Healthcare

Industry

Cyberattack at Shields Healthcare Group Compromises Personal Medical Data of Millions of Patients

March 7, 2022

Shields Health Care Group reported a healthcare cyberattack to HHS impacting 2 million individuals. The Massachusetts-based healthcare group provides MRI, PET/CT, and ambulatory surgical services to patients across New England at more than 30 locations.

According to a notice on Shields’ website, the organization discovered suspicious activity on its network on March 28, 2022. Shields immediately launched an investigation and took steps to contain the incident. The investigation revealed that an unknown actor gained access to certain Shields systems from March 7 to March 21. The unknown actor also acquired certain data from the systems.

Shields relies on partnerships with hospitals and medical centres. It is believed that up to 53 separate facilities and their patients are affected.

read more

Georgia Hospital Takes Computer Systems Offline – Continues to Provide Care.

June 30, 2022

A cyberattack on Jack Hughston Memorial Hospital has led the Georgia hospital to pull certain systems offline and operate under electronic health record procedures, local news outlets reported Wednesday. It’s unclear the type of attack behind the network outage. Patient care has not been interrupted. At this stage of the investigation, it is unclear if, and to what extent, patient information has been compromised.

read more

Kaiser Permanente Hit in Attack; 70,000 Records Exposed

April 5, 2022

Kaiser Permanente, the largest nonprofit health plan provider in the United States, suffered a data breach after an attacker gained access to a worker’s emails which exposed health information of almost 70,000 patients.
In a notice to patients on June 3, Kaiser revealed someone gained access to an employee’s emails at the Kaiser Foundation Health Plan of Washington on April 5 that contained protected health information, including patient names, dates of service, medical record numbers, and lab test result information.
Financially sensitive information, including social security and credit card numbers, was not exposed by the breach, according to the healthcare provider.

read more

Belgian Hospital CHwapi victim of a cyberattack: operations canceled

January 17, 2021

Cyberattack at Center Hospitalier de Wallonie Picarde (CHwapi) in Tournai, Belgium has left its systems crippled cancelling surgeries for 2 days and diverting emergency cases to other hospitals for one week.

No less than 80 of the 300 computer servers were affected. Since the personal data of the admissions department were no longer accessible, the staff has returned to using pen and paper. No computer theft was committed and no ransom demand was made.

A team from the federal police’s Computer Crime Unit was on site to support the hospital’s computer specialists.

read more

Crypto-virus RYUK Attacks French Hospitals in Lyon Area

February 15, 2021

Hôpital Nord-Ouest, the hospital group for the North of Lyon, reported two hospitals were stricken with ransomware attacks, and a third pre-emptively cut connections with an IT provider, in less than a week. Surgeries were postponed and emergency patients re-routed to other facilities as each hospital site’s team set up limited procedures to ensure the exchange of information necessary for patient care, as well as a crisis unit to organise the operation of all three sites. The attack by the crypto-virus RYUK, a kind of ransomware, “strongly impacts” the Villefranche, Tarare and Trévoux sites of the North-West Hospital, the hospital said in a statement.

Following the attack, French President Emmanuel Macron said his office plans to inject one billion euros (US$1.21 billion) into the country’s cyberdefense.

read more

Scripps Health Ransomware Attack Costs Expected to Exceed $113M.

May 15, 2021

In the May 2021 ransomware attack, Scripps Health lost access to information systems at two of its hospitals, staff couldn’t access the electronic medical record system, and its offsite backup servers were also affected. Without access to critical IT systems, Scripps Health was forced to re-route stroke and heart attack patients and trauma patients could not be accepted at its main hospitals. The company stated it took 4 weeks to recover from the attack.

Losses sustained as a result of the attack are expected to exceed $113 million. The costs are likely to increase further still. The protected health information of 147,267 patients was compromised in the attack, and several class action lawsuits have been filed against Scripps Health over the theft of patient data. The expected losses do not include litigation costs.

read more

Hillel Yaffe Hospital Ransomware Attack Paralyzed Majority of Hospital’s Computer Systems.

October 13, 2021

According to reports, among the affected systems are the hospital’s electric doors, as well as the patient registry system – which severely hampered the medical center’s ability to receive and discharge patients. Some non-urgent procedures were canceled, but most of the hospital’s work continued using alternative IT systems and pen and paper. Cybersecurity experts said the hospital did not deploy the best possible security options, making it vulnerable to attack.

The hospital was back to being fully operational over a month after a ransomware attack. To reduce the vulnerability of follow-up attacks, medical centers across Israel shut down some IT systems.

read more

Cyberattack: Surgeries Postponed At Melbourne Hospitals.

March 16, 2021

A number of hospitals in Melbourne shut down elective surgeries after a suspected cyber attack on its computer network. Healthcare centers in the city’s east run by Eastern Health were forced to postpone the surgeries and shutdown several IT systems. The hospitals affected (Box Hill, Maroondah, Healesville and Angliss) continued with category 1 elective surgeries, which impacted patients who require treatment within 30 days – all other operations stopped.

The company issued a statement on the issue, confirming their system had been taken offline until they identified the problem but stressed that no patient information had been leaked.

read more

Ransomware Attack Forced Ambulance Diversion At Eskenazi Health

August 4, 2021

Eskenazi Health in Indianapolis went on diversion for more than 5 days, meaning all incoming ambulances were routed to other hospitals after an attempted ransomware attack early Wednesday morning. The attack occurred around 3:30 a.m., and the diversion began at 7:51 a.m. Wednesday. The move affected all of the health system’s locations, including Sidney & Lois Eskenazi Hospital downtown. Outpatient clinics remained open. Eskenzai contacted patients with an appointment or procedure that needed to be rescheduled because of the incident. “Monitoring systems responded as they should have and no employee or patient data appeared to be compromised.” Tom Surber, media relations coordinator for Eskenazi Health, said in an emailed statement.

read more

Cyberattack on N.L. Healthcare System Possibly Worst In Canadian History

October 30, 2021

Thousands of Newfoundland and Labrador residents had appointments cancelled as a result of the attack, ranging from blood work to cancer care. Patient and employee information has been stolen from three out of the four regional health authorities. System had to be rebuild from scratch taking over a month. Sources say ransom was paid, but decryption key did not work. Later reports indicated 200,000 patient and employee files were taken from a network drive.

UPDATE: July 2022: Newfoundland and Labrador’s largest health authority has notified 37,800 people that their privacy was breached as part of last fall’s devastating cyberattack.

read more