Cyberattack cripples Brockton Hospital, forces ambulance diversions and cancels cancer treatments

By 
, April 7, 2026 
Category:

A cybersecurity incident knocked out electronic medical records and internet services at Brockton Hospital in Massachusetts, forcing the 216-bed facility to divert ambulances, cancel chemotherapy treatments, and send nurses and doctors scrambling for pen and paper.

Signature Healthcare, which operates the hospital, announced Monday that it was responding to the attack. By Tuesday, chemotherapy infusion services had been canceled outright. Retail pharmacies remained shuttered. Ambulatory practices and urgent care were set to reopen, but officials warned patients to expect delays.

The breach left a community hospital, the kind of facility that serves as a lifeline for working families, operating in the dark, literally stripped of the digital infrastructure modern medicine depends on. Emergency and in-patient services stayed open, and surgeries proceeded as scheduled, but the damage to routine care was immediate and real.

Pen and paper in a digital age

Brooke Hynes, who works in strategic communication for Signature Healthcare, told the Daily Mail that the cyberattack brought down the hospital's electronic medical records system entirely. Nurses and doctors had to switch to handwritten documentation, a throwback that slows every step of patient care, from medication orders to lab results.

The hospital also lost internet services. Staff implemented what Signature Healthcare called "downtime procedures," a clinical term for making do without the tools that keep a modern hospital running.

WCVB reported that ambulances were diverted to nearby hospitals, even though emergency and in-patient services at Brockton remained open. That diversion pushes strain onto neighboring facilities and adds critical minutes to transport times for patients in the surrounding area.

Signature Healthcare issued a brief statement acknowledging the scope of the problem:

"We are working with external partners to investigate and restore operations as quickly as possible."

What those external partners have found, and whether ransomware was involved, remains unknown. The hospital has not disclosed the cause or origin of the attack, whether any patient data was compromised, or how long the disruptions will last.

Cancer patients left waiting

The most gut-level consequence: chemotherapy infusion services scheduled for Tuesday were canceled. For cancer patients on a treatment schedule, a missed session is not a minor inconvenience. It is a disruption to a protocol their oncologists designed around timing, dosage, and disease progression.

No public accounting has been given of how many patients lost appointments or how quickly those sessions might be rescheduled. The hospital's retail pharmacies stayed closed as well, cutting off another access point for patients who depend on the facility for medications.

This is the human cost that gets buried under the antiseptic language of "cybersecurity incident" and "downtime procedures." Somebody's mother missed chemo. Somebody's grandfather couldn't fill a prescription. Somebody in the back of an ambulance got rerouted to a hospital farther away.

A pattern that keeps repeating

Brockton Hospital is not an isolated case. Just months earlier, a ransomware attack forced the University of Mississippi Medical Center to close dozens of clinics across the state and cancel many patient procedures for over a week. In March, an attack on medical device maker Stryker knocked out its networks worldwide, disrupting an electronic ordering system and a patient-data system used by first responders.

The frequency of these attacks on healthcare infrastructure should alarm anyone who depends on a hospital, which is to say, everyone. Cyber threats against American institutions have grown increasingly brazen, from state-linked propaganda networks to direct strikes on critical services.

Cynthia Kaiser, a former top FBI cyber official who now heads Halcyon's Ransomware Research Center, framed the problem bluntly in comments to Politico:

"Every day, hospitals are being targeted."

Kaiser pointed to a structural vulnerability that makes healthcare an especially attractive mark. Hospitals run on thin margins. Administrators face impossible trade-offs between patient care budgets and cybersecurity spending.

"A lot of hospitals operate on thin margins and they think they have to choose between patient care and cybersecurity."

That is not an excuse. It is a diagnosis. And the prescription, better defenses, more resources, serious deterrence, has been slow in coming.

Why hospitals make easy targets

Paul Connelly, former chief security officer at hospital system HCA Healthcare, laid out the calculus from the hackers' side:

"Hacking groups either want to get paid, want to collect data or they want to create chaos."

Attacking a hospital, Connelly said, can "achieve at least one of those goals, or all three at once." Hospitals hold vast troves of sensitive personal and medical data. They operate around the clock under life-or-death pressure. And that pressure makes them more likely to pay a ransom quickly rather than risk prolonged shutdowns.

The FBI has advised against paying ransoms, arguing that doing so only encourages future attacks. That is sound policy in the abstract. But when your electronic records are gone, your pharmacies are dark, and cancer patients are being turned away, the pressure to pay becomes enormous.

Lawmakers in Washington have pushed legislation to stem the barrage of attacks on healthcare systems and provide federal support to struggling hospitals and medical centers. The Trump administration's National Cyber Strategy has vowed to impose "consequences" on hacking groups that target critical infrastructure like hospitals.

The gap between talk and protection

Vowing consequences is the right instinct. But consequences have to be real, and they have to arrive before the next hospital goes dark. The pattern is now well established: attack, chaos, slow recovery, a few public statements, and then silence until the next breach.

Kaiser did not hold back:

"People need to care about this. Security officials need to care about this. There needs to be more outrage across society about what these hackers are doing."

She is right. The outrage deficit is real. A cyberattack that cancels chemotherapy and diverts ambulances should command the same public attention as a physical attack on a hospital. The damage to patients is no less tangible because the weapon was digital.

The Brockton Hospital incident remains full of unanswered questions. Was this ransomware? Who carried it out? Was patient data stolen? How long will full services take to restore? Signature Healthcare has offered little beyond its initial statement and the bare facts of what went offline.

That opacity is itself a problem. Patients and the public deserve a clear accounting, not just of what happened, but of what defenses were in place and why they failed.

A test of seriousness

The broader question is whether the country treats healthcare cybersecurity as the critical-infrastructure emergency it plainly is, or continues treating each incident as a one-off misfortune. Hospitals are not tech companies. They cannot simply go offline for a few days while engineers sort things out. Every hour of downtime carries a potential cost measured in human health.

Federal support, stronger deterrence, and real accountability for the attackers are all necessary. So is an honest conversation about why so many hospitals remain vulnerable years after the threat became obvious.

When hackers can shut down a community hospital's cancer treatments with a keystroke, the system has failed the people it exists to protect. The only question left is whether anyone in a position to fix it treats that failure as urgent, or waits for the next one.

About Jack Newsome

STAY UPDATED

Subscribe to our newsletter and receive exclusive content directly in your inbox