← Case Files · The Breach Files

2022 · Public hospital (India)

AIIMS Delhi, 2022: the hospital went back to paper, and the record stayed thin

Case file · 5 min read · Published 15 September 2026

People affected
Reported to involve patient records at national scale; no verified figure was ever published
When it happened
23 November 2022
Made public
23 November 2022
How they got in
Not established publicly; ransomware affecting servers hosting the hospital's e-hospital systems
Attributed to
Never publicly attributed with evidence; official statements and press reports did not agree
What it cost
Outpatient, inpatient, laboratory and billing services on manual processes for roughly two weeks, at a hospital handling thousands of patients a day

What was exposed: Patient records (extent unverified) · Hospital administrative systems · Clinical service availability

On 23 November 2022 the servers running the systems at the All India Institute of Medical Sciences in New Delhi were encrypted. Registration, appointments, laboratory reports and billing moved to paper, at a hospital that sees thousands of outpatients daily and takes referrals from across the country. Nearly four years later, most of the basic facts about the incident remain unestablished.

What happened

AIIMS Delhi is the apex public hospital in India, a referral destination of last resort, with a patient population drawn from every state and a caseload that makes even brief downtime consequential. The attack affected servers hosting its e-hospital systems, the software handling patient registration, appointments, laboratory reporting and billing.

The hospital reverted to manual processes. Patients were registered on paper, reports were handwritten, and queues lengthened at an institution where they are already long. Services were run this way for roughly two weeks before the main systems were progressively restored, with full restoration of all functions taking longer still.

That much is reliably documented, because it was directly observable: journalists were at the hospital, patients described what they encountered, and the hospital issued operational updates. Almost everything past that point becomes contested.

What was never established

Reports at the time cited figures in the tens of millions of patient records at risk, including those of senior political figures. Those figures were attributed to unnamed sources. No forensic finding supporting them was published, and neither the hospital nor the government released a count of affected records.

Press reports described a ransom demand of around ₹200 crore in cryptocurrency. Officials later stated publicly that no ransom demand had been received. Both accounts circulated widely; neither was accompanied by evidence a reader could weigh.

Attribution followed the same pattern. Various claims about the origin of the attack appeared in reporting and in briefings, including assertions of foreign involvement. No supporting technical evidence was published. In an attribution context, that distinction is not pedantry: attribution claims without published indicators cannot be assessed, corroborated, or corrected, and they have a long history of being wrong in ways nobody ever revisits.

Why this file is shorter on facts than the others. Every other case in this archive rests on something durable, a regulator's findings, a court filing, an inquiry report, a company's own technical write-up. For this incident, none of those documents exists publicly. That is not a gap in research; it is the finding. Where no institution is obliged to publish what it learned, the public record of a major attack on public infrastructure consists of press accounts of anonymous briefings, and it stays that way permanently.

The disclosure gap

India's framework at the time placed reporting obligations on organisations to report incidents to CERT-In, the national computer emergency response team, within tight timeframes. That is a real obligation with real value, it gives the national agency visibility. It is not a transparency mechanism. Nothing in it requires that findings be published, that affected individuals be notified, or that a post-incident account ever reach the people whose records were involved.

The Digital Personal Data Protection Act was passed in 2023, after this incident, and introduced notification duties for personal data breaches. Even so, the distinction worth carrying forward is between notifying a regulator and publishing an account. Singapore's SingHealth report and the British Library's post-incident paper exist because institutions chose, or were compelled, to explain themselves in public. Notification to an agency produces no such document.

The practical consequence falls on patients. Someone treated at AIIMS in the years before November 2022 has no way to find out whether their records were affected, no notification to wait for, and no published finding to consult. The absence of a number is not evidence that the number was small.

The timeline

  1. 23 November 2022: Systems at AIIMS Delhi are encrypted; the hospital moves to manual processes.
  2. Late November 2022: A police complaint is filed; national agencies are reported to be involved in the investigation.
  3. Early December 2022: Reports of a large cryptocurrency ransom demand circulate; officials publicly state no demand was received.
  4. December 2022: Core e-hospital services are progressively restored after roughly two weeks of manual operation.
  5. December 2022: Parliamentary statements address the incident without publishing forensic findings or a record count.
  6. 2023: The Digital Personal Data Protection Act is passed, introducing breach notification duties that did not apply at the time of this incident.

What it changed

Within the Indian health system the attack functioned as a warning that landed. Hospital IT security moved up the agenda, advisories circulated across public health institutions, and the specific weaknesses that make hospitals easy, flat networks, shared credentials, unsupported operating systems attached to diagnostic equipment, got more attention than they had before.

What did not change was the documentary record. The incident produced no inquiry report, no regulatory decision setting out findings, and no technical account from which other hospitals could learn specifics. Every institution that wanted to avoid the same outcome had to reason from press coverage. Against that, the countries that publish, including Singapore after SingHealth, and the British Library after Rhysida, hand their entire sector a usable document.

If you were treated at AIIMS before November 2022

Assume the data held about you may have been affected, and that no notification is coming, because none was ever issued. Hospital records in India typically hold name, contact details, address, age, identity numbers where collected, and clinical detail, a combination that supports convincing impersonation rather than direct financial fraud.

The approach that follows is the same one that works for every unverified exposure: treat knowledge of your details as proof of nothing. A caller who cites a genuine past appointment, a test result, or an identity number has established only that they have access to a record. No hospital, insurer or government office completes anything by asking for a one-time password or a payment to an individual account. Ring back on a number you looked up yourself, and treat unexpected contact referencing your medical history with the same suspicion you would give a message about your bank.

Checked against every breach on record, against public breach data only. Your address is not sent to us as a form and is not stored, it is handed straight to the lookup tool in your own browser. See the privacy policy.

Questions people ask

How many patient records were affected?

No verified figure exists. Press reports at the time cited figures in the tens of millions of patient records, including those of prominent individuals, but these were attributed to unnamed sources rather than to any published forensic finding. The hospital and the government did not publish a count. Repeating an unverified number as though it were established is how a large share of breach reporting goes wrong, and this file declines to do it.

Was a ransom demanded?

Press reports described a demand of around ₹200 crore in cryptocurrency. Officials subsequently stated in public that no ransom demand had been received. Both accounts were reported widely and neither was accompanied by evidence. What can be said with confidence is that systems were encrypted and services were disrupted for weeks.

Who was responsible?

This was never established publicly. Investigating agencies were involved and various attributions circulated in the press, including claims of foreign origin. No evidence supporting any specific attribution was published, and attribution asserted without published evidence is not a finding, it is a claim.

Why is there so little documented about a breach this significant?

Because at the time there was no enforced statutory obligation to publish one. India's Digital Personal Data Protection Act was passed in 2023, after this incident, and the reporting duties that did exist ran to a national agency rather than to the public or to patients. Absent a duty to publish findings, there is no mechanism that produces a document like Singapore's SingHealth inquiry report or the British Library's post-incident paper.

Sources

Read next

Case files are written from the public record: regulatory findings, court filings, company disclosures and contemporaneous reporting, cited above. Figures are the ones the organisation or its regulator finally settled on, which is often not the number first reported, where that differs, the page says so. Disputed accounts are marked as disputed rather than resolved in either direction.

← All case files Breach archive →