Register for our August 18 Virtual Event "Nuclear History: Hiroshima, Nagasaki, and the stories we must never forget"

From medicine to ambulances, how the Iran war is exposing US health care vulnerabilities 

By Kristen Cline | Analysis | March 26, 2026

A plume of smoke rises after an explosion on February 28 in Tehran, Iran. After explosions were seen in the Iranian capital, the office of the Israeli Defense Minister issued a statement saying it had launched a preemptive strike against the country. (Smart phone photo by Majid Saeedi/Getty Images)A plume of smoke rises after an explosion on February 28 in Tehran, Iran. After explosions were seen in the Iranian capital, the office of the Israeli Defense Minister issued a statement saying it had launched a preemptive strike against the country. (Smart phone photo by Majid Saeedi/Getty Images)

Listen to this article:

Listen to this article
--:--
This audio was generated using an automated voice. Learn more.

The Lifenet network, built by medical technology company Stryker, is a system emergency crews use to transmit a patient’s electrocardiogram to a receiving hospital while an ambulance is still en route. For a patient having a heart attack, that transmission is what activates a hospital’s cardiac catheterization lab before the patient arrives. In cardiac crises, minutes matter, and on March 11 in Maryland paramedics across the state discovered that their cardiac monitoring system had gone dark.

The cause was not a storm or a power failure. It was a full-scale attack for which an Iran-linked hacking collective called the Handala group claimed responsibility. Once inside the Microsoft Intune environment, the hackers claim to have remotely erased data from 200,000 devices across the company’s operations in 79 countries. The Maryland emergency medical services agency advised clinicians to revert to radio consultations, according to CNN. Stryker, however, said some EMS providers had temporarily paused the system “as a precaution” and that it “was not disrupted by the cyber incident.”

Stryker—a multibillion-dollar medical technology company whose equipment is embedded in hospitals and ambulances across the United States—confirmed a “global network disruption” and filed a regulatory disclosure stating that the timeline for full restoration was unknown. The company said it had “no indication of ransomware or malware” and that the investigation was ongoing. Handala stated the attack was retaliation for the February 28, US airstrike on a school in Minab, Iran, that killed at least 168 people, CNN reported. Handala picked a potentially strategic target: Stryker holds a $450 million contract with the Defense Logistics Agency to supply patient monitoring equipment to the US military.

During active combat, the hackers didn’t choose an aviation manufacturer or an oil company; they chose the health care sector.

The Stryker attack was not an isolated incident, but it exposed how vulnerable health care is across simultaneous dimensions. The US pharmaceutical supply chain depends on China and India for raw materials and on shipping lanes that Iran can now threaten. US hospitals are under cyberattack by Iranian and North Korean actors simultaneously, coinciding with a wave of cyber strikes that against the United States since the Iran war began. The workforce that staffs those hospitals has been hemorrhaging for years and shares personnel with the military reserve system at risk of activation. And the federal agencies responsible for defending the US health care system have been systematically cut.

RELATED:
How to salvage the NPT Review Conference

The chokepoint. When Iran retaliated against the US-Israeli strikes by crippling transit through the narrow Strait of Hormuz, a critical trade route in the Middle East, most media attention fell on oil tankers. Iran’s stranglehold on the strait, however, impacts more than oil prices. For example, the United States imports 47 percent of its generic pharmaceuticals from India, which relies on chemicals and oil that are shipped through and around the strait to produce these drugs.

Since Operation Epic Fury began, tanker traffic through the Strait of Hormuz has dropped approximately 90 percent. And major shipping companies—including Maersk, CMA CGM, and Hapag-Lloyd—have altered their shipping routes.

The pharmaceutical supply chain’s fragility was already proven before the war started. In September 2024, for example, Hurricane Helene flooded a single Baxter International factory in North Carolina and knocked out 60 percent of America’s intravenous (IV) fluid production overnight. Hospitals gave patients Gatorade instead.

Increased cyber-attacks. In the weeks surrounding Handala’s attack on Stryker, cybersecurity researchers documented a convergence of cyber attacks, including on health care-related targets. North Korea’s Lazarus group was  reportedly deploying ransomware against US health care organizations with attacks traced back to November 2025, using infrastructure shared with Russian cybercriminal networks.

The attacks are not surprising.

