Written by Ehrun Omuemu, PharmD 2027
September 16, 2024
The CrowdStrike Outage: A Seismic Disruption to Healthcare
On July 19, 2024, a global IT outage caused by a faulty CrowdStrike update sent shockwaves through the healthcare industry, severely impacting Electronic Health Record (EHR) systems and telemedicine services. CrowdStrike, a leading cybersecurity firm, released an update for its Falcon product, a cloud-based platform designed to prevent breaches. However, this update contained a critical flaw that caused Windows-based devices to crash, resulting in the infamous "blue screen of death". This incident highlighted the critical role of cybersecurity in modern healthcare and exposed vulnerabilities in our increasingly digitized medical infrastructure.
Epic Systems, the most widely used EHR platform in the United States, found itself at the center of this digital storm. While Epic's software and services were not directly affected, the CrowdStrike update created significant technical issues that prevented healthcare organizations from accessing their Epic EHR systems. Many hospitals and health systems reported that staff workstations used to access Epic were down. In contrast, others experienced issues with data center software that blocked access to multiple systems, including Epic. This disruption forced healthcare providers to revert to manual, paper-based processes, significantly slowing operations and potentially impacting patient care.
The outage also had a profound effect on telemedicine services, which have become increasingly vital since the COVID-19 pandemic. Epic's cloud-based platform, Nebula, experienced disruptions due to a separate but concurrent Azure Central region outage, knocking some features such as telehealth visits offline. This double whammy of technical issues left many healthcare providers scrambling to maintain continuity of care for patients relying on remote consultations. The incident underscored the vulnerability of telemedicine infrastructure and the need for a robust backup system.
The impact of the CrowdStrike outage extended far beyond Epic and telemedicine services. Hospitals and health systems across the United States, United Kingdom, Israel, and Germany reported significant disruptions. Many were forced to cancel non-urgent surgeries, procedures, and medical appointments. Some facilities, like Mass General Brigham, had to cancel all previously scheduled non-urgent surgeries, procedures, and medical visits.
In the aftermath of the outage, healthcare IT teams worked tirelessly to implement fixes and restore systems. CrowdStrike released patches and workarounds, but the recovery process was not smooth for all affected organizations. Some health systems, like Providence, estimated it would take up to four weeks to return all their computers online.
This incident serves as a stark reminder of the healthcare industry's reliance on digital infrastructure and the potential consequences of IT failures. It highlights the need for:
1. Robust disaster recovery and business continuity plans
2. Regular testing of downtime procedures
3. Improved redundancy in critical systems
4. Enhanced cybersecurity measures and updated testing protocols
The CrowdStrike outage of July 2024 will likely be remembered as a landmark moment in healthcare IT. It exposed vulnerabilities in our digital health infrastructure and emphasized the delicate balance between technological advancement and system reliability. As the healthcare industry continues to digitize, it must prioritize resilience and redundancy to ensure that patient care remains uninterrupted, even in the face of unforeseen technical challenges.
References:
LaPointe J. Crowdstrike outage hits US hospitals. Healthcare Dive. https://www.healthcaredive.com/news/crowdstrike-outage-hits-us-hospitals/721887/. Published July 19, 2024. Accessed September 15, 2024.
Green J. Global IT outage disrupts Epic EHR systems. Becker's Hospital Review. https://www.beckershospitalreview.com/ehrs/global-it-outage-disrupts-epic-ehr-systems.html. Published July 19, 2024. Accessed September 15, 2024.
Taylor H. Latest live updates on a major IT outage spreading worldwide. CNBC. https://www.cnbc.com/2024/07/19/latest-live-updates-on-a-major-it-outage-spreading-worldwide.html. Published July 19, 2024. Accessed September 16, 2024.
Sullivan T. Worldwide IT disruption disrupts healthcare delivery. Healthcare IT News. https://www.healthcareitnews.com/news/worldwide-it-disruption-disrupts-healthcare-delivery. Published July 19, 2024. Accessed September 16, 2024.
Muoio D. Crowdstrike outage disrupts hospitals including Intermountain, Providence. Modern Healthcare. https://www.modernhealthcare.com/digital-health/crowdstrike-outage-hospitals-intermountain-providence. Published July 22, 2024. Accessed September 16, 2024.