Our research examines why disaster recovery plans break down against an active adversary, what it actually takes to keep a revenue cycle running through a breach, and how to build the case for your board.
Real health systems. Three outcomes.
The difference between these outcomes was not how sophisticated the attacker was.
It was how long each organization could keep operating without its systems.
Scripps Health
in lost revenue over a four-week ransomware recovery
Ambulance diversion, roughly a month of paper charting, patient portal offline for weeks.
Palomar Health
Fitch credit downgrade tied directly to the attack
Billing "severely disrupted" for about two months; patients reported care delays.
St. Margaret's Health
core IT systems offline; about a year to clear the billing backlog
Closed permanently in 2023. Area EMS now drives 60+ miles to the next hospital.
Sources: Scripps regulatory disclosures & HHS OCR; Fitch Ratings & Becker's Hospital Review; St. Margaret's Form 990 & CNN reporting.
Most payers allow 90 to 180 days to file a clean claim. An outage measured in weeks, followed by a backlog measured in months, pushes a meaningful share of claims past the deadline.
That revenue is not delayed. It is gone, and no recovery project gets it back.
The Recovery In Depth™ series
Five breaches. The standards weren't enough.
Scripps Health
Systems restored in about four weeks. The ~30-letter vendor assurance process ran on its own, slower clock.
The Recovery In Depth™ Lesson: This is exactly the gap Remparo Continuity is built to close: an isolated, HIPAA-compliant environment that was never connected to the compromised network, so eligibility checks, scheduling, and billing keep moving while that proof is still being assembled, not after.
Download Full Case Study (PDF)Ardent Health Services
Epic restored in 12–13 days. Full patient-portal recovery still took seven weeks.
The Recovery In Depth™ Lesson: That's the pattern Remparo Continuity and Vault are built around: keeping the slowest clocks — scheduling, eligibility, and billing — from being the ones that gate a hospital's full return to normal, even when the technical recovery itself goes about as well as it can.
Download StudyAscension
EHR access restored in about five weeks. Reconnecting hundreds of suppliers was still unfinished months later.
The Recovery In Depth™ Lesson: This is the scale problem Remparo Continuity and Vault are built to prevent: keeping eligibility, scheduling, and billing running on infrastructure that never touched the compromised network, so a health system isn't negotiating its way back to normal operations one vendor at a time.
Download StudyCommonSpirit Health
Most markets regained EHR access in about five weeks. Accounts receivable did not normalize for months longer.
The Recovery In Depth™ Lesson: Remparo Continuity is designed to keep billing and claims moving on a separate, trustworthy track from day one, so the receivable pileup this case shows doesn't have to be the default outcome of a breach.
Download StudyProspect Medical Holdings
Services declared back online in 40 days. Financial normalization was still ongoing months after that.
The Recovery In Depth™ Lesson: Remparo Continuity is built for exactly that gap: running billing, scheduling, and eligibility on infrastructure that was never touched by the breach, so a health system isn't still cutting paper checks to vendors months after its systems are declared "back online."
Download StudyThese are independent, publicly reported incidents. The organizations named are not Remparo clients. Recovery In Depth™ analysis reflects Remparo's assessment of the public record, not statements made by the organizations themselves.
Guided Readiness Assessment
Not sure where to start? Take the readiness assessment yourself, right now, or talk it through with our team. A guided session means bringing your existing DR plan to a working session, not a demo — you leave with a scored gap list you can take to your board, whether or not you buy anything. Tell us what's going on and we'll point you the right way.
Want to know where your DR plan stands?
Take our short readiness assessment to gauge how prepared your organization is to respond to a breach incident.
Begin Self-Assessment →Ready to get ahead of a ransomware attack?
You don't assemble your emergency kit during a storm. Plan ahead.