In 2024, the health care sector suffered more reported cyberthreats than any other US critical infrastructure sector: 444 incidents, including 238 ransomware attacks. A study by University of Minnesota researchers estimated that ransomware attacks were responsible for a decrease in hospital capacity of 17-24 percent and an increase in inpatient mortality of 34-38 percent. These are not just data points, but a quantifiable and predictable loss of human life.

Protecting the health care industry. The cyber threats on health care are coming at a particularly vulnerable moment for the sector. One hundred thousand registered nurses left the profession during COVID, according to the National Council of State Boards of Nursing. New nurses are needed to replace those leaving, but the nursing pipeline is constrained: Over 80,000 qualified nursing school applicants were turned away in 2024 because nursing schools lacked the faculty and other resources to train them. Meanwhile, the Veterans Administration has shed more than 40,000 employees in a single year, including 3,000 registered nurses.

RELATED:
Beyond alarmism: A realistic assessment of Bushehr’s plutonium risk

The Hospital Preparedness Program, a key federal funding source dedicated to hospital emergency readiness, provides grants to hospitals for surge capacity planning, medical supply stockpiling, and coordinated disaster response across state and local health systems. The program faces complete elimination in the fiscal year 2026 budget for the US Health and Human Services Department.

To better secure the health care sector, beyond improved cyber security protection, even more urgent action is necessary. The United States must ensure emergency domestic manufacturing capacity for essential pharmaceuticals, particularly antibiotics, insulin, and generic active pharmaceutical ingredients; in short, drug production lines must be funded with the same urgency as those for producing ammunition. The United States must restore and expand the Hospital Preparedness Program with dedicated surge capacity. And there must be a realistic assessment of what happens to civilian hospitals when reserve medical personnel are deployed to conflict zones.

The United States hardened aviation after the 9/11 terrorist attacks. It hardened financial services after major breaches. It imposed mandatory cybersecurity standards on energy infrastructure and defense contractors. Health care is the sector many of America’s strategic vulnerabilities intersects—supply chains, cyber exposure, workforce depletion. The agency responsible for defending that sector—the Cybersecurity and Infrastructure Security Agency—had lost roughly 30 percent of its workforce by mid-2025.

That agency entered the Iran war with its website noting it was “not actively managed” due to a funding lapse.

Sen. Ron Wyden, the Oregon Democrat, said the current approach to health care cybersecurity was “self-regulation and voluntary best practices,” calling it “woefully inadequate,” in a 2024 letter the Health and Human Services Department. Since then, legislation bolstering cyber security has been moving through the Senate.

Health care is facing multiple threats. The Iran war is exacerbating and surfacing them. The only question left is whether policymakers will treat hospital operations as critical infrastructure before the next disruption becomes a mass-casualty event.


Together, we make the world safer.

The Bulletin elevates expert voices above the noise. But as an independent nonprofit organization, our operations depend on the support of readers like you. Help us continue to deliver quality journalism that holds leaders accountable. Your support of our work at any level is important. In return, we promise our coverage will be understandable, influential, vigilant, solution-oriented, and fair-minded. Together we can make a difference.

Keywords: Iran
Topics: Biosecurity

Get alerts about this thread
Notify of
guest

3 Comments
Oldest
Newest Most Voted
Julius Mazzarella
Julius Mazzarella
4 months ago

Kudos to the author. More attention should be brought to the vulnerability to our health care which I fear people take for granted,

Dean Webb
Dean Webb
4 months ago

We are seeing an uptick in cyberattacks that aren’t doing data exfiltration or ransomware demands – basically, damage is the goal. Skipping those steps necessary to monetize attacks make them harder to detect and faster to execute. Healthcare IT systems must place availability above security, which makes them highly exposed to cyberattacks. With the cuts at CISA and even military staff being told to ignore activity from Russia, the USA health system presents itself as a major target of opportunity. I’m actually surprised we aren’t experiencing greater disruption, but perhaps pro-Iranian attackers and other groups are in early phases of… Read more »

Kristen Cline
Kristen Cline
4 months ago
Reply to  Dean Webb

I honestly think the only reason why the disruption of service in healthcare goes unnoticed is because the government sector has devolved into an unsustainable time bomb. We are so used to dysfunction that it does not even rise to our attention. When doing my research, I was surprised that only one EMS service reported the outage. However after speaking to colleagues, they simply didn’t notice. Striker’s LifeNet ECG transmission system is so unreliable that intermittent outages are little more than an irritation. Healthcare professionals will engineer around issues at the point of service- most hospitals and EMS providers are… Read more »