{"id":58413,"date":"2025-04-02T11:36:11","date_gmt":"2025-04-02T11:36:11","guid":{"rendered":"https:\/\/www.threatshub.org\/blog\/for-healthcare-orgs-disaster-recovery-means-making-sure-docs-can-save-lives-during-ransomware-infection\/"},"modified":"2025-04-02T11:36:11","modified_gmt":"2025-04-02T11:36:11","slug":"for-healthcare-orgs-disaster-recovery-means-making-sure-docs-can-save-lives-during-ransomware-infection","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/for-healthcare-orgs-disaster-recovery-means-making-sure-docs-can-save-lives-during-ransomware-infection\/","title":{"rendered":"For healthcare orgs, disaster recovery means making sure docs can save lives during ransomware infection"},"content":{"rendered":"<p>When IT disasters strike, it can become a matter of life and death for healthcare organizations \u2013 and criminals know it.<\/p>\n<p>We\u2019re not exaggerating the risks: In 2024 a successful ransomware attack on a Texas trauma hospital saw it <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2024\/09\/30\/texan_hospital_ransomware\/\" rel=\"noopener\">turn away ambulances<\/a> &#8211; and that was just one of <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2024\/10\/24\/ransomware_ripple_effect_hospitals\/\" rel=\"noopener\">hundreds of known ransomware infections<\/a> at US hospitals.<\/p>\n<p>Then there was the <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2024\/11\/20\/change_healthcares_clearinghouse_services\/\" rel=\"noopener\">Change Healthcare intrusion<\/a> that paralyzed claims and payment systems for weeks across hundreds of thousands of medical clinics, hospitals, and pharmacies in the US. That disaster left many Americans unable to acquire prescription medicine as usual.<\/p>\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"top\" data-raptor=\"condor\" data-xsm=\",fluid,mpu,\" data-sm=\",fluid,mpu,\" data-md=\",fluid,mpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_specialfeatures\/disasterrecoveryweek&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2Z-0zEchjMqSpetA9D9I6WgAAAYI&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_specialfeatures\/disasterrecoveryweek&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2Z-0zEchjMqSpetA9D9I6WgAAAYI&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<p>&#8220;Healthcare organizations have a uniquely high-stakes environment when it comes to disaster recovery due to the sensitivity of data and the life-or-death nature of their services,&#8221; said Sherrod DeGrippo, Microsoft&#8217;s director of threat intelligence strategy.<\/p>\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"top\" data-raptor=\"falcon\" data-xmd=\",fluid,mpu,leaderboard,\" data-lg=\",fluid,mpu,leaderboard,\" data-xlg=\",fluid,billboard,superleaderboard,mpu,leaderboard,\" data-xxlg=\",fluid,billboard,superleaderboard,brandwidth,brandimpact,leaderboard,mpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_specialfeatures\/disasterrecoveryweek&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44Z-0zEchjMqSpetA9D9I6WgAAAYI&amp;t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_specialfeatures\/disasterrecoveryweek&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44Z-0zEchjMqSpetA9D9I6WgAAAYI&amp;t=ct%3Dns%26unitnum%3D426raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<div class=\"adun_eagle_desktop_story_wrapper\">\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"mid\" data-raptor=\"eagle\" data-xxlg=\",mpu,dmpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_specialfeatures\/disasterrecoveryweek&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33Z-0zEchjMqSpetA9D9I6WgAAAYI&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_specialfeatures\/disasterrecoveryweek&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33Z-0zEchjMqSpetA9D9I6WgAAAYI&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<\/p><\/div>\n<p>&#8220;Unfortunately, threat actors know this well and take advantage of this reality,&#8221; she added. &#8220;Healthcare organizations are often specifically targeted by ransomware actors because of their unique requirements and patient risks.&#8221;<\/p>\n<blockquote class=\"pullquote\" readability=\"6\">\n<p>Healthcare organizations are often targeted by ransomware actors because of their unique requirements and patient risks<\/p>\n<\/blockquote>\n<p>Those distinct risks healthcare providers face mean they are more likely to pay ransoms quickly, rather than attempt ransomware recovery.<\/p>\n<p>Ty Greenhalgh, industry principal of healthcare at infrastructure resilience outfit Claroty and also an ambassador for a US Department of Health and Human Services <a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/405d.hhs.gov\/about\">task force<\/a> on cybersecurity in healthcare, has an example that illustrates why healthcare orgs pay up.