What nobody tells you when a hospital gets attacked.
A French hospital takes two years to recover from a ransomware attack. 1,000 workstations, 200 applications, patient records lost forever. I lived through a ransomware attack in 2018. What makes me angry is not the attack.

I lived through a ransomware attack. In 2018. Not in a hospital, in a small organisation. We had backups, and that is what saved us. Two months to recover. Two months in which every morning started with the same question: what works today? Two months rebuilding, checking, doubting every restored file, wondering whether something had been forgotten in some corner of the system. And we were small. A few dozen workstations. A handful of applications.
The Pontarlier hospital, in the Doubs, has been living through the same thing since the night of 18 to 19 October 2025. That night, a cryptolocker-type ransomware paralysed in one go the eight sites of the Centre Hospitalier de Haute-Comté, of which Pontarlier is the main facility. But on a scale beyond comparison. More than 1,000 workstations. Around 200 applications. An information system on which prescriptions, laboratory results, billing, patient monitoring and the phone switchboard all depend. Everything. Six months after the attack, the return to normal is not expected before early 2027.
When you read this kind of thing in the press, you remember the number. Two years. It is shocking, and it goes by fast. What you do not remember is everything that plays out between the incident and that distant date. And yet that is where the heart of it lies.
The daily reality no article describes
What people do not see is an entire hospital running on paper. Handwritten prescriptions. Test results circulating in physical form. Nurses noting by hand what software used to record in two clicks. Doctors who no longer have access to their patients' history. A phone switchboard gone silent for months.
What people do not see is the paralysed billing. The hospital delivers care it can no longer code, examinations it can no longer bill, procedures whose administrative trace exists nowhere. The Agence Régionale de Santé released 2 million euros in exceptional aid. It will not be enough. The operating loss will run into the millions. And some of the procedures carried out during those months will never be recovered. A blood test that does not appear in the digital record at the moment of the rebuild is a procedure that no longer exists administratively. It was done. The patient was treated. But the system will never know it.
What people also do not see is the weight on the teams. I remember, in 2018, the exhaustion that sets in from the second week. Not the exhaustion of one sleepless night. The exhaustion of a continuous effort, with no clear horizon, with no certainty that what you rebuild today will not cause a problem tomorrow. In a small organisation, it was already heavy. In a hospital where caregivers have to take care of patients and at the same time compensate manually for every function that IT used to handle, it is crushing. And it has lasted six months.
Why is the real problem not the attack, but the aftermath?
The director of the Pontarlier hospital is calling for a nationalised protocol to handle these situations. He says his hospital is not the only one going through this. He is right down the line. And that is exactly what makes me angry.
In 2022/2023, the Fédération Wallonie-Bruxelles commissioned a cybersecurity maturity audit of around a hundred Belgian municipal administrations and local authorities. I was the lead auditor on that assignment. I supervised all hundred audits. The findings were damning: an appalling level of maturity, exposed infrastructure, continuity plans that were non-existent or theoretical, teams without resources and without training.
Among the recommendations I handed in, there was one I considered structural: the creation, at the federal level, of a dedicated emergency response capability. Not a best-practices guide. Not yet another framework. An operational response force, able to intervene concretely on the most serious cases, to streamline the rebuilding effort, to pool the technical skills these organisations cannot afford to maintain in-house. The idea was simple: nationalise the remediation effort so that affected institutions can get back on their feet as quickly as possible, instead of leaving them alone in the face of a disaster they have neither the skills nor the budget to handle.
That was in 2023. We are in 2026. Nothing has happened. Neither this recommendation, nor any of the others, for that matter.
How many French hospitals are hit by a cyberattack?
The director is right: Pontarlier is nothing like an isolated case. In 2024, CERT Santé, the state service in charge of incidents in the healthcare sector, received 749 security reports, up 29% in a year, filed by 558 organisations. Among them, forty ransomware attacks, including four major compromises. Four hospitals, in a single year, plunged into exactly what Pontarlier is living through.
And the phenomenon is nothing new. On the night of 20 to 21 August 2022, the Centre Hospitalier Sud-Francilien in Corbeil-Essonnes fell to the LockBit ransomware. The hospital refused to pay, and entire medical records ended up online. On 3 December of the same year, the André-Mignot hospital in Versailles triggered its emergency plan and transferred intensive care patients for want of an information system. Every time, the same scene: an organisation alone in front of the rubble, a rebuild that stretches over months, and a few weeks later another one starting from zero, recovering nothing of what the previous one had learned.
Every hospital for itself, and ransomware for all
What is playing out in Pontarlier is exactly the scenario we described three years ago. A public, medium-sized organisation, without the resources of a university hospital, left alone in the face of a two-year rebuild. With welcome but insufficient financial aid. With exhausted teams. With lost data. With 700,000 euros of equipment to buy back and an operating loss in the millions. And with no dedicated national structure to come and lay hands on the system and speed up the rebuild.
Are NIS2 and the CaRE programme enough the day after an attack?
