Tuesday, 21 January, 2025, started as a typical day in the radiotherapy department at Cliniques Universitaires St. Luc. Medical consultations and treatments were ongoing, and final verifications were being completed for our new CT simulator, which we were set to start using the next day. Our department is comprised of a main site in Brussels with a CT simulator and two Linacs, and an interconnected satellite site (with one Linac) 30km away.
Around 3 pm, our department began to experience connectivity issues. These included issues accessing Microsoft Teams; our oncology information system (ARIA) and treatment planning systems (Raystation and Ethos) froze; and we had difficulties connecting to our hospital's patient file system. Eventually, all software became unavailable. A public announcement soon followed, informing all users of a global IT breakdown and instructing them to revert to emergency procedures. In our radiotherapy department, this meant that no patients could be treated.
Fortunately, cyberattack publications (Flavin et al., 2022) and national incentives had, to some extent, prepared our department for such an event, and communication with radiotherapy patients was maintained through the use of backup files that contained patient contact and clinical information.
Potential Issues After IT Recovery
Thanks to the diligent efforts of the hospital IT team, our electronic patient records system became partially available on Wednesday, 22 January, and ARIA and our treatment planning systems were gradually recovered. This swift response allowed us to resume treatments on Thursday, 23 January. However, during this recovery period, we encountered several issues that may serve as valuable lessons for other departments.
The IT recovery phase brought several challenges, including significant system slowdowns due to the backlog of tasks, making it essential to prioritise core activities such as treatment delivery. Incomplete server restoration highlighted the risk of data loss, with missing information on cone beam CTs, treatment sessions and approvals. Certain software systems were not fully functional, including that used for surface-guided radiotherapy, and there were access problems with one treatment planning system. Communication with both patients and staff proved critical so that we could manage rescheduling and provide updates on the evolving situation. Finally, the breakdown placed considerable stress on staff, who faced disrupted workflows, inaccessible patient records, and the added pressure of compensating for treatment delays—all of which underscored the value of a brief multidisciplinary debrief to address experiences and lessons learned.
The IT breakdown at our institution revealed a reality that modern radiotherapy departments can no longer ignore: the consequences of an internal IT failure can mirror those of a full‑scale cyberattack. Although this incident was not malicious in origin, the operational impact on patient care, staff workload, data integrity, and clinical workflows was nearly identical. This event underscores the urgency of strengthening digital resilience—not only against external threats, but also against unintentional system failures, which are inherent to increasingly complex hospital infrastructures. Just as the Irish cyberattack illuminated vulnerabilities at the national level, our experience highlights that preparedness must extend beyond cybersecurity alone.
Flavin A, O'Toole E, Murphy L, Ryan R, McClean B, Faul C, McGibney C, Coyne S, O'Boyle G, Small C, Sims C, Kearney M, Coffey M, O'Donovan A. A National Cyberattack Affecting Radiation Therapy: The Irish Experience. Adv Radiat Oncol. 2022 Aug 6;7(5):100914. doi: 10.1016/j.adro.2022.100914. PMID: 36148382; PMCID: PMC9486432.

Aude Vaandering
Radiotherapy quality manager
Cliniques Universitaires St Luc
Brussels, Belgium