The Aftermath of a Cyberattack: Inside Scripps Health Hospital in San Diego

Inside Scripps Health in San Diego Following a Devastating Cyberattack
A firsthand experience shared by our Chairman of the Board, Besim Oktayer:
Scripps is renowned as one of the premier healthcare networks in the United States. Six days ago, my wife was admitted through the emergency room at Scripps after suffering a fall that fractured her hip and arm. Prior to our arrival, the hospital had suffered a major cyberattack, and hackers were demanding a ransom. The FBI intervened, stating that negotiations with extortionists would not take place and taking control of the digital systems to investigate. Although 17 days had passed since the intrusion began, their computer systems were still completely offline.
Through this ordeal, I witnessed firsthand the catastrophic consequences when an enterprise of this scale has its IT infrastructure frozen: Only critical emergency room patients were being accepted, and regular hospital operations had ground to a halt. Staff members could not even determine which patients occupied which rooms without physically walking the corridors to check names taped to doorframes. Email communications were entirely disabled. Doctors could not access diagnoses, patient charts, or X-rays digitally; they had to rely exclusively on physical paper files hurriedly delivered before surgery, with everything hand-recorded. Before my wife entered the operating room, the surgeon remarked, “I was unaware of the arm fracture because the X-ray never reached me; today I can only operate on her hip, and we will perform the elbow surgery two days later.” The billing and accounting systems were equally paralyzed—staff could not generate statements, issue invoices, or process payments. No one could even estimate how long it would take to manually transcribe weeks of paper records back into the digital database once systems were restored. We ultimately were discharged from the hospital without receiving discharge paperwork or paying, as staff noted they would contact us whenever their systems recovered.
In short, the extent of operational collapse exceeded anything one could imagine. If you do not want your enterprise to face a similar crisis, keep cybersecurity risk persistently at the top of your leadership agenda. Just as you place physical security guards at your premises, continuously audit your cybersecurity posture and eliminate vulnerabilities before attackers exploit them.


