
What ‘The Pitt’ got right on a hospital ransomware attack
Key Takeaways
- Reverting to paper workflows can preserve clinical operations, but transfer coordination, census accuracy, and documentation integrity quickly become bottlenecks without rehearsed, role-specific downtime processes.
- Executives must make layered containment decisions amid partial encryption and uncertain vendor exposure, prioritizing life-safety and time-critical diagnostic systems while documenting dependencies and restoration order.
Cyberattacks don’t end in an hour. Hospitals must understand what real recovery demands.
Midway through the second season of “The Pitt,” the alarm at the fictional Pittsburgh Trauma Medical Center is not a code blue. It is the CEO walking the floor and telling the staff that the network is going dark. Two nearby hospitals have been hit with ransomware, and PTMC’s own systems are going offline as a precaution.
Within minutes, the chart rack is back, the fax machine is humming, and orders are moving on paper. Any healthcare leader who has lived through a real cyber incident will recognize the texture immediately, and the show captures something the industry has spent years trying to make legible to the public.
A ransomware attack on a hospital is not, first and foremost, a data breach. It is an operational event. It is care delivery under stress.
Where the show is most credible is in the analog hours. The fax machine, the dry-erase board, the printed census sheets, the difficulty of coordinating transfers without a shared digital record: these match the lived experience of staff at affected hospitals over the years and the many providers caught downstream from a ransomware incident. The show gets the texture right.
Where the show necessarily compresses, the gap is wide. And the gap is exactly where healthcare leaders need to be paying attention.
The decision to go offline is rarely that clean
In the show, a single decisive call takes patient systems offline. In real life, that decision is one of the hardest a hospital executive will ever make, and it is almost never that clean. Ransomware events are layered. Some systems are encrypted. Others are degraded. Others appear normal. Connections to third-party vendors may or may not be compromised, and visibility into those vendor environments is often limited. It is rarely a binary call. It is a series of decisions made under time pressure with incomplete information.
That is why mature incident response programs do not simply identify what to take offline. They identify what cannot go offline: life-safety systems, infusion pumps, monitoring, imaging needed for stroke and trauma decisions, and the order in which systems should come back online once recovery begins. Critical systems are mapped. Dependencies are documented. They don’t come back all at once.
Recovery is not an hour. It is months.
The most consequential compression in “The Pitt” is the resolution. By the end of the storyline, the threat is described as fading, other affected hospitals are reported to have paid the ransom, and PTMC brings digital systems back online, confident in their own security.
In a real hospital, that is not where a ransomware story ends. That is where it begins.
The
Paying the ransom does not change that timeline materially. It does not restore systems cleanly, remove the attacker from the environment, or address the conditions that allowed initial access. Forensic validation, identity resets, infrastructure rebuilds, and trust restoration take time, and that’s true whether or not a payment is made.
Improvisation is not a plan
There is a moment in the show where a med student saves the department by reciting the patient board from memory after a resident’s phone capture comes out blurry. It plays as a heroic flourish, and it is good television. It is also a vivid illustration of what hospitals should not be relying on. Photographic memory is not a downtime procedure. The difference between competent ransomware response and chaos is not improvisation. It is preparation.
That preparation begins with knowing what you actually have. A current, asset-based risk analysis — one that maps critical clinical systems, the data flows between them, and the dependencies that determine what stops working when something else fails — is the foundation every other control sits on. Without it, downtime planning, third-party governance, and recovery sequencing rest on guesswork.
From there comes the unglamorous work.
Documenting downtime procedures that nurses, technicians, and physicians can actually execute under pressure. Running tabletop exercises with operational, clinical, communications, and supply chain leaders, not just IT. Drilling staff on paper workflows often enough that they do not need to relearn them mid-incident. Running varied scenarios, because no two attacks unfold the same way. The question is not if. It is when.
Where the industry is making progress, and where gaps remain
Healthcare has learned a great deal since ransomware attacks against the industry began accelerating in the early 2020s. Downtime procedures are more formal. Tabletop exercises are more common. Boards are asking sharper questions. Industry-led collaboration through the Health Sector Coordinating Council and the Health-Information Sharing and Analysis Center is also accelerating cross-organization preparedness.
But the gaps remain operational. Third-party and supply chain dependencies are still under-mapped at most organizations, even after Change Healthcare demonstrated how a single vendor outage can cascade across the sector. Identity and privileged access governance is uneven, particularly across hybrid cloud and acquired environments. Recovery planning still concentrates on technology restoration rather than clinical continuity. And too many organizations still treat cybersecurity as an annual compliance event rather than a continuous discipline.
Heading into the second half of 2026, the question for hospital leaders is not whether they could be hit. It is whether their plan accounts for an event that lasts weeks, not hours, and whether the organization has the visibility, drilled response, and discipline to make that plan real.
A television episode ends in an hour. A ransomware incident does not. The hospitals that come through best are the ones that planned long before the network went dark.
Baxter Lee is president at Clearwater Security.































