Related Experiment Video
Updated: Jan 5, 2026

Implementation of a Real-Time Psychosis Risk Detection and Alerting System Based on Electronic Health Records using CogStack
Published on: May 15, 2020
A retrospective impact analysis of the WannaCry cyberattack on the NHS
S Ghafur1, S Kristensen1, K Honeyford2
11NIHR Patient Safety Translational Research Centre, Imperial College London, London, UK.
Insights
The 2017 WannaCry cyberattack caused significant disruptions to National Health Service (NHS) hospitals, leading to a £5.9 million loss in activity. While no increase in patient mortality was observed, the attack impacted hospital admissions and appointments.
Area of Science:
- Health Informatics
- Cybersecurity in Healthcare
- Health Services Research
Background:
- The 2017 WannaCry ransomware attack significantly impacted global organizations, including critical infrastructure like healthcare systems.
- Understanding the specific effects of such cyberattacks on healthcare delivery is crucial for preparedness and response.
Purpose of the Study:
- To systematically analyze the impact of the WannaCry attack on the National Health Service (NHS) in the UK.
- To quantify the effects on hospital activity, including missed appointments, admissions, and patient mortality.
- To determine the economic costs associated with the disruption caused by the ransomware.
Main Methods:
- A systematic analysis of Hospital Episodes Statistics (HES) data was conducted.
- The study compared hospital activity during the WannaCry attack week to a baseline period.
- Key outcomes measured included outpatient appointments, elective and emergency admissions, A&E attendances, and mortality.
Main Results:
- Overall hospital activity across all NHS trusts showed no significant difference during the attack week.
- Hospitals directly infected by WannaCry experienced significant reductions: approximately 6% fewer total admissions, 4% fewer emergency admissions, and 9% fewer elective admissions per day.
- The total economic cost of reduced activity at infected trusts was estimated at £5.9 million, with no significant increase in mortality reported.
Conclusions:
- The WannaCry ransomware attack led to substantial reductions in hospital activity and significant economic losses in directly affected NHS trusts.
- While this study found no increase in mortality, it highlights the need for further research into the broader impact of cyberattacks on patient safety and care delivery.
- The findings underscore the vulnerability of healthcare systems to cyber threats and the importance of robust cybersecurity measures.
Abstract:
A systematic analysis of Hospital Episodes Statistics (HES) data was done to determine the effects of the 2017 WannaCry attack on the National Health Service (NHS) by identifying the missed appointments, deaths, and fiscal costs attributable to the ransomware attack. The main outcomes measured were: outpatient appointments cancelled, elective and emergency admissions to hospitals, accident and emergency (A&E) attendances, and deaths in A&E. Compared with the baseline, there was no significant difference in the total activity across all trusts during the week of the WannaCry attack. Trusts had 1% more emergency admissions and 1% fewer A&E attendances per day during the WannaCry week compared with baseline. Hospitals directly infected with the ransomware, however, had significantly fewer emergency and elective admissions: a decrease of about 6% in total admissions per infected hospital per day was observed, with 4% fewer emergency admissions and 9% fewer elective admissions. No difference in mortality was noted. The total economic value of the lower activity at the infected trusts during this time was £5.9 m including £4 m in lost inpatient admissions, £0.6 m from lost A&E activity, and £1.3 m from cancelled outpatient appointments. Among hospitals infected with WannaCry ransomware, there was a significant decrease in the number of attendances and admissions, which corresponded to £5.9 m in lost hospital activity. There was no increase in mortality reported, though this is a crude measure of patient harm. Further work is needed to appreciate the impact of a cyberattack or IT failure on care delivery and patient safety.
Related Concept Videos
Guidelines and Strategies for Safe Computer Charting
Maintain Confidentiality and Security:
Issues And Trends In Healthcare Delivery System
Cost Containment
Payment for healthcare services has historically promoted adoption of costly and often unnecessary or inefficient...
Current Trends in Nursing II
Purpose of Health Records II
Healthcare Associated Infections II: Preventive Measures
The best practices for preventing healthcare-associated infections include hand hygiene, patient risk...
Types of Reports II: Incident or Occurrence Report
Purposes:
In the healthcare industry, reports play a crucial role in documenting incidents within an agency. The primary objective of these reports is to ensure patient safety, uphold the...
