Evidence map›Paper›PMID 42809354›Full record

SynthesisJournal of medical Internet research2026

Unveiling Patient-Level Harms and At-Risk Clinical Groups During Hospital Cyberattacks: Systematic Review of Global Case Studies and Social Media Data.

Isabel Straw, Deepak Kumar, Seoyoung Kweon, Jordan Selzer, Christian Dameff, Jeffrey Tully

Abstract readSystematic Review
In one paragraph

Synthesis in Journal of medical Internet research, 2026. The graph could read no effect estimate from its abstract, so it casts no vote on the map. Not yet cited in PubMed.

0numbers the graph read from it
0cells of the map it votes in
0citing papers in PubMed
–field-weighted citation impact
1 · What the graph read from it

What it found

Each row is one number read from the abstract, on the scale the paper reported it, with its interval. Left of the dashed line favours the treatment, right favours the comparator. Under each row is the sentence it came from. New to these charts? A ten-minute tutorial.

The abstract states no effect estimate the extractor could read, or names no intervention and outcome on the map, so this paper lights no cell and moves no belief. It is still indexed, cited and linked below.

2 · The registry

The trial behind it

Trials whose registry record cites this paper, or whose number appears in the abstract. A trial that started after this paper was published is citing it as background, not reporting it.

Neither the registry nor the abstract names a trial number. If this is a trial report, that itself is worth knowing.

3 · Its place in the literature

Who cites it

0 citing papers in PubMed.

No citing paper in PubMed yet.

4 · The record

Corrections and comments

PubMed lists nothing against this paper. Absence here is not a guarantee, only a check that was made.

5 · Who and what money

Authors and funding

6 authors.

Isabel StrawDepartment of Computer Science and Engineering, University of California San Diego, 9500 Gilman Dr, San Diego, CA, 92093, United States, 1 858-534-2230.ORCID http://orcid.org/0000-0003-0003-3550
Deepak KumarDepartment of Computer Science and Engineering, University of California San Diego, 9500 Gilman Dr, San Diego, CA, 92093, United States, 1 858-534-2230.ORCID http://orcid.org/0000-0002-0224-5031
Seoyoung KweonDepartment of Computer Science and Engineering, University of California San Diego, 9500 Gilman Dr, San Diego, CA, 92093, United States, 1 858-534-2230.ORCID http://orcid.org/0009-0006-2120-3570
Jordan SelzerDepartment of Emergency Medicine, George Washington University, Washington, DC, United States.ORCID http://orcid.org/0000-0002-0051-6600
Christian DameffDepartment of Emergency Medicine, University of California San Diego, San Diego, CA, United States.ORCID http://orcid.org/0000-0001-9613-2603
Jeffrey TullyDepartment of Anesthesia, University of California San Diego, San Diego, CA, United States.ORCID http://orcid.org/0000-0002-3537-6716

Funding

No grant is acknowledged in the PubMed record.

6 · The paper itself

Abstract

Background: Cyberattacks against health care organizations are rising in frequency and shifting in nature from data theft to intentional denial of care. Objective: This systematic review identifies and characterizes patient-level harms occurring during hospital cyberattacks across international settings, determines which clinical populations are most vulnerable, and compares patient-level harms reported in peer-reviewed case studies with those described in patient and provider narratives on social media. Methods: Following PRISMA (Preferred Reporting Items for Systematic Reviews and Meta-Analyses) 2020, PRISMA-S (Preferred Reporting Items for Systematic Reviews and Meta-Analyses-Search), and the SWiM (Synthesis Without Meta-analysis) reporting guidelines, we searched MEDLINE, Embase, PubMed, Scopus, and Web of Science for peer-reviewed studies published between January 1, 2004, and July 1, 2026 describing cyberattacks affecting clinical care in health care delivery organizations. Quantitative synthesis was not performed because the included studies reported structurally incompatible outcome types for which no common effect measure existed; synthesis without meta-analysis was conducted according to SWiM. In parallel, a Python (Python Software Foundation) pipeline mined 3408 health care-related subreddits for cyberattack terms extracted during the academic review; posts were reviewed by clinical team members to ensure relevance and coded to clinical specialties and technical failure domains. Results: Fifty-nine studies were included, from which 316 patient-level harms were identified across the combined datasets. Two distinct categories of at-risk patients emerged: those harmed by time-criticality, including patients with stroke, cardiac arrest, and major trauma, for whom delays of minutes to hours are clinically decisive; and those harmed by the intersection of digital dependence and potential for rapid clinical decline, including patients with cancer, patients with diabetes, and those dependent on community prescribing. Specific technical failures were linked to distinct clinical consequences, including those stemming from (1) hardware (oncological harms due to compromised linear accelerators), (2) software (risks for patients with fractures due to failures in digital templating software), and (3) networks/connectivity (fetal deaths due to telemetry failures). Social media data exposed wider harms resulting from infrastructural issues, including compromised door access systems preventing life-saving treatment, failures in ward-based alarms, and closed-circuit television (CCTV) affecting staff/patient safety, and disrupted health-at-home services preventing community therapies. Conclusions: Our study is the first to systematically integrate global case study evidence with large-scale social media data to provide a clinically focused synthesis of patient-level harms during health care cyberattacks. The resulting open-source Cyberattack Impacts, Patient Harms & Emergency Response (CIPHER) dataset links technical failure domains to downstream clinical risks across care settings. As cyberattacks on health care organizations continue to rise in frequency and severity, the boundary between cybersecurity and patient safety has become increasingly blurred, demanding unified frameworks that treat digital resilience and clinical preparedness as inseparable expressions of the same obligation to patients.

Indexed as

Computer SecurityHospitalsHumansSocial MediacyberattackscybersecurityDigital healthmedical informaticsPRISMApublic health

Identifiers

PMID42809354
PMCPMC13622069

What OpenQuestion holds

Textmetadata
Read underepoch 390

Registered trials

None linked

Read under generation 80e0d062 · epoch 390. Bibliography from PubMed, PubMed Central and OpenAlex; grants from NIH RePORTER; trial links from ClinicalTrials.gov; estimates, votes and beliefs from the OpenQuestion graph.