EMTALA’s Inadequacy in the Digital Age

Writer: Geetika Kosuri

Editor: Gabbi McAlonan-Serrano

Associate Editor: Srinidhi Venkitasamy

I. Introduction

    Hospitals have become attractive targets for cyberattacks due to the vast amounts of sensitive patient information they store, relying on uninterrupted digital infrastructures. While treated as privacy concerns, recent ransomware attacks reveal that cyber disruptions can also interfere with emergency medical care. When hospitals lose access to critical networks such as electronic health records (EHRs) and communications, the consequences extend beyond data security into patient care.1 This raises questions under the Emergency Medical Treatment and Labor Act (EMTALA), a statute intended to ensure public access to emergency medical treatment.2 As healthcare becomes increasingly digital, EMTALA’s emergency care obligations rely on operational continuity to a degree not considered in 1986. Ransomware attacks hinder a hospital’s ability to fulfill their legal obligations such as screening, stabilizing, and transferring patients. This highlights the need for federal healthcare preparedness standards to treat cybersecurity risk mitigation as an essential element of emergency care preparedness under EMTALA rather than as a separate compliance concern.

    II. EMTALA and Hospital Emergency Obligations 

      Congress enacted EMTALA in 1986 to prevent “patient dumping,” the practice of refusing comprehensive treatment of patients on the basis of their ability to pay for care, requiring hospitals to provide appropriate medical screening, stabilization, and transfer regardless of a patient’s ability to pay.3 The statute was designed to protect patients’ access to emergency care; however, it was enacted during an era when emergency care operations were significantly less dependent on digital infrastructure. The Centers for Medicare & Medicaid Services (CMS) require hospitals to maintain all-hazards emergency preparedness programs that include risk assessments, communication plans, policies, and training.4 While cyberattacks fall into the all-hazards program, the regulations do not explicitly recognize cybersecurity operational continuity as an essential component of emergency medical preparedness. As hospitals become increasingly dependent on electronic health records, digital communications, and other interconnected systems, disruptions to that infrastructure can directly impair their ability to carry out EMTALA’s screening, stabilization, and transfer obligations. 

      III. Cyberattacks as Operational Healthcare Failures 

        Healthcare cyberattacks are often framed as privacy issues. However, recent ransomware attacks demonstrate that cyberattacks also disrupt the systems through which emergency medical care is delivered.5 This vulnerability is illustrated by the 2024 ransomware attack against Ascension Health. The attack affected portions of the hospital systems’ EHRs and other critical technology networks, prompting clinicians to implement paper documentation and manual workflows while systems were restored.6 Clinicians reported delays in lab results, medication administration communication, and scheduled procedures.7 Patients experienced longer wait times, delays, and uncertainty regarding their care. While not EMTALA violations, these disruptions illustrate how the loss of digital infrastructure impairs hospitals’ ability to perform EMTALA’s screening, stabilization, and transfer obligations. 

        Change Healthcare is a healthcare technology company under UnitedHealth Group (UHG) that processes fifteen billion healthcare transactions annually. It served as the target of a 2024 ransomware attack that disrupted insurance verification, claims processing, and pharmacy transactions across the United States.8 Unlike the Ascension attack, which disrupted operations within a single hospital system, the Change Healthcare breach demonstrated how cyberattacks targeting shared healthcare infrastructure can impair patient care nationwide. According to the American Hospital Association, nearly three-quarters of the surveyed 1,000 hospitals reported direct patient-care impacts, including delays in obtaining authorizations for medically necessary treatment.9 Providers also experienced severe financial strain as reimbursement systems remained offline, forcing some practices to rely on personal funds or risk closure.10 Senators Josh Hawley and Richard Blumenthal warned that although UHG was the victim of an outside attack, “the entire sector is now the victim of UHG’s lack of preparedness and built-in redundancies.”11 Together, Ascension and Change Healthcare reveal that ransomware attacks can disrupt both hospital-level operations and the broader healthcare infrastructure on which hospitals rely, ultimately impairing their ability to carry out EMTALA’s emergency-care obligations. 

        IV. The Legal Gap in Cyber Preparedness Standards 

          Current federal law recognizes both emergency preparedness and cybersecurity, but it does not fully connect the two. EMTALA establishes emergency-care obligations, while CMS emergency preparedness requirements and CISA guidance address hospital resilience. Yet these frameworks do not explicitly recognize cybersecurity operational continuity as a prerequisite to fulfilling EMTALA’s obligations.12

          EMTALA compliance depends on more than a hospital’s physical resources. A cyberattack may not shut down a hospital’s physical resources, but it can deny access to the digital systems that support screening, stabilization, and transfer decisions.13 Providers’ ability to provide emergency care is compromised if they cannot access and communicate patient information, even if their legal duties remain the same. In this sense, ransomware attacks reveal a gap between EMTALA’s obligations to patient care and the technological infrastructure hospitals need to meet them.

