What happens to healthcare if staff lose access to critical patient data for up to 72 hours? During Arendal Week 2026, Norwegian health technology company Aidn is bringing together experts to examine how robust Norway's digital health preparedness really is.
Digitalization has made healthcare faster, more cohesive and increasingly data-driven. At the same time, the reliance on medical record systems, cloud services and functioning communication channels has created new vulnerabilities. A prolonged IT outage or a targeted cyberattack can quickly impact both workflows and patient safety.
This is the starting point for Aidn's program during Arendal Week in Norway on August 10–12. Together with cybersecurity company mnemonic, medical record system provider DIPS and industry organization NHO Geneo, among others, the company wants to promote digital preparedness, usability and security in public healthcare.
72 hours in digital darkness
The most concrete question is formulated in the debate ”72 hours in the dark – how robust is Norway’s digital health preparedness?”. The scenario is that healthcare professionals lack access to critical health data for three days. This tests not only the technology, but also the organization’s backup routines, division of responsibilities and ability to make safe decisions under time pressure.
Electronic patient records contain information that can be crucial for the correct treatment: diagnoses, medications, allergies, test results and previous interventions. If the systems become unavailable, operations must be able to continue without the lack of information creating new risks.
The issue is particularly relevant as cyberattacks against the public sector and critical operations become more sophisticated. The IT industry has previously reported on how AI agents take an active role in state-sponsored cyberattacks. For healthcare, the development means that technical protection needs to be combined with continuity planning, training and regular exercises.
Digital preparedness is more than backups
A robust digital healthcare environment cannot be built through backups alone. Organizations need to know which systems are most mission-critical, how long various outages can be tolerated, and what manual processes to activate when technology is unavailable.
- critical information must be available even when regular systems are down
- backup procedures must be documented, understandable and tested in practice
- Responsibility for incidents needs to be clear between healthcare providers, system suppliers and authorities
- Recovery must be able to be done in a controlled manner without malicious code or incorrect data being included
- staff need to practice working safely when digital tools are not working
For municipalities and regional healthcare organizations, vendor management is also becoming central. Cloud-based solutions can provide high availability and faster development, but the business must understand dependencies, agreed recovery times, and how data can be accessed during a major disruption.
Humans become part of the resistance force
Aidn's program also addresses the role of humans when digital systems fail. Under pressure, the risk of misunderstandings, misjudgments and unsafe shortcuts increases. Technical resilience therefore needs to be complemented by leadership, clear communication and a work environment where staff know what priorities apply.
This perspective makes digital health preparedness a management issue, not just an IT task. Business leaders, security functions, healthcare professionals, and providers need to plan together and start from the consequences for the patient.
Nordic issue with common challenges
Although the discussions take place in Norway, the issues are directly relevant to Sweden and the rest of the Nordic region. The countries have advanced digitalization, decentralized healthcare structures and a growing dependence on interconnected systems. The same technological developments that make healthcare more efficient also create more dependencies that must be protected.
The development should be seen in conjunction with the broader discussion about cyber resilience. In a recent study reported by IT-Branschen, it was stated Nordic AI-powered financial companies have a high exposure to security incidents. The industries differ, but the need is the same: new technologies must be introduced as governance, security and resilience evolve.
From scenarios to practical exercises
The important measure of preparedness is not whether an organization has a plan, but whether the plan works when needed. A 72-hour scenario can reveal unknown dependencies, unclear decision paths, and communication gaps before an actual incident occurs.
For Nordic healthcare providers, this means that continuity exercises should cover both technical disruptions and cyberattacks. The results then need to be translated into investments, updated routines and clearer requirements for suppliers.
More information can be found in Aidn's presentation of the program during Arendalsuka. See also Arendalsuka's official website.








