Introducing CIPHER: The Open-Source Platform Revealing Patient Harms from Healthcare Cyberattacks
D. Isabel Straw (Emergency Doctor / Cyber Security Researcher · UC San Diego Center for Healthcare Cyber Security)
Biohacking Village @ DEF CON 33 · Day 1 · Biohacking Village
Overview
Dr. D. Isabel Straw presented CIPHER, an ambitious open-source project from the UC San Diego Center for Healthcare Cyber Security, at Defcon's Biohacking Village. This initiative aims to fundamentally shift the understanding of healthcare cyberattacks, re-framing them as a critical public health threat. CIPHER (Cyber Attack Impacts, Patient Harms, and Emergency Response) seeks to build robust datasets and models that directly link upstream technical failures during cyber incidents to downstream patient harms, including injuries, diseases, and even deaths, on the hospital floor.

Key moments
- 0:00 Introducing CIPHER: Modeling healthcare cyberattacks as public health threats
- 2:00 Patient deaths and clinical surprise from healthcare cyberattacks
- 3:00 Shift from data theft to denial of patient care
- 4:00 CIPHER's data collection: patient harms across time and specialties
- 5:00 Academic data and interactive map of hospital cyberattacks
- 6:00 Examples of diverse cyberattack vectors on healthcare systems
- 6:40 Medical device vulnerabilities creating new routes for attacks
Introducing CIPHER: The Open-Source Platform Revealing Patient Harms from Healthcare Cyberattacks
Speakers: D. Isabel Straw, Emergency Doctor / Cyber Security Researcher, UC San Diego Center for Healthcare Cyber Security
Conference: Biohacking Village
YouTube: https://www.youtube.com/watch?v=TSXfGdv3nu4
Overview
Dr. D. Isabel Straw presented CIPHER, an ambitious open-source project from the UC San Diego Center for Healthcare Cyber Security, at Defcon's Biohacking Village. This initiative aims to fundamentally shift the understanding of healthcare cyberattacks, re-framing them as a critical public health threat. CIPHER (Cyber Attack Impacts, Patient Harms, and Emergency Response) seeks to build robust datasets and models that directly link upstream technical failures during cyber incidents to downstream patient harms, including injuries, diseases, and even deaths, on the hospital floor.
The urgency for CIPHER stems from the escalating frequency and sophistication of cyberattacks targeting healthcare infrastructure. Historically focused on data theft, these attacks are increasingly pivoting towards denial of patient care, a phenomenon the American Hospital Association has aptly termed "threat to life crimes." Dr. Straw highlighted alarming case studies, such as an infant death in the USA linked to a ransomware attack and over 150 safety incidents and patient deaths in the UK's NHS due to IT downtime. These incidents underscore a critical gap: clinicians often experience "clinical surprise," unsure which patients are most at risk, while technical teams lack insight into the life-criticality of specific systems. CIPHER directly addresses these challenges by providing clinically grounded incident response tools and data to minimize harm and inform strategic decision-making during crises.
Background
▶ Watch: Introducing CIPHER: Modeling healthcare cyberattacks as public health threats (0:00)
The landscape of cybersecurity threats against healthcare organizations has evolved dramatically over the past decade. What began primarily as an effort to exfiltrate sensitive patient data for financial gain or other malicious purposes has transformed into a direct assault on the operational capabilities of hospitals and clinics. This shift towards denial of patient care means that cyberattacks are no longer abstract data breaches but tangible threats to human life. As Dr. Straw emphasized, the disruption of patient care directly correlates with adverse health outcomes, ranging from delayed diagnoses and treatments to permanent injuries and fatalities.
The problem is compounded by a lack of comprehensive, clinically validated data on the specific patient harms resulting from these attacks. Existing incident reporting mechanisms within healthcare are often digitally dependent, rendering them unusable during cyber outages. Furthermore, there can be institutional barriers to clinicians reporting harms, making academic literature a slow and incomplete source of information. This data deficit contributes to the "clinical surprise" experienced by medical staff, who, in the chaotic aftermath of an attack, struggle to prioritize care for the most vulnerable patients or understand the cascading effects of system outages. Technical teams, similarly, often lack a clear, clinically informed hierarchy of critical systems, making it difficult to allocate limited resources effectively during a crisis. CIPHER draws inspiration from public health methodologies, like the web mining used during the COVID-19 pandemic, to complement traditional academic research with real-time, ground-level insights from social media, thereby creating a more holistic and actionable understanding of the problem.
