From Health 201FailSystems

how automated healthcare fails, how you'd know, and what to do at each tier — every claim sourced, reviewed continuously


Propagation pattern

Cascades

Not a layer: the way one failure crosses power, connectivity, devices, models and handoff, and spreads from one organisation to many.

Reviewed 26 September 2026Sources checked when written 26 September 2026 Involved in 16 of 39 incidents71 sources (68 primary or secondary)

What this layer is

Cascades is not a sixth layer. It is a propagation pattern that runs across the other five: power, connectivity, devices, models and handoff. A cascade starts as a failure in one layer, at one organisation, and turns into a failure in other layers or other organisations. Examples: a remote-access portal is breached and national claims processing stops. A security-software update crashes Windows machines and hospital services go offline. A pathology supplier is hit and three hospital trusts have to call for O-type blood donors.

Safety science has argued for decades that serious accidents in complex systems do not come from one broken part. Perrow called accidents in systems that are both interactively complex and tightly coupled 'normal accidents': they are to be expected, not freak events. Reason's Swiss-cheese model describes harm reaching a patient only when latent conditions and active failures in several defensive layers line up. Leveson's STAMP and CAST treat accidents as a loss of control over the system, not a chain of failed parts. Cook and Rasmussen described how hospitals chasing efficiency 'go solid': the buffers that used to soak up a problem disappear, so that an event in one distant part of the hospital suddenly matters everywhere else. None of these models is settled: professionals disagree on what the parts of the Swiss-cheese model mean, and its critics call it too linear. We use them as lenses, not as laws.

On this site a cascade is described by its path (the order in which it crossed layers, such as devices → connectivity → handoff) and its reach (one department, one hospital, a region, a country). Tracing the path matters because the controls that stop a cascade usually sit at the boundaries between layers and between organisations, and those boundaries are the parts nobody owns.

FailSystems viewAutomation does not add many new ways for a single part to fail. What it adds is coupling. When a hospital runs on a shared EHR, a shared clearinghouse, a shared endpoint agent and a shared pathology network, the same fault reaches every place at once, and the paper workaround has usually withered from lack of use. In our judgement the incidents that do the most harm to patients in automated care will be cascades. Most of them will start outside the hospital, in a supplier the hospital does not control and may not know it depends on. Plan for common-mode failure, not for one component failing on its own.

How it fails

Single shared supplier (concentration risk)

Many hospitals, pharmacies or practices depend on one supplier for one function: claims clearing, pathology, identity, endpoint security. When that supplier fails, every customer loses the function at the same moment, and there is often no quick way to switch because contracts, interfaces and enrolments were built for one path. The customers also cannot see into the supplier, so they cannot judge when service will come back.[1,2,3,4]

Warning signs

  • One supplier handles a function for most of the organisations in your region or specialty
  • No alternate supplier is enrolled or tested, or switching would take weeks of EDI or interface work
  • Contract has no restoration-time commitment or incident-notification clause
  • You cannot list which clinical workflows stop if that supplier is down for 7 days

Seen inChange Healthcare ransomware and national claims/pharmacy clearinghouse outage, Synnovis pathology ransomware, South-East London

Common-mode update

One software or content update is pushed to every installation at once and carries a latent defect that testing missed. Because every machine runs the same code, redundancy inside the hospital does not help: the primary and the backup crash together. Updates designed to ship fast, like security content, are the most exposed.[5,6,7]

Warning signs

  • Vendors can push updates to production endpoints with no staging ring under your control
  • Primary and backup systems run the same agent, OS build or content version
  • No inventory of which clinical workstations and servers run each kernel-level agent
  • Recovery requires hands-on access to each machine

Seen inCrowdStrike Falcon content update crashes Windows hosts, including hospital systems

Tight coupling and lost buffers ('going solid')

Efficiency work strips out slack: spare beds, spare stock, spare staff, manual steps. Activities then depend directly on events elsewhere in the system, so a delay in one place becomes a stoppage in another within hours. In a tightly coupled process there is no time to improvise before the next step needs the output of the failed one.[8,9,10]

Warning signs

  • Just-in-time supply with no local stock for time-critical items (blood, reagents, drugs)
  • Bed occupancy routinely near 100%
  • Paper downtime forms missing, out of date or never drilled
  • Workflows where the next step cannot start without an electronic result

Seen inSynnovis pathology ransomware, South-East London, Texas winter storm: record load shed, hospitals lose water and heat