          This gap does not require Congress to amend EMTALA itself. Rather, CMS should modernize the emergency preparedness regulations that support hospitals’ ability to carry out EMTALA’s existing obligations. Because CMS already employs an all-hazards framework, explicitly recognizing cybersecurity operational continuity as part of emergency preparedness would modernize the regulatory framework without expanding EMTALA’s statutory duties.14 EMTALA’s purpose remains fully relevant; only the regulatory framework supporting its implementation has failed to keep pace with the digital transformation of emergency medicine.

          For example, CMS could clarify that emergency preparedness planning should include procedures for electronic health record downtime, redundant communication systems, manual documentation workflows, and recovery protocols following cyber incidents. These measures would modernize CMS preparedness standards without expanding EMTALA’s statutory obligations, ensuring hospitals remain capable of performing the duties EMTALA already requires. As emergency care becomes increasingly digital, operational resilience is no longer merely a technology concern, it is a foundational condition of patient care compliance that can be addressed in an amended CMS.

          V. Conclusion 

            EMTALA was enacted to ensure access to emergency medical treatment, but the infrastructure supporting that treatment has changed drastically since 1986. Recent cyberattacks demonstrate that disruptions to digital systems can impair hospitals’ ability to screen, stabilize, and transfer patients, revealing how closely EMTALA compliance has become tied to digital operational continuity. The challenge for healthcare law is not simply responding to cybersecurity failures after they occur, it is recognizing that cybersecurity resilience increasingly affects a hospital’s ability to carry out existing emergency care obligations. Rather than requiring Congress to fundamentally revise EMTALA, modern healthcare needs to call for regulatory guidance that explicitly recognizes cybersecurity operational continuity as an essential component of emergency preparedness. By incorporating cybersecurity resilience into existing CMS emergency preparedness requirements, hospitals would be better equipped to fulfill the emergency-care obligations that EMTALA has required all along.15 As emergency care becomes increasingly digital, operational resilience should be viewed not merely as a technology concern, but as a foundational component of emergency-care readiness.

            1. Susan Li et al., Cyber-Attacks on Hospital Systems: A Narrative Review, 7 Am. J. Geriatric Psychiatry Open Sci., Educ. & Prac. 30 (2025). ↩︎
            2. Emergency Medical Treatment and Labor Act (“EMTALA”), 42 U.S.C. § 1395dd (2024). ↩︎
            3. David A. Ansell & Robert L. Schiff, Patient Dumping: Status, Implications, and Policy Recommendations, 257 JAMA 1500 (1987). ↩︎
            4. 42 C.F.R. § 482.15 (2024). ↩︎
            5. Yuki Noguchi, Hospitals Hit by Ransomware Are Paying the Price in Delayed Care, NPR (Jun. 2024), https://www.npr.org/2024/06/19/nx-s1-5010219/ascension-hospital-ransomware-attack-care-lapses (on file with the Undergraduate Law Review at FSU). ↩︎
            6. Ascension Health, Management Discussion and Analysis Fiscal Year 2024 Fourth Quarter (2024). ↩︎
            7. Id. ↩︎
            8. American Hospital Association, Change Healthcare Cyberattack Underscores Urgent Need to Strengthen Cyber Preparedness for Individual Health Care Organizations and as a Field (Jan. 2025), https://www.aha.org/system/files/media/file/2025/02/Change-Healthcare-Cyberattack-Underscores-Urgent-Need-to-Strengthen-Cyber-Preparedness.pdf (on file with the Undergraduate Law Review at FSU). ↩︎
            9. Id. ↩︎
            10. American Medical Association, Change Healthcare Cyberattack Physician Practice Financial Impact Survey Results (Mar. 2024). ↩︎
            11. HITRUST Alliance, Letter to U.S. Congress and Regulatory Members Regarding the Change Healthcare Cyberattack (Jun. 2024). ↩︎
            12. Cybersecurity and Infrastructure Security Agency, Cybersecurity Performance Goals 2.0 (CPG 2.0), https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0 (on file with the Undergraduate Law Review at FSU). ↩︎
            13. Li et al., supra note 1, at 34. ↩︎
            14. 42 C.F.R. § 482.15 (2026). ↩︎
            15. Emergency Medical Treatment and Labor Act (“EMTALA”), 42 U.S.C. § 1395dd (2024). ↩︎

            Comments

            Leave a comment