Hospitals and Water Systems Are Facing a New Kind of Cyber Threat. Here’s What Experts Are Warning
Cybersecurity threats against critical infrastructure have become a national issue as hospitals, water systems, and power operators rely on more internet-connected equipment. The latest warnings have focused on hospitals and drinking water utilities, where federal officials and security firms say attackers are targeting operational technology and hard-to-patch devices. In communities across the U.S., that means risks are no longer limited to stolen data and can now affect basic services people use every day.
Federal warnings put hospitals and water systems in focus

On Jan. 18, 2024, the Environmental Protection Agency and the White House said cybersecurity weaknesses at drinking water systems were a growing concern, with EPA noting that about 70% of utilities it inspected did not fully meet basic cyber requirements. The same month, the U.S. Department of Health and Human Services said the health sector faced elevated cyber risk after years of ransomware attacks that disrupted care, records, and billing systems. Those warnings centered on a newer problem for many operators: connected control systems, remote access tools, and internet-facing devices that were not built with modern security in mind.
Security researchers have tracked the same pattern. In a 2024 report, Claroty said healthcare and water operators increasingly depend on operational technology and Internet of Medical Things devices, many of which stay in service for 10 years or longer. The Cybersecurity and Infrastructure Security Agency has also repeatedly warned that internet-exposed industrial control systems can give attackers a path into essential operations, including pumps, treatment controls, imaging equipment, and building systems.
The local impact is biggest where systems are small and old

The practical risk often lands hardest at the local level. In Pennsylvania, Texas, and California, state and federal agencies have investigated cyber incidents tied to municipal water providers in the past two years, but officials have not released a comprehensive national list of every affected utility. In healthcare, HHS has said smaller hospitals, including rural facilities, often have fewer security staff and older machines, which can leave them more exposed when a vendor issue or ransomware attack spreads across networks.
What is confirmed is that service disruptions can quickly become local problems. In 2023 and 2024, several hospitals around the U.S. diverted patients or delayed procedures after cyber incidents, according to public statements from health systems and state agencies. In the water sector, EPA has said many small and mid-sized utilities lack dedicated cybersecurity personnel, and the agency has linked that staffing gap to slower patching, weaker passwords, and outdated remote-access setups.
Why experts say this threat is changing for residents

Experts say the shift is happening because more critical equipment is connected than it was a decade ago. The American Hospital Association said in 2024 that hospitals depend on networked imaging systems, smart infusion pumps, electronic records, and third-party software vendors, creating more possible entry points. In the water sector, the Government Accountability Office and CISA have both said many utilities still run legacy control systems that were designed for reliability, not internet security, and can be difficult or expensive to replace.
For residents, that means the consequences can extend beyond a data breach. A hospital cyberattack can delay lab work, prescriptions, or emergency transfers, while a utility intrusion can force manual operations or precautionary shutdowns, according to CISA guidance and EPA statements. Federal agencies have said there is no single fix, but the current message is clear: threats to critical infrastructure increasingly involve the connected systems behind local services, not just the computers in the front office.