Nursing homes have joined the ranks of hospitals, healthcare facilities, and other medical practices by converting their traditional records systems into digital systems. The days of storing health records on paper documents in filing cabinets are over.
Now, nursing homes use computer software and digital technology to manage their health records, billing invoices, medication distribution, appointment schedules, and all other aspects of their operations. These digital systems not only improve the efficiency of nursing homes, but also make it easier for staff to access critical information about patients.
Unfortunately, the increasing use of digital technology to manage patient data opens up doors for cybercriminals to target nursing homes and all other healthcare facilities that have upgraded to digital recordkeeping. Cybercriminals can use ransomware and other malicious cyberattacks to steal sensitive patient data for their own selfish purposes. These attacks have only gotten worse for nursing homes.
A Rising Number of Cyberattacks on Healthcare Organizations
According to a 2025 study from JAMA Network Open, U.S. healthcare data breaches experienced more than double the number of data breaches they normally experience between 2010 and 2024.
In 2010, there were only 216 reported incidents of data breaches at healthcare organizations. Fourteen years later, in 2024, there were 566 reported incidents. Within the same period, the number of compromised patient records skyrocketed from 6 million reported incidents to more than 170 million. Cyberattacks have already cost healthcare organizations about $2.4 billion within these 14 years.
The consequences for the nursing homes and their elderly residents are beyond devastating. The first big consequence is identity theft, where the cybercriminal uses an elderly resident’s name and Social Security number to take out unauthorized loans and other financial thefts. Most of the elderly residents are not even aware this is happening until they end up in significant debt and become unable to pay for their nursing home care.
As for the nursing homes themselves, it can cause operational disruptions and system failures for them. Doctors and nurses may be unable to access patient medical records, medication lists, physician communication logs, and other critical documents for delivering quality care. That means the cyberattacks end up compromising the health and safety of elderly residents because they cannot receive the care that they need to stay comfortable, healthy, or alive.
The Growing Threat of Ransomware
Cybercriminals continuously develop new ways to hack and retrieve data on computer systems. However, some of them don’t even care about stealing personal information to commit identity theft. They would rather have the healthcare organization pay money directly to them. That is why ransomware is becoming one of the more common cyberattacks to threaten nursing homes and other healthcare facilities.
In case you have never heard of the term before, ransomware is a type of cyberattack where the cybercriminal prevents an individual or organization from accessing the data on their own computer system. The ransomware will encrypt the files on the computer so that the owner or manager cannot access them. Then, the cybercriminal will demand that the person pay a specific amount of money if they want to regain access to their computer files again.
To make matters worse, modern ransomware cyberattacks now have the capability of stealing sensitive information and locking access to the computer systems at the same time. The cybercriminals will threaten to release the patient information publicly if the nursing homes or patient victims refuse to pay the specified dollar amount.
Nursing homes are particularly attractive targets for cybercriminals because many of these facilities have outdated computer systems with old operating systems and security features. In fact, nursing homes are usually some of the last healthcare facilities to update their systems with the latest security technologies and safeguards against the latest cyberattacks.
Why Nursing Homes Are Liable in Cyberattacks
Nursing homes have much more to worry about from cyberattacks than just operational disruptions and threats to resident health. They also have to worry about their financial and legal costs from the attacks as well.
A successful cyberattack could make a nursing home civilly liable for failing to protect their residents’ sensitive medical information or their physical health in general. Everything, from the regulatory investigations to lawsuits, could ultimately shut down a cyberattacked nursing home, leaving the residents with no place to go for long-term care. If that doesn’t happen, the nursing home will still have to spend a lot of money on legal counsel, forensic investigations, cybersecurity specialists, and system restoration to bring themselves back to normal after the attack.
Any organization, such as a nursing home, that manages patient health information must comply with the federal provisions of the Health Insurance Portability and Accountability Act (HIPAA), particularly the requirements concerning the security and privacy of digitally stored patient health information. When there is a cyberattack or any security breach, federal regulators will investigate to see whether the facility had implemented the appropriate safeguards and risk assessments to protect patient data. If they didn’t, the facility will face significant civil fines, penalties, or worse.
How Elderly Victims Can Seek Compensation for Nursing Home Neglect
When a ransomware or other cyberattack contributes to the financial or physical harm of an elderly resident at a nursing home, the victim may have the legal right to seek compensatory damages from the nursing home. It all depends on whether the facility was neglectful in preventing or responding to the attack. If the elderly victim or their family can prove the nursing home failed to take reasonable precautions or respond appropriately to the attack, they could have a strong case to make against the nursing home for negligence.
Only a licensed and experienced elder abuse law firm can help elderly victims and their families navigate a complex case like this. “The Berberian Firm has represented clients who’ve experienced many different forms of elder abuse, some stemming from ransomware attacks on the outdated computer systems of nursing homes,” said Richard Berberian, the founder and lead attorney of the firm.
“When we proved that those nursing homes failed to upgrade their systems to protect resident data, we were able to win large settlements for our clients who suffered physical health challenges from this neglect.”
Nursing homes cannot afford to delay the inevitable. They must regularly upgrade their computer systems and security software to protect themselves and their residents before it is too late for both.



