Local Hospitals Contract Cybersecurity Firms for Regular 'Tabletop' Attack Drills
Following regional breaches, city and suburban health systems are conducting simulations to shore up incident response across networks and connected devices.
By Rashid Karim · March 12, 2026 · 4 min read

Hospitals across New York City and its suburbs have quietly begun hiring outside cybersecurity firms to run regular "tabletop" attack simulations, a response to a spate of regional breaches that exposed the fragile links between clinical devices and hospital networks in neighborhoods from Chelsea to Jamaica and the Bronx waterfront.
The exercises, led by firms such as RidgePoint Security and SecureHarbor Cyber, bring together clinicians, IT staff, legal counsels and communications teams in conference rooms near Bellevue-adjacent Midtown and in suburban command centers to walk through staged scenarios — ransomware locking electronic health records, Trojan malware pushing bogus orders to connected infusion pumps, or attackers disrupting HVAC controls in critical care units.
"We treat the tabletop like a fire drill for decision-making under duress," said Dr. Noor Amin, chief information security officer at East River Medical Center on the Lower East Side. "It forces surgeons, nurses and the CIO to speak the same language about patient safety and gives us a chance to see where our processes break down before an attacker exposes those faults on a weekend night."
Hospitals are signing formal contracts at a brisk pace: 32 metro-area hospitals and 18 affiliated outpatient centers have engaged external tabletop providers since January, up 45 percent from the same period last year, according to a market estimate compiled by a trade group in Manhattan; the average contract runs 9 to 12 months and carries a price tag between $150,000 and $400,000 depending on scope, while the drills themselves typically test networks with 800 to 1,500 endpoints, including infusion pumps, bedside monitors and PACS imaging systems.
Suburban health systems have followed suit. Harborview Health System in Mineola and Westchester Community Hospitals in White Plains have each hosted multi-agency exercises that included local 911 dispatchers and private ambulance operators, a shift designed to mirror real-world logistics when ambulances reroute or hospitals divert patients because of a digital outage affecting bed management systems.
Tabletops vary in realism. Some start with a simulated phishing email and escalate to a ransomware detonation that forces a shutoff of networked EKG machines; others inject supply-chain compromise narratives, where a commonly used device firmware update carries malicious code. Participants map patient-flow disruptions on whiteboards, test failover communications to encrypted mobile lines and rehearse public statements for families waiting in lobbies near Roosevelt Hospital's old outpatient wing in Jackson Heights.
"What we see repeatedly is not a single technology failing but a breakdown in coordination: who pulls the plug on a device, who authorizes the notification to families, who talks to regulators," said Maya Rowan, principal at RidgePoint Security, who has led drills in Brooklyn Navy Yard facilities and in a Chelsea pediatric center. "Tabletops expose those handoffs and let teams practice them until they become muscle memory."
That muscle memory matters at a technical and regulatory level. State regulators and insurers are increasingly asking for documented incident-response exercises as part of oversight and underwriting. A compliance official at a multi-hospital system in Midtown, who requested anonymity to discuss internal remediation, said tabletop findings led to immediate network segmentation between clinical device subnets and administrative traffic and to contracts that require vendors to provide timely firmware patches and authenticated credentials.
Hospitals report early wins: a Manhattan community hospital that staged a tabletop last month discovered default administrative passwords in its infusion pump fleet and required vendors to perform an emergency credential reset across 120 devices; another system corrected a vendor API that allowed an imaging workstation to traverse into a billing server. Executives said tabletop-driven improvements — from software updates to alternate patient-routing protocols — can cost a fraction of a ransomware payout, with preventive upgrades averaging $400,000 per system vs. potential remediation and downtime costs measured in the millions.
Looking ahead, hospital CIOs and outside firms say exercises will get more frequent and more complex, incorporating simulated AI-driven adversaries and including outpatient clinics, ambulance services and radiology centers across borough lines; the goal, administrators say, is not to eliminate risk but to make the response to it routine, so that when an attack arrives the city’s hospitals can keep their lights on and their patients safe.