Washington, DC (July 23, 2026) – Healthcare is increasingly moving online, and that poses a growing number of new risks.
In 2024, the ransomware group that breached Change Healthcare stole an astonishing volume of data. 192.7 million people are known to have been affected and had their personal and health information stolen in that single attack. It was the largest healthcare data breach in history. Between 2024 and 2025, the healthcare industry experienced over 700 data breaches, exposing more than 275 million patient records. This was a 63.5 percent increase from 2023 and the largest healthcare data exposure in U.S. history.
Think about what that means for patients who depend on digital systems to access their prescription information. When a cyberattack takes down a healthcare network, or when a ransomware group holds hospital systems hostage, digitally stored medication information can become completely inaccessible. Sometimes for days or weeks at a time. Healthcare breaches cost an average of $7.42 million per incident, the costliest of any industry. The patients caught in the middle rarely see those costs. They just see an error message where their health information used to be.

The FDA is currently weighing a shift toward digital Patient Medication Information (PMI), but as the recent wave of healthcare cyberattacks shows, digital-only formats create real risks for patients. Printed medication information cannot be taken by cybercriminals. When a hospital or pharmacy is locked down by hackers, patients’ printed medication information is still safely sitting on their kitchen counter.
Ransomware attacks remain the primary threat to healthcare organizations. While the financial toll is staggering, the human cost can be even higher. Patients who can’t access their dosing schedules, drug interaction warnings, or refill guidance during a system outage face real health risks.
That’s why the bipartisan Patients’ Right to Know Their Medication Act (H.R. 5133) is a commonsense patient safety measure for the digital age. Requiring manufacturers to include standardized printed medication information with every prescription ensures that no cyberattack can cut a patient off from the information they need to stay safe. Relying on pharmacies to print medication information on demand leaves a critical gap. If a healthcare organization or the FDA itself is hacked or hit with ransomware, pharmacies may lose the ability to generate that information at all, leaving patients without it at the exact moment they need it most.
Technology has a role in healthcare, but critical health information shouldn’t be one system failure away from disappearing. Printed medication information must be preserved as a primary source of critical information and as a backup to technology risks.
For more information about PPLA, click here.
