When Systems Stay Up but Care Starts to Slow: Care slowing while systems remain available and containment must preserve clinical control.When Systems Stay Up but Care Starts to Slow: Care slowing while systems remain available and containment must preserve clinical control.
S10 Group Article series· Why Resilience Changed

When systems stay up
but care starts to slow

Why operational control can begin to erode
while the hospital still appears to be running
Article #1
Originally published: 11 May 2026
Rewritten: 11 September 2026
By Stan van Gemert | S10 Group
By Stan van Gemert

Executive summary

Healthcare cyber incidents do not always begin with full system failure. Care can slow while services remain open because trust in data, suppliers, workflows or clinical dependencies has weakened. This article explains why resilience depends on the ability to contain uncertainty, preserve controlled degraded operations and keep care governable before operational friction becomes a wider cascade.

The hospital did not close. Care still changed.

On 6 April 2026, Signature Healthcare Brockton Hospital reported a cybersecurity incident affecting parts of its information environment. Inpatient care and walk-in emergency services remained open. Surgeries continued. Staff moved to established downtime procedures.

Yet ambulances were diverted. Chemotherapy infusions were cancelled for a day. Pharmacies could advise patients but could not fill prescriptions. Laboratory work and tests continued, although some could be delayed.

No single sentence said that the hospital had stopped. Taken together, they described something more difficult to govern: a hospital still caring for patients while the speed, confidence and reach of normal operations had already narrowed.

This is often how cyber pressure first becomes real in healthcare. Not as total collapse, but as friction. A result takes longer to confirm. A routine workflow needs a second check. A clinical team waits because one digital dependency can no longer be trusted quickly enough.
A hospital can be open and already be losing operational control

The first failure may be trust, not availability

Technical dashboards are good at showing whether systems answer. Care delivery needs more. Information must be timely, reliable and available in the right clinical context. A supplier connection must not merely exist; it must still be safe to use. A result must not merely be visible; it must still be trustworthy enough to support a decision.

That creates a difficult middle state. Systems are not fully down, but normal confidence has gone. Staff compensate with telephone calls, paper records, manual checks, repeated data entry and workarounds that were designed to preserve care for a limited period.
Those workarounds matter. They keep essential activity moving. But they also consume time and attention. As more tasks require confirmation, throughput falls. Queues form. Handoffs become slower. The organisation remains technically active while its practical ability to coordinate care begins to weaken.

Uptime shows whether a system responds.
Resilience shows whether care can still rely on it

Synnovis showed what one degraded dependency can do

The 2024 ransomware attack on Synnovis made this distinction visible across south-east London. Synnovis provides pathology services that sit inside countless clinical decisions: blood tests, specimen analysis, transfusion support and the information needed to plan or continue treatment.

The hospitals did not all cease operating. Urgent and emergency care remained available. Yet the attack significantly reduced the capacity to process tests, delayed outpatient appointments and elective procedures, and forced clinical teams to work around a pathology dependency that could no longer perform normally.

That is why the incident cannot be understood as an isolated supplier outage. Pathology is part of the decision chain. When it slows, the effect appears in other places: treatment planning, theatre schedules, transfusion choices, primary care backlogs and the amount of uncertainty that clinicians must carry.

The resilience question is therefore not simply how quickly a laboratory system can be restored. It is whether care can remain controlled while a trusted dependency is degraded and the full incident boundary is still incomplete.
Operational slowing becomes measurable before collapse
Synnovis / NHS England: NHS England reported that the attack significantly reduced Synnovis’s test-processing capacity and delayed more than 11,000 outpatient and elective-procedure appointments. Later reporting described 10,152 acute outpatient appointments and 1,710 elective procedures postponed at the two most affected trusts. Blood-transfusion cross-matching was also disrupted, requiring greater use of O-type blood while services were restored.

Regional spillover study: A 2023 JAMA Network Open cohort study examined 19,857 visits at two emergency departments adjacent to a separate health system under a month-long ransomware attack. During the attack and recovery phase, the unaffected departments saw significant increases in patient census, ambulance arrivals, waiting-room time, patients leaving without being seen, length of stay and county-wide ambulance diversion.

Process-simulation evidence: A 2025 BMC Medical Informatics and Decision Making paper used real-world data from a German trauma-room process to model cyber-related system outages and degraded technical performance. The proof-of-concept showed how process performance can deteriorate as critical resources become unavailable or less efficient, supporting the need to identify dependencies and tolerable degradation before an incident.