Cross-infrastructure interdependency

Hospitals depend on utilities that depend on each other. Loss of electricity can stop water treatment and gas supply, which in turn stops hospital heating, sterilisation and toilets. Patients at home on powered equipment lose it at the same time and arrive at the emergency department. The hospital's generator covers its own electricity but not the water pressure or the patients' home equipment.[11,12,13,14]

Warning signs

  • Emergency plan assumes municipal water and gas stay up when the grid is down
  • Boilers or chillers depend on mains water pressure
  • No register of local patients on home oxygen, dialysis or other electricity-dependent equipment
  • Regional plan assumes neighbours can take transfers during a region-wide event

Seen inTexas winter storm: record load shed, hospitals lose water and heat

Regional spillover to neighbouring hospitals

A hospital that goes to downtime diverts ambulances and patients to its neighbours. The neighbours have their own systems intact but not the extra capacity, so waits, walk-outs and delays in time-critical care rise there too. One organisation's cyber incident becomes a capacity incident for the region.[15,16,17]

Warning signs

  • One health system holds a large share of regional inpatient capacity
  • No regional agreement on diversion, transfers or shared downtime capacity
  • EMS diversion hours climbing without a known cause
  • Neighbouring hospitals are told about an outage by the news, not by the affected organisation

Seen inRansomware spillover to adjacent San Diego emergency departments, WannaCry ransomware across the NHS in England

Defensive disconnection

Cutting network links to contain an attack is often the right call, but it causes a cascade of its own. Partners that relied on the link lose the service, and organisations that were never infected shut systems down as a precaution because they lack clear central advice. The outage from containment can be larger than the outage from the attack.[1,16]

Warning signs

  • No pre-agreed criteria for when to disconnect from a partner or supplier
  • No plan for running the services that ride on that connection while it is cut
  • Central incident guidance takes hours to reach local sites

Seen inChange Healthcare ransomware and national claims/pharmacy clearinghouse outage, WannaCry ransomware across the NHS in England

Latent conditions lining up

Most cascades need several existing weaknesses at once: an unpatched system, a portal without multi-factor authentication, a missing bounds check, an untested backup. Each one is tolerable alone and may sit unnoticed for months. The cascade happens when a trigger finds a path through all of them. Use the Swiss-cheese picture with care. A survey of quality and safety professionals found they read its parts (holes, slices, arrow) in very different ways, and critics argue it is too static and linear. Its defenders still consider it useful because it is systemic.[18,16,1,5,19,20,21]

Warning signs

  • Known findings (unpatched hosts, missing MFA, failed audits) carried forward year after year
  • Assessments that were done but gave no one the power to require fixes
  • Incident reviews that stop at the first human or technical 'root cause'

Seen inWannaCry ransomware across the NHS in England, Change Healthcare ransomware and national claims/pharmacy clearinghouse outage, CrowdStrike Falcon content update crashes Windows hosts, including hospital systems

Incidents

CrowdStrike Falcon content update crashes Windows hosts, including hospital systems

A faulty Rapid Response Content update to CrowdStrike's Falcon sensor crashed about 8.5 million Windows devices worldwide. Outside-in measurement found disrupted services at 759 of 2,232 US hospitals studied.[5,30,31,6,7,32,33]

PathDevices → Connectivity & data → Human handoff

Synnovis pathology ransomware, South-East London

Ransomware hit Synnovis, the pathology provider for several south-east London NHS trusts and GP practices. Blood testing and matching collapsed, more than 11,000 appointments and procedures were postponed, O-type blood ran short nationally, and one death was later partly attributed to a delayed result.[34,35,36,37,10,38,39,3]

PathConnectivity & data → Human handoff

Ascension ransomware and multi-week EHR downtime

A ransomware attack took Ascension's electronic records offline for about five weeks. Clinicians told KFF Health News of medication errors and delayed lab results, and one said he had no training for the attack; Ascension said its care teams were trained for such disruptions.[40,41]

Change Healthcare ransomware and national claims/pharmacy clearinghouse outage

Attackers used stolen credentials on a Change Healthcare Citrix remote-access portal that had no multi-factor authentication, then deployed ransomware nine days later. Disconnecting the clearinghouse stalled pharmacy claims, medical claims and payments across the US.[1,2,42,43,44]

