The next cybersecurity question for hospitals: How big is the blast radius?
UC San Diego researchers have built what they call a “hospital IT system in a box.”
Project CRASHCART is designed to restore patient records, communications and clinical workflows after a cyberattack. Using satellite and cellular connections, it can create a private network that bypasses compromised hospital systems.
It’s a smart response to a problem hospitals are confronting more often: what happens when the network goes down? Cybersecurity has long focused on keeping attackers out. But as hospitals connect more devices, applications, vendors and AI systems, another question matters just as much:
If something is compromised, how far can it go?
Call it the blast radius.
Healthcare’s attack surface is growing because connected care is growing. More connected systems can give clinicians faster access to information, allow devices to work together and support new applications at the edge.

But what does this mean for the architecture underneath connected care? Hospitals often add devices and applications one connection at a time. Over years, this can create an environment in which critical systems depend on layers of point-to-point connections, vendor software and network access that were never designed as one system.
This is where resilience gets harder.
CRASHCART is interesting because it treats continuity as an infrastructure problem: if the primary environment is compromised, create another path for critical information and workflows.
At Astute, we think about the same problem from another direction. The more devices, applications and AI tools a hospital connects, the more important the infrastructure between them becomes. Hospitals need a way to manage how signals move across that environment without making every new connection another dependency to untangle later.
Cybersecurity teams will keep working to stop attacks.
Connected-care infrastructure also has a job: make sure one failure does not become everyone’s failure.




Comments