIn

Edward M. Roche, PhD, JD

Edward Roche is the director of scientific intelligence for Barraclough NY, LLC. Mr. Roche is also a member of the California Bar. Prior to his career in health law, he served as the chief research officer of the Gartner Group, a leading ICT advisory firm. He was chief scientist of the Concours Group, both leading IT consulting and research organizations. Mr. Roche is a member of the RACmonitor editorial board as an investigative reporter and is a popular panelist on Monitor Mondays.

Related Stories

Leave a Reply

Please log in to your account to comment on this article.

Featured Webcasts

2026 ICD-10-CM/PCS Coding Clinic Update Webcast Series

Uncover essential coding insights with nationally recognized coding authority Kay Piper, RHIA, CDIP, CCS. Through ICD10monitor’s interactive, on‑demand webcast series, Kay walks you through the AHA’s 2026 ICD‑10‑CM/PCS Quarterly Coding Clinics, translating each update into practical, easy‑to‑apply guidance designed to sharpen precision, ensure compliance, and strengthen day‑to‑day decision‑making. Available shortly after each official release.

April 13, 2026

2026 ICD-10-CM/PCS Coding Clinic Update: Fourth Quarter

Uncover critical guidance on the ICD-10-CM/PCS code updates. Kay Piper reviews and explains ICD-10-CM/PCS coding guidelines in the AHA’s fourth quarter 2026 ICD-10-CM/PCS Coding Clinic in an easy to access on-demand webcast.

December 14, 2026

2026 ICD-10-CM/PCS Coding Clinic Update: Third Quarter

Uncover critical guidance on the ICD-10-CM/PCS code updates. Kay Piper reviews and explains ICD-10-CM/PCS coding guidelines in the AHA’s third quarter 2026 ICD-10-CM/PCS Coding Clinic in an easy to access on-demand webcast.

October 12, 2026

2026 ICD-10-CM/PCS Coding Clinic Update: Second Quarter

Uncover critical guidance on the ICD-10-CM/PCS code updates. Kay Piper reviews and explains ICD-10-CM/PCS coding guidelines in the AHA’s second quarter 2026 ICD-10-CM/PCS Coding Clinic in an easy to access on-demand webcast.

July 13, 2026

Trending News

Featured Webcasts

Compliance for the Inpatient Psychiatric Facility (IPF-PPS): Minimizing Federal Audit Findings by Strengthening Best Practices

Federal auditors are intensifying their focus on inpatient psychiatric facilities, using advanced data analytics to spotlight outliers and pursue high‑dollar repayments. In this high‑impact webcast, Michael Calahan, PA, MBA, Compliance Officer and V.P., Hospital & Physician Compliance, breaks down what regulators are really targeting in IPF-PPS admissions, documentation, treatment and discharge planning. Attendees will learn practical steps to tighten processes, avoid common audit triggers and protect reimbursement and reduce the risk of multimillion-dollar repayment demands.

April 9, 2026

Mastering MDM for Accurate Professional Fee Coding

In this timely session, Stacey Shillito, CDIP, CPMA, CCS, CCS-P, CPEDC, COPC, breaks down the complexities of Medical Decision Making (MDM) documentation so providers can confidently capture the true complexity of their care. Attendees will learn practical, efficient strategies to ensure documentation aligns with current E/M guidelines, supports accurate coding, and reduces audit risk, all without adding to charting time.

March 31, 2026

The PEPPER Returns – Risk and Opportunity at Your Fingertips

Join Ronald Hirsch, MD, FACP, CHCQM for The PEPPER Returns – Risk and Opportunity at Your Fingertips, a practical webcast that demystifies the PEPPER and shows you how to turn complex claims data into actionable insights. Dr. Hirsch will explain how to interpret key measures, identify compliance risks, uncover missed revenue opportunities, and understand new updates in the PEPPER, all to help your organization stay ahead of audits and use this powerful data proactively.

March 19, 2026

Top 10 Audit Targets for 2026-2027 for Hospitals & Physicians: Protect Your Revenue

Stay ahead of the 2026-2027 audit surge with “Top 10 Audit Targets for 2026-2027 for Hospitals & Physicians: Protect Your Revenue,” a high-impact webcast led by Michael Calahan, PA, MBA. This concise session gives hospitals and physicians clear insight into the most likely federal audit targets, such as E/M services, split/shared and critical care, observation and admissions, device credits, and Two-Midnight Rule changes, and shows how to tighten documentation, coding, and internal processes to reduce denials, recoupments, and penalties. Attendees walk away with practical best practices to protect revenue, strengthen compliance, and better prepare their teams for inevitable audits.

January 29, 2026

Trending News

Happy National Doctor’s Day! Learn how to get a complimentary webcast on ‘Decoding Social Admissions’ as a token of our heartfelt appreciation! Click here to learn more →

CYBER WEEK IS HERE! Don’t miss your chance to get 20% off now until Dec. 1 with code CYBER25

CYBER WEEK IS HERE! Don’t miss your chance to get 20% off now until Dec. 2 with code CYBER24