Ransomware and cyber incidents targeting hospital digital infrastructure have emerged as genuine patient-safety threats yet remain underrecognized in critical care practice.Intensive care units (ICUs) are uniquely vulnerable: Physiological states are tightly coupled to digital workflows, electronic health records (EHRs) anchor medication safety, and dense Internet of Medical Things (IoMT) environments expand the attack surface.India faces a compounded risk-the 2022 All India Institute of Medical Sciences (AIIMS) Delhi ransomware attack exposed fragmented systems, an absence of post-incident clinical surveillance, and the operational reality that "Western" cybersecurity fixes do not translate directly to resourcevariable settings.This Viewpoint reframes cyber-resilience as a bedside safety competency rather than an information technology (IT) concern and proposes a resource-stratified three-tier preparedness framework.Tier 1 defines minimum viable controls achievable by any ICU: Downtime kits, paper medication administration records (MARs), designated roles, and structured drills.Tier 2 adds targeted redundancy; tier 3 outlines advanced capabilities for tertiary centers.When digital systems fail, patient survival depends on analog competencies practiced before the crisis.
Choudhuri et al. (Mon,) studied this question.