Why Romania’s Hospitals Are Entrusting Patient Data to Paper
In a healthcare sector relying increasingly on electronic patient records, cloud-based systems and connected healthcare networks, it can be easy to assume that paper records belong firmly in the past. Yet a major cyber-attack on Romania’s healthcare system in 2024 demonstrated exactly why physical records still have an important role to play in protecting patient care and sensitive information.
When ransomware attackers compromised a widely used hospital management platform, Romanian authorities took the extraordinary decision to disconnect more than 100 hospitals from the internet. Doctors, nurses and administrators suddenly found themselves without access to many of the digital tools they relied upon every day. Their solution was simple: they returned to pen and paper.
The incident became an international case study in cyber resilience, showing that while digital systems bring enormous benefits, organisations must never overlook the value of secure offline processes.
When Digital Systems Fail
According to reporting by the BBC, the attack spread through a popular healthcare management system used across Romanian hospitals. Clinical teams lost access to patient records, laboratory requests, test results, pharmacy systems and administrative functions.
To contain the attack, hospitals were instructed to disconnect from the internet immediately. While this helped prevent further spread of the ransomware, it also meant medical staff had to continue caring for patients without many of their normal digital systems.
Paper records, printed documentation and offline processes became essential. Hospitals developed temporary manual systems to register patients, record treatment information and communicate laboratory results while cyber-security teams worked to restore services.
Importantly, patient care continued. Most hospitals were operating close to normal within days, demonstrating that resilient organisations still need practical alternatives when technology becomes unavailable.
Why Healthcare Remains a Prime Target
The Romanian incident is far from unique. Healthcare organisations have become one of the most attractive targets for cyber criminals because they manage large volumes of highly sensitive personal information while delivering services that cannot simply stop operating.
The European Union Agency for Cybersecurity (ENISA) found that ransomware accounted for 54% of analysed cyber threats against the European healthcare sector. Hospitals and healthcare providers were the primary victims in 53% of incidents, while patient data breaches featured in 46% of reported healthcare cyber incidents.
The UK has experienced similar challenges. The 2024 ransomware attack on pathology provider Synnovis disrupted services across several London NHS trusts and reportedly exposed highly sensitive patient information, including records relating to cancer treatment and sexual health services.
Another major incident involved healthcare software provider Advanced, where hackers accessed sensitive information relating to 82,946 individuals. The Information Commissioner’s Office subsequently issued a fine of more than £6 million.
Research cited within the UK healthcare sector has also suggested that 81% of healthcare providers reported experiencing ransomware attacks during 2022.
These figures illustrate a simple reality: healthcare data is both valuable and highly sensitive, making robust information governance essential throughout the entire information lifecycle.
The Security Value of Physical Records
The Romanian response highlights an important distinction. Paper records are not inherently more secure than digital records, nor should organisations abandon digital transformation. However, physical records provide an alternative route when cyber incidents disrupt access to electronic systems.
Unlike connected networks, paper documents cannot be encrypted by ransomware, accessed remotely by attackers or rendered unavailable through network outages.
For healthcare organisations, this creates an important resilience benefit. Critical information can remain accessible even when digital infrastructure is compromised.
However, physical records introduce their own security responsibilities. Patient information recorded on paper remains personal data and must be protected accordingly. Unsecured storage, unauthorised access or improper disposal can create significant compliance and reputational risks.
Secure Disposal Matters Just as Much as Secure Storage
Whether information exists in digital or physical form, organisations remain responsible for protecting it throughout its entire lifecycle.
Under UK GDPR’s Storage Limitation principle, organisations must not retain personal data for longer than necessary and must be able to justify retention periods. Once information is no longer required, it should be securely deleted, anonymised or destroyed.
Article 32 of UK GDPR and EU GDPR requires organisations to implement appropriate technical and organisational measures to protect personal data based on the level of risk involved. This obligation extends to the secure disposal of information-bearing records and media.
For healthcare organisations, the NHS Records Management Code of Practice 2021 provides further requirements around retention schedules, secure destruction processes and maintaining evidence that records have been appropriately destroyed. Responsibility for compliance remains with the healthcare organisation even when destruction activities are outsourced.
The ICO’s audit framework also makes clear that organisations should be able to demonstrate secure disposal procedures, maintain appropriate contracts with destruction providers and obtain evidence of destruction.
Supporting Compliance with SECURALL®
For organisations handling confidential information, secure destruction should never be treated as an afterthought.
Avena Group’s SECURALL® service provides a fully secure and compliant solution for managing confidential paper records from collection through to certified destruction. Secure, lockable consoles and bins provide a theft-resistant and tamper-resistant collection point for sensitive documents, while collections are carried out by thoroughly vetted personnel using Avena’s own fleet of unbranded vehicles.
Every stage of the process is designed around security, compliance and traceability. GDPR audit certification is provided as standard, helping organisations demonstrate responsible information management and compliance obligations.
Additional safeguards include DBS-screened staff, CCTV monitoring and real-time vehicle tracking, creating a secure chain of custody from collection through to destruction.
Importantly, secure destruction doesn’t mean waste. Materials collected through SECURALL® are recycled entirely within the UK through a zero-waste-to-landfill process, producing high-quality recycled pulp while ensuring confidential information is permanently destroyed.
UK hospitals have already benefitted from implementing SECURALL® for their paper-based data security, and the payback has been in more than enhanced data security.
Read the Colchester Hospital Case Study, for example, to find out how switching to Avena Group for confidential data shredding resulted in a safer, more efficient, streamlined waste management process.
Resilience Requires More Than Technology
Romania’s hospitals demonstrated that resilience is not simply about having the latest software or strongest firewall. It also depends on having practical contingency plans, robust information governance and secure processes that continue to function when technology becomes unavailable.
For healthcare providers and any organisation handling sensitive personal information, the lesson is clear: digital security and physical information security must work together. Protecting data doesn’t end when a record is created, and it doesn’t end when that record is no longer needed. Secure handling, secure storage and secure destruction all play a vital role in maintaining trust, compliance and operational continuity.
Ready to adopt a secure confidential waste solution? Speak to one of our experts today.
Do you want a quick quote today? Get a quote today.

