Hospital Cyberattacks: Part XII: A Personal Encounter

EDITOR’S NOTE: Edward Roche, in association with RACmonitor, is writing a series of articles on the need for U.S. healthcare facilities to protect themselves from cybercriminals demanding ransoms for patient records. This is the twelfth installment in the series.

It all started innocently enough.

Dr. Wang said my EKG looked “a little off,” but she could not pin down anything specific. They ordered up my previous EKGs from six years ago. “There is a slight change,” she said. “I think you should have a cardio stress test.”

“What’s that?”

The medical community calls it a “stress test;” I call it the “radioactive rat track torture.” You are hooked up with so many wires you look like Robocop. Then, on command, you start running on the treadmill, just like a rat. There were encouraging words from the attending physician: “the treadmill always wins.”

I get going along at a brisk pace, and they inject radioactive dyes into my blood. “Don’t go near children for three days,” I’m told. “We will give you a pass in case you set off a bomb detector at the airport.” Comforting thoughts.

Then there was imaging, then more of the “radioactive rat track torture,” then more radiation injections and more imaging. 

“The test is not conclusive,” I am told. “Let us know what your cardiologist says.”

Back to Dr. Wang. “I suspect something, but nothing shows up,” she says. “I think you should go to the cath lab for an examination.” 

“What’s that?”

“Oh, it’s a simple procedure. They look into your heart with a camera and if something is wrong, they fix it. It is an outpatient procedure. Easy in, easy out.” She explained the procedure further. “They are going to do what?”

So, I start calling around. To my surprise, most of my buddies have had it done already. My high school friend Benny: “it’s nothing to worry about, I’ve had it done five or six times. The only problem is the mental effects, heh heh.”

With me sulking through similar feelings as an inmate on death row, the surgery day finally arrives. The hospital sends a car and driver for me. It is 5:50 a.m., but the Italian chauffeur from Jersey starts a cheerful conversation. “So you’re going to get your pipes blown out, right?”

I arrive at the hospital, but the information booth does not know where to direct me. “Our computer is slow today.” After wandering around the halls for a while like a medical refugee, I find the right place.

“Here, fill out this form.”

Then more waiting, then on to the next step, the preparation room. They ask me a few questions and log the data into paper forms. “We are having problems with our computers today,” I’m told. “Most people are working with a pencil.” I didn’t give it much thought.

They do an EKG, but the first one looks like modern art because the machine goes haywire and its needles seem to have a mind of their own. It resembled an original Jackson Pollock painting. “Perhaps we should try it again.”

“OK, wait and someone will call you.”

And they did.

Up to the next floor, all of your shoes and clothes go into a bag, and there’s the donning of those goofy hospital covers that leave your backside exposed. Hospital attire is in serious need of a makeover.

Then I’m in the holding pen. “We will move you into surgery as soon as a room is available.” They said that five times, each time with no effect.

Then the time comes. “Ready to go?”

They begin to roll the bed, then stop dead in their tracks. A physician’s assistant (PA) runs up. “There is no blood test!” 

No can believe it. “How could this happen?”

It’s the computer, stupid.

The hospital had been hit with a cyberattack. They were operating in paper mode. The prep team did not have a computer to tell them that a blood test was needed.

Then more delays. What should have been an “in and out” procedure turned into 48 hours.

The medical professionals continued to go about their work, but with less certainty than before.

We depend on computers too much of the time.

“If my case had been urgent,” I thought to myself, “the hacker would have killed me.”

This series on cyber security will return to its regular themes in the next issue of RACmonitor.

Yes, the author is still with us.

Facebook
Twitter
LinkedIn

Edward M. Roche, PhD, JD

Edward Roche is the director of scientific intelligence for Barraclough NY, LLC. Mr. Roche is also a member of the California Bar. Prior to his career in health law, he served as the chief research officer of the Gartner Group, a leading ICT advisory firm. He was chief scientist of the Concours Group, both leading IT consulting and research organizations. Mr. Roche is a member of the RACmonitor editorial board as an investigative reporter and is a popular panelist on Monitor Mondays.

Related Stories

Leave a Reply

Please log in to your account to comment on this article.

