The World Health Organization is warning that cyberattacks against health-care systems can go far beyond data theft, disrupting essential services and putting patient safety at risk. As African countries accelerate digitalization in health, the need to strengthen cyber defenses is becoming increasingly urgent.
A hospital can be brought to a standstill without a single physical door being forced open. A cyberattack can lock computer systems, make patient records inaccessible or expose sensitive medical information. For health facilities, the consequences can quickly move from the digital world into the treatment room.
The World Health Organization (WHO) says cyberattacks have emerged as a threat to public health and safety. Health-care organizations have become attractive targets because they hold vast amounts of sensitive information while increasingly depending on interconnected digital systems.
When cybercrime disrupts care
One of the most serious threats is ransomware, in which malicious software blocks
access to data and systems and attackers demand payment to restore them. In a health facility, such an attack can disrupt much more than administrative work.
According to WHO, cyberattacks have led to canceled outpatient appointments and elective surgeries. In more serious cases, emergency departments have had to turn ambulances away, while cancer centers have postponed treatments. The Organization therefore considers cyberattacks on hospitals not simply a matter of confidentiality or financial loss, but potentially a patient-safety issue.
Africa’s digital transformation under pressure
Across Africa, digital technologies are increasingly being integrated into health systems to improve disease surveillance, data management, communication and access to care. Electronic records, telemedicine and connected health platforms can make services more efficient, but they also increase dependence on digital infrastructure.
This creates a challenge for countries that must expand digital health while ensuring that the systems behind it remain secure. Hospitals are not the only potential targets. Laboratories, pharmaceutical companies, medical-device manufacturers, health technology providers and other actors in the health-care supply chain are also increasingly interconnected.
The WHO has highlighted particular difficulties in resource-constrained settings, including shortages of cybersecurity expertise, inadequate governance frameworks and the complexity of securing existing digital infrastructure.
Building stronger digital defenses
For WHO, cybersecurity must therefore become part of health-system preparedness. This means investing not only in technology but also in people and procedures. Staff need cybersecurity awareness, health facilities need tested incident-response plans, and authorities need mechanisms for sharing information about threats and responding rapidly when attacks occur.
The message is increasingly clear: digital transformation cannot be separated from digital protection. As African health systems become more connected, protecting medical data also means protecting the continuity of care.
For patients, the real test of a digital health system is not simply how much technology it can deploy, but whether it can keep delivering care when that technology comes under attack.
