Cyberattacks represent a rapidly escalating threat to the healthcare sector worldwide, posing severe financial risks, disrupting critical workflows, and directly endangering patient safety. It is estimated that nearly 2,000 organisations worldwide fall victim to a successful cyberattack every day, including hospitals, and this number continues to rise [1,2]. The vulnerability is particularly acute within radiation oncology (RO) departments, which have evolved to be entirely dependent on highly integrated digital ecosystems.
1. The Attackers’ Motivation and Logic
The motivation and modus operandi of ransomware attackers are straightforward: they steal or encrypt critical healthcare data to severely restrict or entirely prevent clinical operations. To allow a swift return to normal operations, they leverage this disruption to demand massive ransom payments.
- The Business of Cybercrime: Modern cybercrime operates as a highly organised, lucrative business model. Threat groups rely on corporate structures that include specific divisions of labour (e.g., initial access brokers who breach networks, malware operators, and software developers) and even offer "Ransomware as a Service" (RaaS) subscription or affiliate models. To make it as easy as possible for victims to pay the ransom (usually in Bitcoin), they even operate “customer hotlines.”
- The Logic of the Attack: Attackers systematically exploit digital or human vulnerabilities via common attack vectors such as phishing emails, social engineering, malware, or unpatched zero-day exploits. Once access to a hospital network is gained, the primary mechanism of a ransomware attack involves encrypting critical servers and digital resources while covertly exfiltrating data, resulting in a severe data breach.
- The Motivation: The overarching motivation of these threat actors is financial gain. By completely crippling a hospital's operations, attackers establish immense leverage. They recognise that healthcare organisations cannot afford prolonged downtime due to the immediate risk to human life, creating intense pressure on the institution to yield to multi-million dollar ransom demands in exchange for decryption keys.
2. The Impact on RO
Because RO departments are entirely dependent on the constant availability of electronic patient data, a failure of clinical systems or the unavailability of patient records has uniquely far-reaching consequences.
- Extreme Digital Dependency: RO has transitioned into entirely paperless environments based on digital pathways. A modern RO department relies on a fragile web of interconnected technology: the hospital information system (HIS), electronic medical records (EMR), treatment planning systems (TPS), radiation oncology information systems (ROIS), and the linear accelerators (Linacs) themselves.
- The Reality of a Complete Shutdown: When an attack occurs, the network must typically be severed to contain the threat, leading to a total digital blackout. Without network connectivity, staff lose immediate access to the EMR. This includes dose prescriptions, appointment schedulers, patient contact information, pre-calculated treatment plans, and treatment histories. Treatment becomes impossible, forcing the immediate cancellation of planned sessions and patient appointments until further notice.
- The Challenge of Continued Treatment: Outages caused by cyberattacks can last several weeks or even months. Because oncology treatments are time-sensitive, care cannot simply be put on hold until IT systems are restored. Clinical teams must go to great lengths, sometimes relying on incomplete or fragmented offline sources just to determine which patients are currently undergoing a course of treatment and what their exact fractionated status is. Based on this limited information, patients often have to be referred to alternative RO clinics, a process that requires the time-consuming recalculation and safety-checking of radiation treatment plans from scratch.
3. The Lack of Readiness
Despite the severity of this threat environment, hospitals and specialised departments, including RO in particular, exhibit a severe, systemic lack of preparedness. While non-medical industries have long-established comprehensive cybersecurity and business continuity safeguards, the healthcare sector severely lags behind. Specific guidance and tailored emergency standards for radiotherapy have historically been absent. Many institutions function under the dangerous assumption that cybersecurity is strictly an IT department problem rather than a shared clinical responsibility.
- The High Barrier to Manual Fallbacks: Compounding the problem, modern radiation delivery devices feature immense hardware and software barriers that prevent network-independent or standalone operation. If a department has failed to prepare offline backup repositories or robust hardcopy routines, it cannot safely identify which patients are mid-regimen, what doses have already been applied, or how to reconstruct missing charts. Rebuilding corrupted patient databases from scratch or re-measuring machine beam data manually is an extraordinarily difficult, drawn-out process that can sideline a department for weeks.
4. Real-world Examples
The catastrophic vulnerabilities outlined above are demonstrated by real-world events documented across global healthcare infrastructure:
- The Irish National Health Service (HSE) Attack (2021): A massive national ransomware attack compromised Ireland's public health IT infrastructure in May 2021. Due to the widespread implementation of EMR, public radiation therapy departments across the country lost all ability to retrieve patient details. This triggered the immediate cessation of radiation treatments, interrupting care for hundreds of oncology patients nationally and forcing authorities to rely on emergency alerts through national media to instruct displaced patients to contact their clinics. It took between 4 and 14 days before linacs nationwide could safely be operated within isolated networks to resume patient treatments [3].
- Windsor Regional Cancer Centre, Ontario (2023): A major ransomware incident disrupted this cancer centre in Canada in October 2023. In addition to encrypting all clinical data, the attack rendered internet connections, Wi-Fi, email, and telephone infrastructure entirely unavailable. This brought radiation planning and treatment delivery to a complete standstill, as no access to treatment-related data was possible. The situation forced vulnerable cancer patients to endure 2-to-4-hour travel times to be referred to neighbouring facilities across the province. It took six weeks before treatment planning and irradiation processes could be re-established on-site [4].
- Hospital ClĂnic de Barcelona (2023): In March 2023, a targeted ransomware attack knocked down all virtual servers at the hospital and severed access to the ROIS and treatment planning workflows. Due to the inability to operate the linacs offline (even though the physical machines were otherwise functional), all patients had to be transferred to a neighbouring hospital. Determining patient treatment statuses required a massive logistical effort to manually retrieve what little data remained available (such as partial paper records). Ultimately, entirely new treatment plans had to be created for all referred patients. It took 12 days before the affected RO department could recommence basic operations [5].
In all of these incidents, ransom demands amounting to several million dollars were made, but the clinics refused to comply. Instead, the systems had to be rebuilt from backups and, in some cases, entirely from scratch. Notably, during the Irish crisis, the attackers released the decryption keys for free (for unknown reasons); however, it still took several months before all servers and data storage systems could be fully checked, sanitised, and safely restored to their original state.
Conclusion
This overview demonstrates that cyberattacks are a real, severe, and immediate threat to RO. In addition to raising awareness that this problem can affect any institution at any time, comprehensive guidelines for preparedness are urgently needed. The ESTRO ROSQ Committee has addressed this issue through a dedicated working group to develop a corresponding framework [6]. Future updates will delve deeper into this content to make it as straightforward as possible for clinics to begin assessing their own readiness.

Samuel Peters
HOCH Health Ostschweiz
Department of Radiation Oncology, Kantonsspital St.Gallen
St. Gallen, Switzerland