Featured Webcasts

Proactive Denial Management: Data-Driven Strategies to Prevent Revenue Loss

Denials continue to delay reimbursement, increase administrative burden, and threaten financial stability across healthcare organizations. This essential webcast tackles the root causes—rising payer scrutiny, fragmented workflows, inconsistent documentation, and underused analytics—and offers proven, data-driven strategies to prevent and overturn denials. Attendees will gain practical tools to strengthen documentation and coding accuracy, engage clinicians effectively, and leverage predictive analytics and AI to identify risks before they impact revenue. Through real-world case examples and actionable guidance, this session empowers coding, CDI, and revenue cycle professionals to shift from reactive appeals to proactive denial prevention and revenue protection.

November 19, 2025
Sepsis: Bridging the Clinical Documentation and Coding Gap to Reduce Denials

Sepsis: Bridging the Clinical Documentation and Coding Gap to Reduce Denials

Sepsis remains one of the most frequently denied and contested diagnoses, creating costly revenue loss and compliance risks. In this webcast, Angela Comfort, DBA, MBA, RHIA, CDIP, CCS, CCS-P, provides practical, real-world strategies to align documentation with coding guidelines, reconcile Sepsis-2 and Sepsis-3 definitions, and apply compliant queries. You’ll learn how to identify and address documentation gaps, strengthen provider engagement, and defend diagnoses against payer scrutiny—equipping you to protect reimbursement, improve SOI/ROM capture, and reduce audit vulnerability in this high-risk area.

September 24, 2025
2026 IPPS Masterclass 3: Master MS-DRG Shifts and NTAPs

2026 IPPS Masterclass Day 3: MS-DRG Shifts and NTAPs

This third session in our 2026 IPPS Masterclass will feature a review of FY26 changes to the MS-DRG methodology and new technology add-on payments (NTAPs), presented by nationally recognized ICD-10 coding expert Christine Geiger, MA, RHIA, CCS, CRC, with bonus insights and analysis from Dr. James Kennedy.

August 14, 2025

Trending News

Featured Webcasts

Surviving Federal Audits for Inpatient Rehab Facility Services

Surviving Federal Audits for Inpatient Rehab Facility Services

Federal auditors are zeroing in on Inpatient Rehabilitation Facility (IRF) and hospital rehab unit services, with OIG and CERT audits leading to millions in penalties—often due to documentation and administrative errors, not quality of care. Join compliance expert Michael Calahan, PA, MBA, to learn the five clinical “pillars” of IRF-PPS admissions, key documentation requirements, and real-life case lessons to help protect your revenue.

November 13, 2025
E/M Services Under Intensive Federal Scrutiny: Navigating Split/Shared, Incident-to & Critical Care Compliance in 2025-2026

E/M Services Under Intensive Federal Scrutiny: Navigating Split/Shared, Incident-to & Critical Care Compliance in 2025-2026

During this essential RACmonitor webcast Michael Calahan, PA, MBA Certified Compliance Officer, will clarify the rules, dispel common misconceptions, and equip you with practical strategies to code, document, and bill high-risk split/shared, incident-to & critical care E/M services with confidence. Don’t let audit risks or revenue losses catch your organization off guard — learn exactly what federal auditors are looking for and how to ensure your documentation and reporting stand up to scrutiny.

August 26, 2025
The Two-Midnight Rule: New Challenges, Proven Strategies

The Two-Midnight Rule: New Challenges, Proven Strategies

RACmonitor is proud to welcome back Dr. Ronald Hirsch, one of his most requested webcasts. In this highly anticipated session, Dr. Hirsch will break down the complex Two Midnight Rule Medicare regulations, translating them into clear, actionable guidance. He’ll walk you through the basics of the rule, offer expert interpretation, and apply the rule to real-world clinical scenarios—so you leave with greater clarity, confidence, and the tools to ensure compliance.

June 19, 2025

Trending News

Happy National Doctor’s Day! Learn how to get a complimentary webcast on ‘Decoding Social Admissions’ as a token of our heartfelt appreciation! Click here to learn more →

CYBER WEEK IS HERE! Don’t miss your chance to get 20% off now until Dec. 2 with code CYBER24