Source caution: Signature Healthcare described a cybersecurity incident; its official notice did not initially classify it as ransomware. The JAMA findings are observational associations, and the BMC work is a simulation model. Use both to demonstrate operational pressure, not to claim universal clinical outcomes or direct causation.
View more details chevron A white downward-facing V-shaped chevron on a transparent background.
View more details
Close more details

Slowing becomes a cascade

One delayed result may be manageable. One paused interface may be absorbed. One manual handoff may be safe. The problem begins when each workaround creates another dependency on scarce people, time and attention.

A clinician waits for confirmation. A laboratory repeats a step. An administrator reconstructs information from another source. A receiving team calls back because the normal exchange cannot be trusted. Each action is reasonable. Together, they reduce the amount of care the system can move safely.

The pressure does not respect organisational boundaries. When one hospital loses capacity, patients move. When patients move, neighbouring emergency departments absorb the demand. A cyber incident inside one organisation can therefore become a continuity problem for an entire regional care system.

The cyber perimeter and the care perimeter are not the same. An incident may begin in one network, one supplier or one service account. Its operational consequences follow the pathways through which care is coordinated.

Downtime is visible. Degraded trust is distributed — and often harder to govern.

The problem is not negligence. It is unmade decisions.

Healthcare organisations do not depend on complex technology because they are careless. They depend on it because modern care is connected, specialised and time-critical. Legacy systems remain in use because replacement is difficult. External providers are necessary. Clinical devices and data exchanges support work that cannot simply pause.

Prevention and compliance remain essential. They reduce exposure, establish discipline and make failure less likely. But they do not make the live decision when a dependency has become unsafe. A policy does not decide which connection can be narrowed. An audit does not determine how long a workflow can operate manually. A framework does not authorise a targeted isolation before every fact is known.

That is the gap between preparation and executable control. The organisation may have documented what should happen, yet still be unable to make the smaller operational move that prevents uncertainty from spreading into more systems, teams and care pathways.

What control would change

Control under pressure is the ability to make bounded decisions before the only remaining choices are unsafe continuation or broad shutdown. In practice, that means leadership and operational teams have already agreed:

  • which clinical pathways depend on which data, identities, platforms and supplier connections
  • which technical paths can be narrowed, paused or isolated without stopping essential care
  • which services can operate in a controlled degraded mode, and for how long
  • who can authorise the first containment move while evidence is still incomplete and
  • what evidence must be preserved so that decisions can later be explained and defended.

The objective is not to eliminate every delay. During a serious incident, some friction may be unavoidable. The objective is to stop local uncertainty from becoming a wider loss of governability.

If one critical dependency became unsafe tomorrow, which care process would slow first, and who could narrow the technical path before clinical teams had to improvise?

Where S10 Group’s platform fits

Our platform does not decide which clinical service takes priority. Instead, it strengthens the operational containment layer, buying clinical, technical, and executive teams the vital room they need to make those decisions

When prevention has been bypassed, our platform detects lateral movement after entry and interrupts malicious behaviour before it spreads further across the environment. It helps protect virtual infrastructure, prevent data theft and stops ransomware encryption before a compromised path places a wider set of systems and workflows in doubt.

For healthcare, the value is practical. Every workload, identity path or supplier route that can be contained precisely is one less dependency that clinical teams need to treat as uncertain. Targeted containment can preserve essential operations while the organisation establishes what happened, what remains trustworthy and what must be restored next.

The result is not perfect normality during an incident. It is a smaller and more governable problem: fewer systems entering the blast radius, fewer workflows forced into emergency workarounds and more decision space before operational slowing becomes a cascade.

The first resilience test is not recovery

Recovery matters, but it comes later. The first test is whether the organisation can keep care governable while trust is incomplete.
A resilient hospital does not pretend that every service will continue at full speed. It knows where slowing will accumulate, which activities must remain available, which dependencies can be restricted and who has authority to act before the complete forensic picture exists.

That is why this article opens the resilience series. Leaders must be able to recognise the incident before every status light turns red. The hospital may still be open. Care may still be moving. But if trust is weakening and no controlled move exists, the cascade has already started.

The first visible sign of cyber failure may not be a system going down. It may be care taking longer to decide what can still be trusted.

Hear first when a new S10 Group release is published

Would you like to receive a short note when S10 Group publishes a new article or newsletter?

Leave your name and email address below. We will send a short update when a new release is available, with a brief summary and a direct link to the publication.

No noise. No automated campaign stream. Just a simple signal when there is something worth reading.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Coming soon

Wednesday 9 September:
"The CISO role changed faster than most organisations adapted."

Friday 11 September:
"The First Alert Was Not the Boundary".

Further readings