Key Findings
▶ Watch: Shift from data theft to denial of patient care (3:00)
The CIPHER project has unearthed significant insights into the multifaceted nature of patient harms from healthcare cyberattacks, synthesizing data from both academic literature and social media. The core finding is the creation of a comprehensive CIPHER database, which currently catalogs over 300 cyberattack-induced patient harms across various clinical settings globally.
Analysis of this database reveals a striking diversity of impacts, which are not uniform across all incidents. These impacts are influenced by three intersecting factors: the cyberattack parameters (how hackers gained access, which systems were targeted), the hospital's technical dependencies (reliance on digital prescribing, specific communication pathways), and the local patient population (prevalence of specific diseases, demographics). For instance, a hospital in a trauma-heavy urban area will experience different critical impacts than one in a rural area serving a predominantly elderly population with chronic conditions.
From academic data, CIPHER found extensive documentation of harms in emergency medicine and acute care. Examples include the Conti ransomware attack in Ireland, which severely impacted cancer patients by disrupting radiotherapy and chemotherapy services. The Sanovis attack in 2024 took out pathology services, leading to critical issues for trauma patients needing blood transfusions and obstetric emergencies like C-sections. The tragic infant death case was linked to failures in remote telemetry on labor wards, affecting neonates and complex pregnancies.
Crucially, social media data provided a complementary and often more immediate perspective, filling gaps left by the slower, more formal academic reporting. While academic sources focused on acute care, social media revealed significant harms in psychiatry (patients reporting medication access issues and symptom deterioration), neurology (chronic pain and migraine patients unable to access preventative care), and obstetrics (disruptions to birth plans, miscarriage care, and even lost cervical smear results). Staff reports on platforms like Reddit highlighted issues such as CCTV systems going down on high-risk psychiatric wards, raising safety concerns, and the failure of air conditioning and patient call alarms, forcing nurses to resort to manual rounds and patient bells.
Beyond direct clinical systems, CIPHER identified several unanticipated findings. These included issues with hospital fridges losing automated temperature control, leading to the spoilage of blood products and critical medications. The loss of digital protocols and internet guidance posed challenges for junior doctors unfamiliar with specialist conditions. Furthermore, the disruption of systems displaying normal ranges for blood tests was noted, potentially leading to misinterpretations, especially for patient subgroups with adjusted physiological thresholds, raising significant health equity concerns.
The impact on the healthcare workforce was also a prominent finding. Both academic and social media data consistently highlighted severe staff fatigue and burnout due to the shift to manual, paper-based operations. Reports on Reddit described radiologists working over 36 hours straight, significantly increasing the risk of medical errors. This was concretely demonstrated by instances of teleradiology services going down, leading to missed injuries in fracture and trauma patients due to uninterpreted imaging.
Finally, the talk underscored the critical impact on life-saving resources and patient transfers. The Sinois attack prompted the NHS to issue urgent public appeals for blood donations due to an inability to cross-match blood types, forcing reliance on limited O-negative universal donor blood. Outages also prevented patients from donating blood. For rural hospitals, extended transfer times for critically ill patients (e.g., C-sections, diabetic ketoacidosis, cardiac arrest) led to significantly worse outcomes, with one UC San Diego study demonstrating a fall in favorable neurological outcomes for cardiac arrest patients during ransomware incidents at neighboring hospitals. The pervasive impact on medical devices, from digital templating software for orthopedic implants and cloud-based chemotherapy platforms to linear accelerators for radiotherapy, further highlighted the direct link between technical outages and severe patient harm, extending even to non-medical but critical hospital infrastructure like AC systems and call lights.
Technical Deep Dive
▶ Watch: CIPHER's data collection: patient harms across time and specialties (4:00)
The CIPHER project is built upon a dual-pronged data collection methodology, integrating both structured academic evidence and unstructured social media insights, followed by sophisticated modeling to visualize and predict patient harms. The core output is an open-source platform providing accessible resources for researchers, clinicians, and technical teams.
