Cybersecurity as Patient Safety: The New Compliance Frontier for Healthcare Operators

August 9, 2026

On this page

Ready to be survey-ready?

See how AccrediCulture turns compliance into an operating system across every facility.

Yes, a cyber incident is a patient safety event. Regulators have said so out loud.

If a ransomware attack takes your EHR down, diverts ambulances, or delays a scan, treat it as a patient safety event, not an IT ticket. The Joint Commission said this plainly in August 2023 when it published Sentinel Event Alert 67: Preserving patient safety after a cyberattack. In that alert, TJC framed cyberattacks as a growing patient safety concern and told organizations to prepare to deliver safe care during extended downtime. The number of cyberattacks and information system breaches in healthcare has grown steadily, escalating from isolated incidents to widespread targeted and malicious attacks, and in 2022, 707 data breaches occurred, exposing more than 51.9 million patient records, according to data from HHS.

The compliance implication is direct. A cyber incident that disrupts care can trigger sentinel event review under TJC policy, Condition-level findings under CMS 42 CFR §482 (particularly Governing Body, QAPI, and Medical Record Services), and an OCR investigation under the HIPAA Security Rule. Your incident-management workflow, your CAP process, and your emergency management program all need to catch it, not just your IT service desk.

The numbers surveyors are reading before they walk in

Cybersecurity as Patient Safety: The New Compliance Frontier for Healthcare Operators — The numbers surveyors are reading before they walk in

The evidence base is now large enough that surveyors, state agencies, and OCR investigators are citing it. A few figures worth committing to memory:

  • The 2023 OCR Annual Report to Congress on HIPAA Compliance shows OCR received 732 reports of data breaches affecting 500 or more individuals in 2023, a 17% year-over-year increase, and across those breaches 113,173,613 individuals had their protected health information exposed, stolen, or impermissibly disclosed, with hacking and IT incidents accounting for 590 of the 732 large breaches and roughly 108.7 million of the 113 million compromised records.
  • The McGlave, Neprash, and Nikpay study of hospital ransomware attacks linked to Medicare claims found that ransomware attacks decrease hospital volume by 17 to 24 percent during the initial attack week, with recovery occurring within three weeks, and among patients already admitted to the hospital when a ransomware attack begins, in-hospital mortality increases by 34 to 38 percent.
  • In a JAMA Health Forum analysis, 44.4 percent of ransomware attacks disrupted care delivery through electronic-system downtime, cancelled appointments and ambulance diversion, with an average disruption lasting 15.8 days, and only 20.6 percent of organizations recovered their data from backups.

A quote worth pinning to your governance charter, from The Joint Commission’s Alert 67: “preparing for a cyberattack should not only concern hospital IT staff, but instead all hospital staff. Every staff member must prepare to operate during a cyber emergency.”

What Alert 67 actually tells surveyors to look for

The alert is not a suggestion. It maps to existing standards your surveyors already score. Emergency Management Standard EM.11.01.01 requires a hospital to conduct a hazards vulnerability analysis that includes human-caused hazards such as cyberattacks, EM.13.01.01 requires a continuity of operations plan, EM.14.01.01 requires a disaster recovery plan, and EM.15.01.01 requires emergency management education and training. That is a survey trail with your name on it if the HVA does not include cyber.

TJC’s own guidance sets the bar higher than most operators expect. Organizations should be prepared to have life- and safety-critical technology offline for four weeks or longer. Four weeks. Not four hours. If your downtime binders assume the EHR is back by lunch, rewrite them.

Concrete actions the alert calls out: form an interdisciplinary downtime planning committee with representation from every stakeholder group, designate response teams for unanticipated downtime, and train those teams on the specific incidents that trigger downtime procedures. Form a downtime planning committee to develop preparedness actions and mitigations, with representation from all stakeholders, designate response teams, create an interdisciplinary team to mobilize during unanticipated downtime events, and train team leaders, their respective teams and all staff on how to operate during downtimes, including specific incidents that would cause downtime to go into effect.

How to fold cyber into the accreditation program you already run

Cybersecurity as Patient Safety: The New Compliance Frontier for Healthcare Operators — How to fold cyber into the accreditation program you already run

You do not need a separate cyber program. You need cyber threaded through the compliance program you already have. Here is how we help clients wire it in:

  1. Incident intake. Every suspected cyber event enters the same incident management workflow as a medication error or a patient grievance. Same triage. Same 24-hour clock. Same escalation to the sentinel event committee if patient care was disrupted.
  2. Root cause analysis. Run a full RCA on the clinical impact, not only the technical breach. Which patients were diverted? Which orders were delayed? Which paper workarounds failed?
  3. Corrective action plan. The CAP owns the follow-through. Downtime training gaps, HVA revisions, vendor risk reassessments, and policy updates all live in one plan with assigned owners and dates.
  4. Policy alignment. Emergency Management, HIPAA Security Rule (45 CFR §164.308–164.312), Governing Body, QAPI, and Medical Record Services policies each need a cyber section. Cross-reference them so a surveyor pulling one finds the others.
  5. Governance. The committee overseeing this should include the Compliance Officer, CMO or medical director, CNO, CIO or CISO, Risk, Legal, Emergency Management, and a board representative. Not an IT working group.

This is why we built AccrediCulture the way we did. Incident management, policy, EOC and EM, CAPs, and accreditation documentation all sit in one place. When a surveyor asks how you handled last quarter’s downtime event, you open one screen, not seven.

Frequently asked questions

Does a ransomware attack qualify as a sentinel event under Joint Commission policy?
It can. If the attack results in death, permanent harm, or severe temporary harm from delayed or diverted care, it meets the sentinel event definition and should be reviewed under your SE policy. Even when it does not, Alert 67 treats cyber-related care disruption as a patient safety concern warranting proactive review.

What CMS Conditions of Participation are implicated when an EHR goes down?
Most commonly Governing Body (§482.12), QAPI (§482.21), Medical Record Services (§482.24), and Emergency Preparedness (§482.15). A prolonged outage can produce Condition-level findings in any of these if downtime procedures fail or documentation gaps appear.

How should we document a cyber incident inside our corrective action plan?
Treat it like any other CAP: root cause, contributing factors, corrective actions with owners and due dates, evidence of completion, and effectiveness review. Add a specific section for clinical impact and downtime performance so surveyors see the patient safety lens, not only the IT lens.

Who needs to be on the governance committee overseeing cybersecurity as patient safety?
Compliance, medical leadership (CMO), nursing leadership (CNO), IT/security (CIO or CISO), Risk, Legal, Emergency Management, and a board liaison. The committee should report up to the Governing Body on a set cadence.

What are surveyors asking about cybersecurity during accreditation visits in 2024 and 2025?
Expect questions on your HVA (does it include cyber?), downtime plans (do they cover four-plus weeks?), staff training records, tabletop exercise documentation, incident reports tied to any recent outages, and how cyber events are reviewed inside your QAPI program. Have the artifacts ready in one place.

Scroll to Top