PathConnectivity & data → Human handoff

How you'd know

  • Map your dependencies before the event. List every external service a clinical workflow needs (clearinghouse, lab, e-prescribing, identity, endpoint agents, cloud EHR) and mark any service shared with most of your region. If you cannot produce this map, you cannot see a cascade coming.[68,69]
  • Watch external availability, not only internal alarms. During the CrowdStrike outage, researchers detected disrupted hospital services from outside by scanning network ports and FHIR endpoints every few hours. Hospitals and regional coalitions can use the same kind of outside-in monitoring to spot outages at peers and suppliers.[6]
  • Track regional load signals: EMS diversion hours, ambulance arrivals, left-without-being-seen rates and stroke-code volume at your own ED. A sudden rise with no local cause may be a neighbour's outage reaching you.[15]
  • Require suppliers to tell you when they activate their contingency plan. HHS has proposed requiring business associates to report contingency-plan activation within 24 hours. Until that is final, put it in the contract.[44]
  • Treat a rise in workaround use as a signal. Manual claims, phoned results, O-negative use above baseline and paper orders all show that a coupled system has degraded, often before anyone declares an incident.[10,2]

What to do, tier by tier

What should already be in place at each degradation tier for this layer. Tier 0 is normal automated running; tier 3 is paper, batteries and judgement.

These are practices reported or recommended in the cited sources, gathered for reference. They are not a prescription for your organisation; judge what fits your setting, and check the current official text of any standard.

0Full automation

  • Build and keep a dependency map that links each clinical service to the suppliers, networks, devices and utilities it relies on. Review it every year and after any major change.[68,69]
  • Write cybersecurity and restoration requirements into supplier contracts: multi-factor authentication on remote access, a restoration-time commitment, notice within 24 hours of contingency activation, and yearly written evidence of safeguards.[44,1,4]
  • Require staged rollout for any vendor update that runs with kernel or administrator rights on clinical endpoints. Get control over the rollout ring in writing, and keep a sample of clinical workstations on a delayed ring.[5]
  • Do not let your primary and backup depend on the same thing. Where a function is life-critical, make sure the backup uses a different supplier, network path or software stack.[9,7]
  • Close known latent conditions on a deadline: unpatched internet-facing systems, remote-access portals without MFA, unsupported operating systems. Give someone the authority to enforce the deadline.[16,1]

1Assisted operation

  • Enrol an alternate for each concentrated supplier before you need it (for example, a second clearinghouse EDI enrolment, or a reference-lab agreement), and test the switch once a year.[2,17]
  • Set pre-agreed disconnection criteria with key partners: who can cut the link, what runs while it is cut, and what evidence brings it back.[1,16]
  • Keep a read-only copy of the EHR that can print, and test it regularly, so clinicians keep access to records while the primary system or its network is down.[67]
  • When your blood-matching or lab capacity drops, tell your blood supplier the same day, so that O-type stock can be managed nationally rather than drained locally.[10]

2Manual operation

  • Keep enough paper downtime forms in every care area for at least 8 hours of ordering, medication administration, lab and radiology, and run unannounced downtime drills at least once a year.[67]
  • Tell neighbouring hospitals and EMS early when you go on diversion or downtime, and agree in advance how to share load. Regional capacity is a shared resource in a cascade.[15,17]
  • Rank services by clinical criticality and restore in that order. HHS has proposed a 72-hour restoration target for critical systems. Test whether you could meet it.[44]
  • Prepare all staff, not only IT, to deliver care during an extended cyber downtime, and prioritise the services that must stay safe.[47]

3Analog fallback

  • Have signed arrangements with other hospitals to take your patients when your operations are limited or stopped, as the CMS emergency preparedness rule requires. Check that those hospitals do not depend on the same supplier, grid segment or water system as you.[17]
  • Plan for region-wide events where every neighbour is degraded at once. During the Texas freeze, one Austin hospital found no other hospital could take a large number of transfers.[14,11]
  • Plan for your community's electricity-dependent patients coming to the ED for oxygen and power when the grid fails. Keep space, outlets and oxygen supply for them.[13,12]
  • After recovery, review the incident as a control problem (CAST or similar), not a hunt for a root cause. Ask which constraints, feedback loops and decision-makers failed to stop the spread, including at suppliers.[19,70]

Standards and rules (US)