Data Collection and Sources:
- Academic Data: The foundation of CIPHER's academic dataset is a systematic literature review of published, peer-reviewed publications detailing hospital cyberattacks globally. This rigorous process identified approximately 50 case studies of hospital ransomware incidents. To make this data digestible and interactive, the team developed an interactive hospital attacks map. Users can scroll through geographical locations, click on specific attack points, and access detailed information about the attack vector (e.g., WannaCry's global impact, Conti ransomware in Ireland via phishing, Deep Blue Magic ransomware in Israel exploiting a VPN vulnerability), as well as the specific patient harms observed. The research also acknowledges proof-of-concept papers that demonstrate vulnerabilities in networked medical devices, highlighting potential future attack vectors.
- Social Media Data: Recognizing the limitations and delays of academic reporting, CIPHER implemented a data mining algorithm to analyze web and social media data. This involved sifting through over 6,000 posts on platforms like Reddit, specifically targeting support forums and healthcare staff forums. The algorithm searched for keywords associated with known cyberattacks (e.g., "Deep Blue Magic ransomware," "WannaCry," "hack") and terms indicating patient harm or operational disruption. The collected raw data then underwent a crucial clinical validation process, where clinicians on the UC San Diego team reviewed posts to ensure their relevance to specific specialties, assign appropriate harm categories, and exclude non-relevant content or bot-generated posts. This meticulous process resulted in a combined database of over 300 clinically validated patient-level harms.
Data Modeling and Visualization:
The validated data is then transformed into sophisticated models designed to predict and visualize patient events over time. The primary visualization tool is a 3D interactive cube, where patient safety incidents are plotted across three critical axes:
- X-axis (Time): Spanning from "hour one" immediately after an attack up to "day 28," illustrating the temporal progression of harms.
- Y-axis (Clinical Specialties): Representing different medical departments, such as orthopedics, hematology, pediatrics, or psychiatry, to show where harms manifest.
- Z-axis (Technical Systems): Categorizing the affected hospital systems, such as "communications" (for paging systems), "imaging" (for radiology), or "booking systems."
This 3D model allows users to manipulate the graph, filtering for specific clinical specialties (e.g., pediatrics) or focusing on the impact of particular technical system failures (e.g., what happens when only the booking system goes down). The visualizations also distinguish between harms reported via social media versus academic sources, and clicking on a data point provides access to its original source information.
Building on these 3D visualizations, the CIPHER project is developing advanced public health models of cyber clinical risk over time. Inspired by epidemiological models used for phenomena like excess deaths during the COVID-19 pandemic, these models assign a "magnitude score" to each incident based on its severity (morbidity or mortality). This allows for the transformation of the 3D data into 2D plots where the y-axis represents the "seriousness of the harm" and the x-axis represents "time." The ultimate goal is to generate forecasts of patient safety incidents across different specialties, providing a predictive capability for incident response planning. While the intricate mathematical details of these models were not fully elaborated during the talk, Dr. Straw confirmed they will be accessible on the project's GitHub repository, alongside the datasets and demo code.
Demo / Proof of Concept
▶ Watch: Examples of diverse cyberattack vectors on healthcare systems (6:00)
While Dr. Straw's presentation did not include a live, interactive demonstration of the CIPHER platform or an exploit proof-of-concept, she extensively described and visually showcased its capabilities. The "sneak preview" included screenshots and visual representations of the platform's core features. These included the interactive hospital attacks map, allowing users to explore cyberattack case studies geographically and understand their patient harm impacts. She also presented the searchable database functionality for social media posts, demonstrating how users could filter by specialty (e.g., pediatrics, psychiatry), patient vs. staff reports, or specific harm types. The sophisticated 3D visualizations of patient safety incidents across time, clinical specialties, and technical systems were also displayed, illustrating the platform's analytical power. These visual aids served as a comprehensive conceptual demonstration of how the CIPHER platform functions and the insights it provides, with the full platform and code slated for release on GitHub.
Defensive Implications
▶ Watch: Medical device vulnerabilities creating new routes for attacks (6:40)
The insights gleaned from the CIPHER project offer critical guidance for healthcare organizations seeking to bolster their defenses and refine their incident response strategies against increasingly dangerous cyber threats.
Firstly, the paramount implication is the necessity for clinically grounded incident response. Current approaches often prioritize technical recovery, but CIPHER demonstrates that understanding the direct patient impact of system outages is crucial. Technical teams must gain insights into which systems are truly life-critical from a clinical perspective. For example, knowing that a radiology system going down poses a different, and potentially more immediate, threat to life than an e-prescribing system, allows for informed prioritization during an attack. This requires close collaboration and shared understanding between IT security and clinical staff.
