READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Romania's 2024 Mass Hospital Hack: How 100 Facilities Went to Pen and Paper to Survive Ransomware

Romania's 2024 Mass Hospital Hack: How 100 Facilities Went to Pen and Paper to Survive Ransomware
In February 2024, ransomware attackers breached a single Romanian medical software firm and spread to over 100 hospitals nationwide. Romania's cyber-security chief ordered every affected hospital offline, forcing doctors to paper records for four days. The response has since become a studied model for how health systems should plan for the same thing happening to them.

The Attack

On the night of February 9–10, 2024, criminals quietly infiltrated the servers of RSC, a Bucharest-based software company, according to BBC News. RSC makes a widely used hospital management platform called Hippocrates, which handles admissions, lab orders, pharmacy logistics, radiology requests, and payroll for dozens of Romanian hospitals.

The attackers deployed a ransomware strain called BackMyData. It encrypted files across every connected Hippocrates installation, turning medical records into gibberish, and left the standard demand: pay in bitcoin or lose everything.

Staff at Pitești children's hospital, southwest of Bucharest, were the first to notice errors on Sunday morning, February 10. By dawn Monday, hospitals across Romania had confirmed the system was down.

The Call That Went to 100+ Hospitals

Dan Cimpean, head of Romania's national cyber-security centre (DNSC), faced a decision with no good options. Let the ransomware keep spreading through connected hospital networks, or cut them all off from the internet and accept the operational chaos that would follow.

He ordered the disconnect.

More than 100 hospitals went dark on network access, according to BBC News. No connected devices. No email. No web browsers. No electronic records.

Medical staff improvised. Surgeon Oana Goidescu, on shift at Buzău Hospital 120 kilometers northeast of Bucharest, described the scope of what vanished: "For each patient, we request lab tests, radiology, medicines and supplies. All of that was gone."

Doctors and nurses reverted to handwritten records, paper prescriptions, and verbal coordination. IT teams worked alongside the DNSC and RSC to map the infection, identify patient-zero entry points, and begin expelling the attackers from systems.

The offline period lasted four days.

Why This Matters Beyond Romania

The FBI has stated that healthcare is now the most targeted sector of critical national infrastructure. That assessment reflects a pattern: hospitals hold sensitive data, operate life-critical systems under severe time pressure, and have historically underfunded cybersecurity compared to banks or utilities.

The Romanian incident stands out not because the attack itself was technically unprecedented, but because the coordinated national response at scale — cutting more than 100 facilities simultaneously, managing patient safety during the blackout, and containing the infection within four days — is rare. Most countries have no tested playbook for a simultaneous multi-hospital compromise through a shared software vendor.

Romania's response has become a reference case for disaster planners internationally, with officials from other countries seeking guidance on how to structure their own mass-hospital-hack protocols, according to BBC News.

The Disconnection Trade-Off

Critics of aggressive internet disconnection orders raise a legitimate point: going to pen and paper in a hospital is not a neutral fallback. Medication errors increase when electronic dosing alerts are gone. Lab results travel slower. Surgical scheduling breaks down. Patients with complex, fast-moving conditions — sepsis, trauma, acute cardiac events — face real added risk when the coordination infrastructure disappears.

This concern deserves to be taken seriously. The four-day outage across 100-plus Romanian hospitals almost certainly created some degree of elevated patient risk, even if no mass casualty event occurred. The honest question for planners is not whether disconnection is painless, it isn't, but whether a contained four-day analog operation is safer than allowing live ransomware to continue spreading through systems managing drug dispensing and surgical records. Romania's cyber response team concluded the disconnect was the lesser risk. The full clinical outcome data from those four days has not been published in the sources available here, so that verdict remains partly unverified.

What the Response Got Right

Speed. The order went out fast enough to stop lateral movement before every hospital in the country was encrypted. The DNSC coordinated directly with the software vendor RSC rather than leaving individual hospitals to respond in isolation, which prevented duplication of effort and conflicting recovery timelines.

Hospital staff also deserve direct credit. Cimpean's order only works if the people on the ground comply immediately and adapt under pressure. According to BBC News, Romanian doctors and nurses created functional workarounds within hours. That kind of analog resilience doesn't happen without training and institutional memory that predates full digital dependency.

The Open Question

RSC's Hippocrates platform connecting 100-plus hospitals through a single vendor is precisely the kind of supply-chain architecture that makes a one-entry-point, mass-casualty-capable attack possible. Romania patched the immediate crisis. Whether the underlying structural vulnerability — shared medical software with broad hospital network access and apparently insufficient segmentation — has been fundamentally addressed is a question the DNSC and RSC have not publicly answered in full as of June 22, 2026.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

left
BBCHow 100 Romanian hospitals switched to pen and paper to defeat a national cyber-attack