InstrumentWhat it requires
CMS Conditions of Participation, Emergency Preparedness, 42 CFR 482.15Hospitals must base their emergency plan on a facility-based and community-based all-hazards risk assessment, have arrangements with other hospitals to receive patients if operations are limited or stop, keep a communication plan with primary and alternate means, and run exercises at least twice a year.[17]
HIPAA Security Rule NPRM, 90 FR 898 (Jan 6, 2025), RIN 0945-AA22 (proposed, not final)Proposes written procedures to restore critical systems and data within 72 hours, yearly written verification of business associates' technical safeguards, and business-associate notice within 24 hours of activating a contingency plan. It cites the Change Healthcare attack.[44]
NIST SP 800-161 Rev. 1 (May 2022, updated Nov 2024)Guidance for building cybersecurity supply chain risk management into strategy, policy and risk assessment for the products and services an organisation buys, across organisation, mission and system levels.[69]
ASTP/ONC SAFER Guide: Contingency Planning (2025)Self-assessment practices for EHR downtime, including paper forms for at least 8 hours, a tested read-only backup EHR, and unannounced downtime drills at least once a year. CMS requires hospitals to attest to the SAFER Guides annually.[67]
Joint Commission Sentinel Event Alert 67 (Aug 2023)Guidance, not a standard. It calls on organisations to prepare all staff to keep care safe through an extended cyberattack downtime.[47]

Elsewhere: EU and UK

EU: the NIS2 Directive (EU) 2022/2555 requires essential and important entities to manage supply-chain security, including the quality and resilience of suppliers' products and services and cybersecurity terms in contracts with direct suppliers (Art. 21). It also provides for coordinated EU risk assessments of critical supply chains (Art. 22). UK: after Synnovis, the Cyber Security and Resilience (Network and Information Systems) Bill would let regulators designate 'critical suppliers' to essential services, and the government's factsheet uses Synnovis as its case study. The bill was still before Parliament in mid-2026. Netherlands: the Dutch Safety Board found in 2020 that hospitals' awareness of IT-failure risk had not kept pace with their dependence on IT. It recommended that hospitals map IT-to-care dependencies, test and drill regularly, and analyse serious outages in depth.[71,3,68]

Severity score v0.1 draft

4Likelihood
5Blast radius
4Detectability (5 = hardest)
80of 125

FailSystems judgementJudgement, first draft. Likelihood 4: five large healthcare cascades in 2017–2024, three of them in 2024 alone, suggest the pattern recurs every year or two somewhere in the US or UK. Blast radius 5: cascades are by definition failures that spread beyond a single organisation; Change Healthcare and CrowdStrike reached national scale. Detectability 4: the triggering weakness is usually latent and often sits inside a supplier the hospital cannot see into, although once a cascade is running it is obvious.

Each factor is scored 1–5 and multiplied, as in a classic FMEA risk priority number. This is our first-draft judgement, not a measurement; see how scoring works and how it will be revised.

What we don't know yet

  • How much patient harm do cascades cause beyond the first organisation? Only Dameff 2023 measured spillover at neighbours, and it covered one region and one event.
  • Which healthcare functions are most concentrated in single suppliers nationally (clearinghouses, pathology, e-prescribing, identity, EHR hosting), and what share of hospitals share each one?
  • Do contract clauses (restoration times, contingency notice, staged rollout) actually shorten outages, or only move liability?
  • How long does downtime proficiency last after a drill, and how often must paper workflows be practised for a hospital to reach tier 3 safely?
  • Is disconnecting early to contain an attack net-beneficial for patients once the downstream outage it causes is counted?

These gaps drive what the nightly research pass looks for. If you have evidence, send it.

