But there is an entire chain of responsibility here. The hospital IT department that chose to use a computer instead of dumber technologies. The IT department that chose to run Windows. The security team that chose to purchase CrowdStrike's software, possibly without vetting them.
If a software's license has clear terms stating that there is no warranty, and the buyer buys it anyway, why shouldn't this be a caveat emptor situation? If they didn't like it, they could negotiate indemnity clauses, go to a competitor, or not use the software at all.
Don't get me wrong, I absolutely think that CrowdStrike did a shitty thing. But maybe they already disclosed that in their license agreement, and the purchasers decided to overlook that to their own peril. After all, running kernel-mode software is equivalent to handing over the keys to your computers. Maybe negotiating/selling software with liability clauses should be more normalized?