
Industries in Focus
Last updated:
8 min.
Based on the research work of Dr. iur. Dr. rer. pol. Fabian M. A. Teichmann
It is a scenario that would have sounded like science fiction just ten years ago: a hacker presses a key, and a clinic with hundreds of patients can no longer perform surgeries, retrieve lab values, or run an emergency room. Today, it is a bitter reality – and it is costing human lives.
Hospitals are among the most attractive targets for ransomware attackers worldwide. The reasons are cynically simple: clinics are existentially dependent on their IT, often have outdated infrastructure, and their mandate to provide care creates maximum pressure to react quickly – if necessary, by paying. Teichmann has systematically examined the legal, ethical, and organizational dimensions of this threat in several papers. The findings are alarming.
The scale of the threat: numbers that give pause
In 2022 alone, three-quarters of all healthcare facilities in Germany were victims of cyberattacks. According to the Federal Office for Information Security (BSI), ransomware is currently the single greatest threat in the healthcare sector. The BSI describes the threat level as higher than ever before (Teichmann, Cyberangriffe auf Kliniken: Patientengefährdungen, rechtliche Pflichten und ethische Herausforderungen, Ethik in der Medizin 2026, pp. 1–23).
Initial studies from the US suggest that hospital mortality can increase by 20 to 35 percent during a severe cyberattack – caused by delays in treatment, the failure of monitoring systems, and the loss of critical patient data. One-third of all cyberattacks on healthcare facilities have a significant or at least noticeable impact on patient care: operations are postponed, treatments aborted, emergency patients rerouted (Teichmann, Ethik in der Medizin 2026, pp. 1–23).
These are not abstract statistics. Behind each of these numbers are human beings.
The Düsseldorf 2020 Case: When a Cyberattack Led to a Fatality
No event illustrates the life-threatening dimension of ransomware attacks on hospitals as vividly as the attack on the Düsseldorf University Hospital in September 2020.
Attackers had exploited a known security vulnerability in a VPN software for months, embedding themselves deep within the clinic's network. On September 10, 2020, they struck: the DoppelPaymer ransomware encrypted the clinic's IT systems almost entirely. The emergency department had to be shut down. For over 13 days – an unprecedented period for a maximum care hospital – no emergency patients could be admitted. Hundreds of operations and procedures were canceled (Teichmann, Ethik in der Medizin 2026, pp. 1–23).
A 78-year-old woman with a life-threatening aortic aneurysm had to be driven past Düsseldorf that evening. The ambulance took her to Wuppertal – about 30 kilometers further. The extra time was not enough. The patient died shortly after admission.
The Düsseldorf Public Prosecutor's Office initiated an investigation for negligent homicide – for the first time in Germany, it was examined whether a cyberattack was the causal factor in a death. The investigation was eventually closed because the causal connection could not be proven with the required certainty. The symbolic impact of the event remained nonetheless: cyberattacks on hospitals can kill people (Teichmann, IT-Sicherheit im Krankenhaus – Neue Pflichten durch IT-SiG 2.0, KRITIS-Dachgesetz und § 391 SGB V, MedR 2025, pp. 959–968).
A remarkable twist in this case: when the hackers found out they had hit a hospital – and not, as apparently planned, only the affiliated university – they voluntarily provided a decryption key and waived their ransom demand. Even cybercriminals, as this case shows, occasionally have moral boundaries. The damage, however, had already long been done.
How attackers target hospitals
Ransomware attacks on healthcare facilities follow an industrially perfected pattern. Highly professional perpetrator groups work with a division of labor: so-called Initial Access Brokers first gain entry into networks through phishing emails, unpatched software, or stolen credentials, and resell this access on the darknet. The actual ransomware operators then take over the encryption and extortion (Teichmann, Ransomware-Angriffe auf Krankenhäuser – Strafrechtliche, Medizinrechtliche und Datenschutzrechtliche Herausforderungen, Zeitschrift für Lebensrecht 2025, pp. 349–366).
Increasingly, so-called Double Extortion is being deployed: patient data is exfiltrated before encryption. The perpetrators then threaten not only to keep the systems locked but also to publish highly sensitive health data – a leverage tool that works even if a clinic has functioning backups.
Why are hospitals such attractive targets? The dependence on IT is existential and directly bio-hazardous to patients. Many clinics operate with heterogeneous, sometimes outdated IT landscapes, where patches and updates were never consistently applied. And the moral pressure to become operational again quickly makes clinics relatively willing payers. Professional attackers therefore deliberately calculate the ransom demand to be just below the anticipated cost of an independent data restoration (Teichmann, Zeitschrift für Lebensrecht 2025, pp. 349–366).
The legal obligations: What hospitals must do today
Germany has responded to the growing threat with a major expansion of statutory security requirements.
Larger hospitals are considered operators of critical infrastructures (KRITIS) and are subject to the BSI Act. They must implement appropriate technical and organizational protective measures according to the state of the art, have them audited every two years, and immediately report serious IT disruptions to the BSI. Compliance with these specifications is actively monitored (Teichmann, MedR 2025, pp. 959–968).
Since January 1, 2022, an expanded obligation applies through Section 391 SGB V: now all hospitals – even those below the KRITIS threshold – must implement appropriate state-of-the-art IT security measures and update their systems at least every two years. The legislature explicitly recommended aligning with the BSI's KRITIS standards. This effectively establishes a uniform security standard for the entire healthcare sector (Teichmann, MedR 2025, pp. 959–968).