Sources cited on this page

  1. Testimony of Andrew Witty, CEO, UnitedHealth Group, before the Senate Finance Committee: 'Hacking America's Health Care: Assessing the Change Healthcare Cyber Attack and What's Next'. US Senate Committee on Finance, 1 May 2024. Primary Testimony / filing · link checked 2026-09-26
  2. AHA Survey: Change Healthcare Cyberattack Significantly Disrupts Patient Care, Hospitals' Finances. American Hospital Association, 15 March 2024. Secondary Journalism · link checked 2026-09-26
  3. Cyber Security and Resilience (Network and Information Systems) Bill factsheet: Designating critical suppliers. UK Government (GOV.UK), 30 June 2026. Primary Guidance · link checked 2026-09-26
  4. Hospital Cyber Resiliency Initiative Landscape Analysis. HHS 405(d) / Health Sector Coordinating Council with CMS, April 2023. Primary Official report · link checked 2026-09-26
  5. External Technical Root Cause Analysis - Channel File 291. CrowdStrike, 6 August 2024. Supporting Official report · link checked 2026-09-26
  6. Patient Care Technology Disruptions Associated With the CrowdStrike Outage. JAMA Network Open (Tully JL, ... Dameff CJ), 1 July 2025. Primary Peer-reviewed · link checked 2026-09-26
  7. Helping our customers through the CrowdStrike outage. Microsoft (David Weston), 20 July 2024. Supporting Official report · link checked 2026-09-26
  8. "Going solid": a model of system dynamics and consequences for patient safety. Quality and Safety in Health Care 14(2):130-134, 2005. Primary Peer-reviewed · link checked 2026-09-26
  9. Normal Accidents: Living with High-Risk Technologies (Updated Edition). Princeton University Press, 1999. Primary Book · link checked 2026-09-26
  10. O Positive and O Negative donors asked to urgently book appointments to give blood following London hospitals IT incident. NHS Blood and Transplant, 10 June 2024. Primary Official report · link checked 2026-09-26
  11. The February 2021 Cold Weather Outages in Texas and the South Central United States — Tracking of Responses to Recommendations. FERC (with NERC and Regional Entity staff), December 2022. Primary Official report · link checked 2026-09-26
  12. February 2021 Winter Storm-Related Deaths – Texas. Texas Department of State Health Services, 31 December 2021. Primary Official report · link checked 2026-09-26
  13. Texas' power outages, water shortages put bigger strain on hospitals. ABC News, 18 February 2021. Secondary Journalism · link checked 2026-09-26
  14. Boil-Water Advisory in Effect, Low Water Pressure Impacts Austin Hospitals. Circle of Blue, 18 February 2021. Secondary Journalism · link checked 2026-09-26
  15. Ransomware Attack Associated With Disruptions at Adjacent Emergency Departments in the US. JAMA Network Open (Dameff C, Tully J, Chan TC, et al.), 8 May 2023. Primary Peer-reviewed · link checked 2026-09-26
  16. Investigation: WannaCry cyber attack and the NHS. National Audit Office (UK), 27 October 2017. Primary Official report · link checked 2026-09-26
  17. 42 CFR 482.15 Condition of participation: Emergency preparedness (hospitals). eCFR / CMS. Primary Regulation · link checked 2026-09-26
  18. Human error: models and management. BMJ 320(7237):768-770, 2000. Primary Peer-reviewed · link checked 2026-09-26
  19. CAST Handbook: How to Learn More from Incidents and Accidents. Nancy G. Leveson, MIT Partnership for Systems Approaches to Safety and Security, 2019. Primary Guidance · link checked 2026-09-26
  20. The Swiss cheese model of safety incidents: are there holes in the metaphor?. BMC Health Services Research 5:71, 2005. Primary Peer-reviewed · link checked 2026-09-26
  21. Good and bad reasons: The Swiss cheese model and its critics. Safety Science 126:104660, 2020. Primary Peer-reviewed · link checked 2026-09-26
  22. Summary of the Amazon DynamoDB Service Disruption in the Northern Virginia (US-EAST-1) Region. Amazon Web Services, October 2025. Primary Official report · link checked 2026-09-26
  23. AWS outage disrupts Tufts Medicine; other health systems unaffected. Becker's Hospital Review (Naomi Diaz), 21 October 2025. Secondary Journalism · link checked 2026-09-26
  24. AWS outage causes disruption to patient care across NHS sites. Digital Health News (Jordan Sollof), 21 October 2025. Secondary Journalism · link checked 2026-09-26
  25. Final Report on the Grid Incident in Spain and Portugal on 28 April 2025. ENTSO-E Expert Panel, 20 March 2026. Primary Official report · link checked 2026-09-26