<\/p>\n<p>&#8220;Somebody comes in for a stroke. You can&#8217;t tell whether it&#8217;s ischemic or hemorrhagic, one&#8217;s a bleed, one&#8217;s a clot,&#8221; Greenhalgh explained to <i>The Register<\/i>. \u201cYou don&#8217;t know what medicine to give, and you got an hour before this person&#8217;s not walking, let alone dying. When you are hit with ransom and your systems are out, you are more likely to pay.&#8221;<\/p>\n<h3 class=\"crosshead\">Crims target data to protect their own health<\/h3>\n<p>Taylor Lehmann, a director for Google Cloud&#8217;s Office of the CISO, thinks criminal gangs understand that putting patients&#8217; lives at risk will draw unwelcome attention.<\/p>\n<p>\u201cIf you do that enough, the FBI and law enforcement are going to come after you,&#8221; Lehmann said. &#8220;Threat actors make more money when law enforcement doesn&#8217;t come after them and shut them down.&#8221;<\/p>\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"top\" data-raptor=\"falcon\" data-xsm=\",fluid,mpu,\" data-sm=\",fluid,mpu,\" data-md=\",fluid,mpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_specialfeatures\/disasterrecoveryweek&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44Z-0zEchjMqSpetA9D9I6WgAAAYI&amp;t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_specialfeatures\/disasterrecoveryweek&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44Z-0zEchjMqSpetA9D9I6WgAAAYI&amp;t=ct%3Dns%26unitnum%3D426raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<p>Criminals\u2019 behavior is therefore changing. \u201cWe&#8217;re not seeing quite as much targeting of critical healthcare systems with the goal of shutting them down and then extracting a ransom payment,&#8221; Lehmann told <i>The Register<\/i>. &#8220;The threat has become more focused on acquiring data and extorting the organization.&#8221;<\/p>\n<p>&#8220;Threat actors will continue to make more money by not necessarily taking organizations down, but extorting them seems to compel payment just as easily,&#8221; he added.<\/p>\n<h3 class=\"crosshead\">The best DR medicines<\/h3>\n<p>Healthcare orgs seeking to inoculate themselves against IT disasters should start with plans to continue service delivery even if systems go down.<\/p>\n<p>&#8220;Clinical staff need clear protocols for working offline, like manual charting or printed medication schedules,&#8221; Microsoft\u2019s DeGrippo said. &#8220;In healthcare, disaster recovery is really about both technical resilience and patient care continuity.&#8221;<\/p>\n<p>On the technical side, she recommends paying special attention to legacy devices for which assistance may be harder to find. DeGrippo also thinks Internet-of-Things devices and operational technology systems deserve special attention.<\/p>\n<div aria-hidden=\"true\" class=\"adun\" id=\"story_eagle_xsm_sm_md_xmd_lg_xlg\" data-pos=\"mid\" data-raptor=\"eagle\" data-xsm=\",mpu,dmpu,\" data-sm=\",mpu,dmpu,\" data-md=\",mpu,dmpu,\" data-xmd=\",mpu,dmpu,\" data-lg=\",mpu,dmpu,\" data-xlg=\",mpu,dmpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_specialfeatures\/disasterrecoveryweek&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33Z-0zEchjMqSpetA9D9I6WgAAAYI&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_specialfeatures\/disasterrecoveryweek&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33Z-0zEchjMqSpetA9D9I6WgAAAYI&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<p>&#8220;Recovery plans need to include ways to safely isolate or restore those,&#8221; DeGrippo added.<\/p>\n<p>Google\u2019s Lehmann thinks healthcare orgs should start by identifying critical assets and understanding all their dependencies. He recommends \u201dfirst mitigating threats to resilience, and then threats to total system loss.\u201d<\/p>\n<p>To preserve availability of some healthcare hardware, buying multiple systems is likely necessary.<\/p>\n<p>&#8220;The only viable plan for many of the systems is just to have two of them,&#8221; Lehmann said. &#8220;Many of them are set up a specific way, a lot of them are out of support or end-of-life, so they can&#8217;t be replaced or the vendor can&#8217;t swoop in and add a new one without disrupting clinical flow.&#8221;<\/p>\n<p>Not only do orgs need a plan, but they also need to practice it.<\/p>\n<p>Lehmann suggests tabletop exercises that simulate losses to key systems, including calling up vendors and seeing how quickly they can reproduce the system. &#8220;Measure the timelines it takes for them to do so and get ahead of what the costs might be in the event that those things happen.&#8221; \u00ae<\/p>\n<p> READ MORE <a href=\"https:\/\/go.theregister.com\/feed\/www.theregister.com\/2025\/04\/02\/disaster_recovery_healthcare\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Organizational, technological resilience combined defeat the disease that is cybercrime When IT disasters strike, it can become a matter of life and death for healthcare organizations \u2013 and criminals know it.\u2026 READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[],"class_list":["post-58413","post","type-post","status-publish","format-standard","hentry","category-the-register"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>For healthcare orgs, disaster recovery means making sure docs can save lives during ransomware infection 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/for-healthcare-orgs-disaster-recovery-means-making-sure-docs-can-save-lives-during-ransomware-infection\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"For healthcare orgs, disaster recovery means making sure docs can save lives during ransomware infection 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/for-healthcare-orgs-disaster-recovery-means-making-sure-docs-can-save-lives-during-ransomware-infection\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2025-04-02T11:36:11+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_specialfeatures\/disasterrecoveryweek&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2Z-0zEchjMqSpetA9D9I6WgAAAYI&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/for-healthcare-orgs-disaster-recovery-means-making-sure-docs-can-save-lives-during-ransomware-infection\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/for-healthcare-orgs-disaster-recovery-means-making-sure-docs-can-save-lives-during-ransomware-infection\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"For healthcare orgs, disaster recovery means making sure docs can save lives during ransomware infection\",\"datePublished\":\"2025-04-02T11:36:11+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/for-healthcare-orgs-disaster-recovery-means-making-sure-docs-can-save-lives-during-ransomware-infection\\\/\"},\"wordCount\":738,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/for-healthcare-orgs-disaster-recovery-means-making-sure-docs-can-save-lives-during-ransomware-infection\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/pubads.g.doubleclick.net\\\/gampad\\\/ad?co=1&amp;iu=\\\/6978\\\/reg_specialfeatures\\\/disasterrecoveryweek&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2Z-0zEchjMqSpetA9D9I6WgAAAYI&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\",\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/for-healthcare-orgs-disaster-recovery-means-making-sure-docs-can-save-lives-during-ransomware-infection\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/for-healthcare-orgs-disaster-recovery-means-making-sure-docs-can-save-lives-during-ransomware-infection\\\/\",\"name\":\"For healthcare orgs, disaster recovery means making sure docs can save lives during ransomware infection 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/for-healthcare-orgs-disaster-recovery-means-making-sure-docs-can-save-lives-during-ransomware-infection\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/for-healthcare-orgs-disaster-recovery-means-making-sure-docs-can-save-lives-during-ransomware-infection\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/pubads.g.doubleclick.net\\\/gampad\\\/ad?co=1&amp;iu=\\\/6978\\\/reg_specialfeatures\\\/disasterrecoveryweek&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2Z-0zEchjMqSpetA9D9I6WgAAAYI&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\",\"datePublished\":\"2025-04-02T11:36:11+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/for-healthcare-orgs-disaster-recovery-means-making-sure-docs-can-save-lives-during-ransomware-infection\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/for-healthcare-orgs-disaster-recovery-means-making-sure-docs-can-save-lives-during-ransomware-infection\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/for-healthcare-orgs-disaster-recovery-means-making-sure-docs-can-save-lives-during-ransomware-infection\\\/#primaryimage\",\"url\":\"https:\\\/\\\/pubads.g.doubleclick.net\\\/gampad\\\/ad?co=1&amp;iu=\\\/6978\\\/reg_specialfeatures\\\/disasterrecoveryweek&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2Z-0zEchjMqSpetA9D9I6WgAAAYI&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\",\"contentUrl\":\"https:\\\/\\\/pubads.g.doubleclick.net\\\/gampad\\\/ad?co=1&amp;iu=\\\/6978\\\/reg_specialfeatures\\\/disasterrecoveryweek&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2Z-0zEchjMqSpetA9D9I6WgAAAYI&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/for-healthcare-orgs-disaster-recovery-means-making-sure-docs-can-save-lives-during-ransomware-infection\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"For healthcare orgs, disaster recovery means making sure docs can save lives during ransomware infection\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"For healthcare orgs, disaster recovery means making sure docs can save lives during ransomware infection 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/for-healthcare-orgs-disaster-recovery-means-making-sure-docs-can-save-lives-during-ransomware-infection\/","og_locale":"en_US","og_type":"article","og_title":"For healthcare orgs, disaster recovery means making sure docs can save lives during ransomware infection 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/for-healthcare-orgs-disaster-recovery-means-making-sure-docs-can-save-lives-during-ransomware-infection\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2025-04-02T11:36:11+00:00","og_image":[{"url":"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_specialfeatures\/disasterrecoveryweek&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2Z-0zEchjMqSpetA9D9I6WgAAAYI&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/for-healthcare-orgs-disaster-recovery-means-making-sure-docs-can-save-lives-during-ransomware-infection\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/for-healthcare-orgs-disaster-recovery-means-making-sure-docs-can-save-lives-during-ransomware-infection\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"For healthcare orgs, disaster recovery means making sure docs can save lives during ransomware infection","datePublished":"2025-04-02T11:36:11+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/for-healthcare-orgs-disaster-recovery-means-making-sure-docs-can-save-lives-during-ransomware-infection\/"},"wordCount":738,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/for-healthcare-orgs-disaster-recovery-means-making-sure-docs-can-save-lives-during-ransomware-infection\/#primaryimage"},"thumbnailUrl":"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_specialfeatures\/disasterrecoveryweek&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2Z-0zEchjMqSpetA9D9I6WgAAAYI&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0","articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/for-healthcare-orgs-disaster-recovery-means-making-sure-docs-can-save-lives-during-ransomware-infection\/","url":"https:\/\/www.threatshub.org\/blog\/for-healthcare-orgs-disaster-recovery-means-making-sure-docs-can-save-lives-during-ransomware-infection\/","name":"For healthcare orgs, disaster recovery means making sure docs can save lives during ransomware infection 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/for-healthcare-orgs-disaster-recovery-means-making-sure-docs-can-save-lives-during-ransomware-infection\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/for-healthcare-orgs-disaster-recovery-means-making-sure-docs-can-save-lives-during-ransomware-infection\/#primaryimage"},"thumbnailUrl":"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_specialfeatures\/disasterrecoveryweek&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2Z-0zEchjMqSpetA9D9I6WgAAAYI&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0","datePublished":"2025-04-02T11:36:11+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/for-healthcare-orgs-disaster-recovery-means-making-sure-docs-can-save-lives-during-ransomware-infection\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/for-healthcare-orgs-disaster-recovery-means-making-sure-docs-can-save-lives-during-ransomware-infection\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/for-healthcare-orgs-disaster-recovery-means-making-sure-docs-can-save-lives-during-ransomware-infection\/#primaryimage","url":"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_specialfeatures\/disasterrecoveryweek&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2Z-0zEchjMqSpetA9D9I6WgAAAYI&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0","contentUrl":"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_specialfeatures\/disasterrecoveryweek&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2Z-0zEchjMqSpetA9D9I6WgAAAYI&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/for-healthcare-orgs-disaster-recovery-means-making-sure-docs-can-save-lives-during-ransomware-infection\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"For healthcare orgs, disaster recovery means making sure docs can save lives during ransomware infection"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/58413","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=58413"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/58413\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=58413"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=58413"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=58413"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}