The hospital chose to rebuild with a level of security aligned with NIS2. That is brave and it is necessary. But NIS2 is a prevention framework. What Pontarlier needed the day after the attack was not a framework. It was a team. People able to land on site, assess the damage, prioritise the rebuild, bring a technical baseline back up in weeks rather than months. And to build on that experience so that the next hospital does not start from scratch.
Some will tell me the state is not standing idle, and that is true. CERT Santé runs a support service reachable day and night, ANSSI provides methodological guidance, and the CaRE programme, launched in late 2023, promises 750 million euros by 2027 to raise the level of healthcare organisations, with a strand specifically dedicated to business continuity and recovery strategies. None of that is useless, quite the opposite. But look at what it is: funding, method, coordination, prevention. Not one of those building blocks lands in Pontarlier on a Monday morning to bring a thousand workstations and two hundred applications back up. CERT Santé advises, it does not rebuild. CaRE funds the before, not the during. NIS2 describes what the system afterwards should look like, not who is going to rebuild it.
That kind of capability exists in some countries. It exists in the private sector for organisations that can afford incident response contracts with specialised providers. It does not exist for a provincial hospital. It does not exist for a town of 15,000 people. It does not exist for the organisations that need it most.
What Pontarlier should set off
I hold nothing against the Pontarlier hospital. They make do with what they have, and the transparency they show is remarkable. What I hold against the system is the structural inertia that means, in 2026, a healthcare organisation hit by ransomware still finds itself alone in the face of two years of rebuilding.
We had made the diagnosis in 2023. We had formulated the recommendation. The answer was silence. And during that silence, the attacks continued, the organisations kept falling, and each one kept getting back on its feet alone, in its own corner, with its own means, reinventing the same solutions the previous one had invented six months earlier.
When I look back on our two months of rebuilding in 2018, with our small organisation and our backups that worked, I measure the gap. Two months was already a chasm. Two years, for a hospital, is another dimension entirely. And the difference between the two is not only a question of size. It is a question of solitude.
The next Pontarlier is already in the queue. The question is not whether it will fall. It is whether it will still be alone when it does.
Sources
- Situation update, 2 million euros in exceptional aid and national support (ANSSI, CERT Santé, CaRE programme): Agence régionale de santé Bourgogne-Franche-Comté.
- Return to paper and fax, 700,000 euros of equipment, operating loss in the millions and the director's call for a national protocol: France 3 Bourgogne-Franche-Comté and Hebdo 25.
- Rebuild running until 2027, 1,000 workstations and 200 applications: Hospimedia and Le Quotidien du Médecin.
- 749 incidents reported in 2024, up 29% and 40 ransomware attacks: Agence du numérique en santé, Observatoire CERT Santé 2024 and Le Quotidien du Médecin.
- CaRE programme, 750 million euros by 2027 and the continuity and recovery strand: Agence du numérique en santé and Hospitalia.
- Cyberattacks on Corbeil-Essonnes (August 2022) and Versailles André-Mignot (December 2022): Le Monde Informatique and Le Monde Informatique.
- NIS2 Directive (EU) 2022/2555: EUR-Lex.
Frequently asked questions
What happened at the Pontarlier hospital?
On the night of 18 to 19 October 2025, a cryptolocker-type ransomware brought down the information system of the Centre Hospitalier de Haute-Comté and its eight sites. More than 1,000 workstations and around 200 applications are affected, and the return to normal is not expected before early 2027.
Why does the rebuild take so long?
An information system on which prescriptions, laboratory results, billing, patient monitoring and the phone switchboard depend has to be rebuilt and checked piece by piece. For a medium-sized organisation, without the resources of a university hospital or a dedicated national rebuilding force, the effort runs into months, even years.
What are the invisible consequences of such an attack?
Running on paper, care delivered but impossible to code or bill, procedures that vanish administratively, and a crushing, lasting burden on caregivers who compensate manually for every IT function.
How many French hospitals are hit by a cyberattack?
In 2024, CERT Santé received 749 reports of security incidents, up 29% in a year, filed by 558 organisations, including 40 ransomware attacks and 4 major compromises. Pontarlier is part of a long series: Corbeil-Essonnes in 2022, Versailles the same year, and many others since.
Does the CaRE programme cover rebuilding after an attack?
The CaRE programme, launched in late 2023, provides 750 million euros by 2027 to raise the security level of healthcare organisations, with a strand dedicated to business continuity and recovery strategies. It is a valuable prevention effort, but it is not an operational team that lands on site to bring the system back up after the attack.
What solution does the author advocate?
The creation of a national emergency remediation capability: an operational team able to intervene on site, to prioritise and speed up the rebuild, and to build on that experience for the next organisations, rather than yet another framework.
Is NIS2 enough to answer the problem?
No. NIS2 is a prevention framework, brave and necessary for rebuilding with a better level of security, but it does not replace the operational response force an organisation needs the day after an attack.

Être en cybersécurité
A cyber roadmap in plain language, for everyone, not just the experts.