  26. La resaca en los hospitales tras salvar el apagón: 'Más allá de cierto caos, hemos sobrevivido bastante bien'. elDiario.es (Sofía Pérez Mendoza), 29 April 2025. Secondary Journalism · link checked 2026-09-26
  27. When the lights went out: impacts of the April 2025 Iberian blackout on the Portuguese National Health Service sovereignty. Frontiers in Public Health, 2025. Primary Peer-reviewed · link checked 2026-09-26
  28. Blackout in Spain: Urgent Analysis of Impact on Emergency Medical Services. Prehospital and Disaster Medicine, December 2025. Primary Peer-reviewed · link checked 2026-09-26
  29. Excess mortality attributable to the 2025 Iberian Peninsula blackout. Nature Communications, July 2026. Primary Peer-reviewed · link checked 2026-09-26
  30. Testimony of Adam Meyers, CrowdStrike, before the House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection: 'An Outage Strikes'. U.S. House Committee on Homeland Security, 24 September 2024. Primary Testimony / filing · link checked 2026-09-26
  31. Microsoft global outage forces hospitals to cancel appointments. STAT (Palmer K, Trang B, Ross C), 19 July 2024. Secondary Journalism · link checked 2026-09-26
  32. Widespread IT Outage Due to CrowdStrike Update. CISA, 19 July 2024. Primary Guidance · link checked 2026-09-26
  33. A look at how Mass General Brigham recovered from the CrowdStrike outage. Healthcare Brew (Cassie McGrath), 11 September 2024. Secondary Journalism · link checked 2026-09-27
  34. Synnovis cyber incident (update of 10 November 2025). NHS England, 10 November 2025. Primary Official report · link checked 2026-09-26
  35. NHS Ransomware Hack Caused Patient Harm in UK, Data Shows. Bloomberg News (Ryan Gallagher), 14 January 2025. Secondary Journalism · link checked 2026-09-26
  36. Ransomware attack contributed to patient's death, says Britain's NHS. The Record by Recorded Future News (Alexander Martin), 25 June 2025. Secondary Journalism · link checked 2026-09-26
  37. Synnovis cyber update. Synnovis, 2025. Supporting Official report · link checked 2026-09-26
  38. Qilin ransomware attack on NHS supplier contributed to patient fatality. The Register, 26 June 2025. Secondary Journalism · link checked 2026-09-26
  39. Ransomware attack continues to disrupt healthcare in London nearly two years later. The Record (Recorded Future News), 2026. Secondary Journalism · link checked 2026-09-26
  40. Cyberattack led to harrowing lapses at Ascension hospitals, clinicians say. KFF Health News (Rachana Pradhan) and Michigan Public (Kate Wells); co-published by NPR, 20 June 2024. Secondary Journalism · link checked 2026-09-26
  41. The state-by-state impact of Ascension's cyberattack. Healthcare Dive, 2024. Secondary Journalism · link checked 2026-09-26
  42. Change Healthcare Cyberattack Underscores Urgent Need to Strengthen Cyber Preparedness for Individual Health Care Organizations and as a Field. American Hospital Association, 2025. Secondary Official report · link checked 2026-09-26
  43. UnitedHealth hikes number of Change cyberattack breach victims to 190 million. Healthcare Dive (Emily Olsen), 27 January 2025. Secondary Journalism · link checked 2026-09-26
  44. HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information (NPRM, FR Doc 2024-30983). HHS Office for Civil Rights, Federal Register 90(3):898-1022, 6 January 2025. Primary Regulation · link checked 2026-09-26
  45. Review of the Guy's and St Thomas' IT Critical Incident — Final report from the Deputy Chief Executive Officer. Guy's and St Thomas' NHS Foundation Trust, January 2023. Primary Official report · link checked 2026-09-26
  46. Incident: cooling related failure in one of our buildings that hosts zone europe-west2-a. Google Cloud Service Health, 19 July 2022. Primary Official report · link checked 2026-09-26
  47. Sentinel Event Alert Issue 67: Preserving patient safety after a cyberattack. The Joint Commission, 15 August 2023. Primary Guidance · link checked 2026-09-26
  48. The February 2021 Cold Weather Outages in Texas and the South Central United States — FERC, NERC and Regional Entity Joint Staff Report (presentation of findings). FERC / NERC, November 2021. Primary Official report · link checked 2026-09-26
  49. Austin hospitals lose water pressure and heat amid winter storm. The Texas Tribune, 17 February 2021. Secondary Journalism · link checked 2026-09-26
  50. Universal Health Services Form 8-K (information technology security incident). Universal Health Services, Inc. / SEC EDGAR, 29 September 2020. Primary Official report · link checked 2026-09-26