In parallel, the requirements of the GDPR apply. Patient data is medical data of a highly sensitive nature. Clinics that experience a data breach due to a cyberattack must report it to the competent data protection supervisory authority within 72 hours and, under certain circumstances, inform the affected patients. Fines can reach up to 20 million euros or four percent of global annual turnover. The first clinics in Europe have already been sentenced to severe penalties (Teichmann, Interdisziplinäre Aspekte der IT-Sicherheit im Gesundheitswesen, medstra 2025, pp. 218–222).
Liability: When are hospital directors held personally accountable?
Teichmann places a question at the center that is uncomfortable for many hospital administrators: can managing directors or chief physicians be held personally liable for insufficient IT security if patients are harmed?
The answer is: Yes, in principle. Under criminal law, offenses of negligence such as negligent homicide or negligent bodily harm could become relevant if it can be proven that gross failures in IT security were causal to patient harm. The benchmark would be the prevailing security standards: BSI requirements, Section 391 SGB V, and recognized industry-specific safety standards. Anyone who leaves known vulnerabilities unpatched for months or systematically cuts IT security budgets and then suffers a preventable attack risks at least the accusation of a breach of duty (Teichmann, Ethik in der Medizin 2026, pp. 1–23).
Under civil law, the principle of organizational liability applies: clinics owe their patients an organization of operations that is secure according to current standards. Today, this includes IT security. Furthermore, under the GDPR, an unfavorable burden of proof rule applies: in the event of a dispute, the hospital must prove that it had taken all reasonable protective measures. If it fails to do so, it is liable for non-material damages to the affected patients (Teichmann, Ethik in der Medizin 2026, pp. 1–23).
No hospital manager in Germany has yet been criminally convicted because of a cyber incident. However, Teichmann considers it only a matter of time before this happens. The legal trend is clear: IT security is a board-level issue – and inaction is no longer an option.
The ethical dilemma: Is it permissible to pay a ransom to protect patients?
Ransomware attacks on clinics present decision-makers with an exceptionally sharp moral dilemma. On one hand, authorities and experts unanimously advise against paying ransoms, because every payment finances the attackers' business model and provokes further attacks. On the other hand, lives are at stake.
Teichmann analyzes this dilemma by drawing on classical bioethical principles – non-maleficence, beneficence, justice, and autonomy (Teichmann, Ethik in der Medizin 2026, pp. 1–23).
The principle of non-maleficence enters an internal contradiction: those who do not pay may allow preventable harm to current patients. Those who do pay finance crime and provoke future attacks, which in turn endanger other patients. Immediate, certain harm clashes with indirect, but diffuse harm.
The principle of beneficence initially seems to favor payment – if it were indeed the fastest way to restore operations. But here too, payment is no guarantee. Many hospitals that paid report incomplete decryptions or even repeat attacks by the same group.
Teichmann does not arrive at a simple formula, because one does not exist. His recommendation is instead: to ensure through rigorous prevention that this decision does not even have to be made in an emergency. Anyone who has functioning offline backups, knows and has tested emergency plans, and has segmented systems, is not blackmailable – at least not fully (Teichmann, Ethik in der Medizin 2026, pp. 1–23).
What the WannaCry attack on the British NHS showed
An international reference event is the WannaCry attack of May 2017, which severely hit the British National Health Service (NHS). Within a few days, thousands of appointments and surgeries were canceled; in five regions of England, emergency departments were temporarily unable to admit patients, forcing ambulances to drive significantly longer distances (Teichmann, Ethik in der Medizin 2026, pp. 1–23).
The NHS had not installed the patch that would have closed the exploited Windows vulnerability – even though it had been available for months. The result: a national health emergency that could have been prevented with a routine update.
This lesson remains valid today: the most dangerous attacks often rely not on highly sophisticated exploits, but on the simple exploitation of known, unpatched vulnerabilities. This is not a technical issue, but an organizational and leadership culture issue.
What hospital managements must do now
Teichmann develops concrete recommendations for action from his legal and ethical analyses (Teichmann, Ethik in der Medizin 2026, pp. 1–23; ibid., MedR 2025, pp. 959–968).
Security updates must be treated as a top operational priority – not as a routine IT task that is postponed when in doubt. Known vulnerabilities must not remain open for months. Backups must not only exist but must be stored offline, regularly tested, and verified for their actual recoverability. Contingency plans that enable at least partial clinical operation without IT – paper-based procedures, redundant communication channels, regional backup concepts – are not a formality, but life-saving preparation.
Network segmentation is one of the most effective technical protective measures: if critical systems such as ICU monitoring, laboratory, and administrative IT are separated from each other, an attacker who compromises one department cannot immediately paralyze the entire clinic. Employee training for recognizing phishing and social engineering closes the human gap that technical measures alone cannot bridge.
And finally: the executive management must regularly place these topics on the agenda. IT security reports belong in board meetings, not just in the IT department.
Conclusion: Patient safety and IT security are inseparable
Teichmann's research leads to a clear conclusion: the safety of patients and the security of the IT systems on which their care depends can no longer be separated. Hospitals that invest in IT security invest in patient protection. Hospitals that neglect this endanger human lives – and increasingly expose their leaders to personal liability.
The legal obligations in Germany today are clear. What is still missing in many places is the cultural anchoring: IT security as a C-level priority, as an ethical duty, as part of the medical duty of care. The 2020 Düsseldorf case was a wake-up call. The question is how many more wake-up calls are needed before this message is received everywhere.
All sources refer to published academic contributions by Dr. iur. Dr. rer. pol. Fabian M. A. Teichmann. The complete bibliography is documented in the list of publications (as of May 2026).
Related Posts