Secondly, hospitals must proactively work to minimize "clinical surprise." This involves developing pre-incident plans that identify specific patient groups most at risk if particular technical systems fail, considering the unique demographics and disease burden of the local patient population. For instance, if a hospital serves a high proportion of cancer patients, the resilience of chemotherapy and radiotherapy systems must be paramount. This proactive risk assessment can inform resource allocation, emergency protocols, and communication strategies during a live incident.
Thirdly, the diversity of attack vectors and their consequences (e.g., VPN vulnerabilities, phishing attacks, medical device exploits) underscores the need for multi-layered security strategies that extend beyond traditional perimeter defenses. Continuous vulnerability management, robust patching, and comprehensive employee training on phishing awareness are vital. Furthermore, the specific findings regarding medical device vulnerabilities highlight the need for dedicated medical device security programs, including inventory management, risk assessment, and segmentation of these devices from the broader hospital network.
Fourthly, organizations must address workforce resilience and support. The significant staff fatigue and increased risk of medical errors during cyberattacks necessitate proactive measures, such as cross-training staff for manual workflows, implementing clear communication channels, and providing psychological support. Recognizing that staff are on the front lines of patient care during these events, their well-being directly impacts patient safety.
Finally, CIPHER's findings extend defensive considerations beyond the hospital walls. The impact on community-based palliative care and newborn registration highlights the need for broader disaster preparedness plans that encompass outpatient services and public health functions. Furthermore, the issues surrounding the depletion of life-saving resources (like blood products) and the challenges of patient transfers call for regional collaboration and mutual aid agreements between healthcare facilities to ensure continuity of critical care during widespread outages. Understanding and addressing these complex interdependencies is vital for a truly resilient healthcare ecosystem.
Key Takeaways
- Healthcare cyberattacks have evolved beyond data theft, now directly causing denial of patient care, leading to injuries, diseases, and even deaths, making them a critical public health threat.
- The CIPHER platform provides an open-source, evidence-based approach to model patient harms, integrating data from academic literature and social media to offer a comprehensive view.
- The impact of cyberattacks on patient care is highly diverse, influenced by the attack parameters, the hospital's specific technical dependencies, and the local patient population's health needs.
- Vulnerable patient groups identified include chronic pain, cancer, obstetric, palliative care, trauma, and pediatric patients, often due to disruptions in specialized treatments, monitoring, or medication access.
- Patient harms extend beyond core IT systems to include non-medical infrastructure (e.g., fridges, air conditioning, call lights) and severe workforce fatigue, significantly increasing the risk of medical errors.
- Effective incident response in healthcare must be clinically grounded, prioritizing life-critical systems and anticipating patient harms to minimize "clinical surprise" and improve patient outcomes.
About the Speaker(s)
Dr. D. Isabel Straw is an Emergency Doctor by training who has transitioned into the field of cybersecurity research. She is affiliated with the UC San Diego Center for Healthcare Cyber Security, where she focuses on understanding the impacts of cyberattacks on patient safety and developing clinically informed emergency response strategies. Her unique background allows her to bridge the gap between technical cybersecurity challenges and their real-world consequences in clinical settings, making her a leading voice in this critical area of research. Dr. Straw encouraged attendees to connect with her on LinkedIn for further discussion and updates on the CIPHER project.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
CIPHER is a genuinely novel research initiative that does something the field has been talking about for years but never actually built: a clinically validated, systematically sourced database linking technical system failures to specific patient harms, with a 3D temporal model on top. The dual-source methodology — academic lit review plus social media mining with clinical validation — is smart and fills a real gap. Minor reservations around the model's mathematical rigor not being fully disclosed and the fact that the platform wasn't live yet, but the research direction and execution shown are substantially ahead of anything currently in this space.
Heather Calloway (CISO) — STRONG ACCEPT
CIPHER is doing something most healthcare security work doesn't: building an evidentiary foundation that connects technical failures to clinical consequences with enough rigor to inform both incident response and governance. The research is credible, the framing is honest about what's known and what isn't, and the defender value is real — particularly for healthcare CISOs who have been flying blind on patient impact during outages. The gap is in translating the research into institutional accountability structures and regulatory implications, which limits its reach at the board level.