  51. Universal Health Services Form 10-K for fiscal year 2020. Universal Health Services, Inc. / SEC EDGAR, 2021. Primary Official report · link checked 2026-09-26
  52. 4 Former Staffers Face Charges Over Nursing Home Deaths After Hurricane Irma. NPR, 26 August 2019. Secondary Journalism · link checked 2026-09-26
  53. Association of Power Outage With Mortality and Hospitalizations Among Florida Nursing Home Residents After Hurricane Irma. JAMA Health Forum, November 2021. Primary Peer-reviewed · link checked 2026-09-26
  54. Lessons learned review of the WannaCry Ransomware Cyber Attack. Department of Health and Social Care / NHS England (William Smart, CIO for Health and Social Care), 1 February 2018. Primary Official report · link checked 2026-09-26
  55. A retrospective impact analysis of the WannaCry cyberattack on the NHS. npj Digital Medicine, 2 October 2019. Primary Peer-reviewed · link checked 2026-09-26
  56. What caused generators to fail at NYC hospitals?. CBS News / Associated Press, 2 November 2012. Secondary Journalism · link checked 2026-09-26
  57. Evacuation of a neonatal intensive care unit in a disaster: lessons from Hurricane Sandy. Pediatrics (American Academy of Pediatrics), 2014. Primary Peer-reviewed · link checked 2026-09-26
  58. Hospital Emergency Preparedness and Response During Superstorm Sandy (OEI-06-13-00260). US HHS Office of Inspector General, 16 September 2014. Primary Official report · link checked 2026-09-26
  59. The Deadly Choices at Memorial. ProPublica / The New York Times Magazine (Sheri Fink), 27 August 2009. Secondary Journalism · link checked 2026-09-26
  60. Hospitals in Hurricane Katrina: Challenges Facing Custodial Institutions in a Disaster. The Urban Institute (Bradford H. Gray, Kathy Hebert), 1 July 2006. Secondary Official report · link checked 2026-09-27
  61. A Failure of Initiative (H. Rpt. 109-377), Medical Care chapter. U.S. House Select Bipartisan Committee on Hurricane Katrina (mirror: LSU Law biotech.law.lsu.edu), 15 February 2006. Primary Official report · link checked 2026-09-27
  62. Blackout of 2003: public health effects and emergency response. Public Health Reports, 2006. Primary Peer-reviewed · link checked 2026-09-26
  63. Lights out: impact of the August 2003 power outage on mortality in New York, NY. Epidemiology, 2012. Primary Peer-reviewed · link checked 2026-09-26
  64. Halamka on Beth Israel's Health-Care IT Disaster. CIO Magazine (Scott Berinato), 15 February 2003. Secondary Journalism · link checked 2026-09-26
  65. All Systems Down. CIO / Computerworld (Scott Berinato), 25 February 2003. Secondary Journalism · link checked 2026-09-26
  66. Computer crash - lessons from a system failure. New England Journal of Medicine 348(10):881-882, 6 March 2003. Primary Peer-reviewed · link checked 2026-09-26
  67. SAFER Guide: Contingency Planning (2025 edition). ASTP/ONC, US Department of Health and Human Services, 2025. Primary Guidance · link checked 2026-09-26
  68. Patient safety during IT outages in hospitals. Dutch Safety Board (Onderzoeksraad voor Veiligheid), 13 February 2020. Primary Official report · link checked 2026-09-26
  69. NIST SP 800-161 Rev. 1: Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations. NIST, May 2022. Primary Standard · link checked 2026-09-26
  70. CAST Handbook: A "Systems Thinking" Approach to the Investigation of Healthcare Adverse Events (Draft). Nancy Leveson, MIT, 28 January 2024. Primary Guidance · link checked 2026-09-26
  71. Directive (EU) 2022/2555 (NIS 2 Directive). European Parliament and Council (EUR-Lex), 14 December 2022. Primary Regulation · link checked 2026-09-26

Cite this pageFailSystems. “Cascades.” https://failsystems.health201.com/layers/cascades/ (reviewed 2026-09-26). Health 201 / AstroNexus LLC. CC BY 4.0.

Information only, not advice. FailSystems is an aggregation and synthesis of published sources. It is not consulting, engineering, legal, regulatory or medical advice, and using it creates no professional relationship. Health systems are complex and no approach fits every organisation: anything you adopt is your own decision, at your own risk, and should be checked against the current official sources and by qualified people who know your setting. Full disclaimer.

Dealing with an incident right now? This site is a reference, not an incident-response service. Activate your organisation's emergency operations plan and incident command, and: