Hospital networks and computers running Epic are very much indirect life-support systems, faulire of which can cause lots of injuries and deaths - as we're learning now in real-time.
I'm hearing that most hospital cybersecurity insurance requires Crowdstrike (or a product like it) on all the endpoints, so if that's true the liability might fall back on them. It will be a protracted argument for sure.
This is likely the case in a lot of places. We're still in the midst of ransomware groups targeting hospitals.