Skip to content

Hospital chain attack part of ongoing cybersecurity concerns

Diverted ambulances. Cancer treatment delayed. Electronic health records offline. These are just some of ripple effects of an apparent cyberattack on a major nonprofit health system that disrupted operations throughout the U.S, including Illinois.

Associated Press
Associated Press
4 min read
Hospital chain attack part of ongoing cybersecurity concerns

Embed from Getty Images

CHICAGO (AP) — Diverted ambulances. Cancer treatment delayed. Electronic health records offline. These are just some of ripple effects of an apparent cyberattack on a major nonprofit health system that disrupted operations throughout the U.S.

While CommonSpirit Health confirmed it experienced an “IT security issue” earlier this week, the company has remained mum when pressed for more details about the scope of the attack. The health system giant has 140 hospitals in 21 states. As of Thursday, it's still unknown how many of its 1,000 care sites that serve 20 million Americans were affected.

Despite the lingering questions, the incident underscores the growing concerns surrounding ransomware attacks on health care systems with patient care at stake.

In Tacoma, Washington, Mark Kellogg told KING-TV that his wife, Kathy, had been scheduled to get a cancerous tumor on her tongue removed on Monday, but the procedure was put off several days because of the cyberattack.[1] Virginia Mason Franciscan Health's parent company is CommonSpirit Health.

“Everything we do today is all on a computer, and without it you’re back to the stone age writing on a tablet,” Kellogg said.

In Iowa, the Des Moines Register reported that the incident forced the diversion of five ambulances from the emergency department of the city’s MercyOne Medical Center to other medical facilities.[2]

The incident forced both MercyOne and VMFH to take certain IT systems offline — including patients' electronic health records — as a precaution.

Brett Callow, a threat analyst with cybersecurity provider Emsisoft, said the incident could be “the most significant attack on the health care sector to date” if all CommonSpirit hospitals and other facilities were affected.

Emsisoft has tracked at least 15 health care systems in the U.S. affected by ransomware this year, which manage more than 60 hospitals. Callow said data was stolen in 12 of the 15 instances, adding that those are almost surely undercounts as some ransomware attacks aren’t widely reported.

Callow said one of the largest known attacks within health care came in September 2020 when a ransomware attack struck all 250 health care facilities owned by Universal Health Services.[3]

CommonSpirit’s incident could exceed that, depending on how many of its facilities were hit. That could mean the company faces large financial costs to get through the incident and recover.

Callow cited the loss of more than $100 million reported by Scripps Health tied to a 2021 ransomware attack that affected its five hospitals in California as an example.

Asked for more information on the incident and its effects on Thursday, a spokesperson for CommonSpirit said the health system could not provide more details.

The most worrying effect of any substantial attack on healthcare is on patients, Callow said.

“I’ve seen reports that at least one of the impacted hospitals had to divert ambulances to other facilities and that delay in getting people the care they need could obviously represent a risk to the lives of patients,” he said. “Beyond that, these incidents can have a long-term impact on patient outcomes — delaying treatments, for example.”

In 2020, the FBI and other federal agencies warned that they had credible information that cybercriminals could unleash a wave of data-scrambling extortion attempts against U.S. hospitals and health care providers.[4]

That's because ransomware criminals are increasingly stealing data from their targets before encrypting networks, using it for extortion. They often sow the malware weeks before activating it, waiting for moments when they believe they can extract the highest payments.

Health care is classified by the U.S. government as one of 16 critical infrastructure sectors Health care providers are seen as ripe targets for hackers.

If patient data is accessed, health care providers are required by law to notify the Department of Health and Human Services.


Subscribe to the Chicago Journal


The Chicago Journal needs your support.

At just $20/year, your subscription not only helps us grow, it helps maintain our commitment to independent publishing.

CLICK HERE TO SUBSCRIBE

If you're already a subscriber and you'd like to send a tip to continue to support the Chicago Journal, which we would greatly appreciate, you can do so at the following link:

Send a tip to the Chicago Journal


Subscribe to the Chicago Journal

Notes & References


  1. Wakayama, Author: Brady. “Cyberattack on Virginia Mason Franciscan Health Impacting Patients.” king5.com, October 6, 2022. https://www.king5.com/article/news/health/virginia-mason-cyber-attack/281-1b3eb4eb-e8d8-421f-9d07-29affaee6308. ↩︎

  2. Ramm, Michaela. “MercyOne Shuts down e-Health Records after 'IT Security Incident' Affects Online Systems.” The Des Moines Register. Des Moines Register, October 4, 2022. https://www.desmoinesregister.com/story/news/health/2022/10/04/mercyone-online-systems-shut-down-cybersecurity-incident-des-moines-hospital/69538349007/. ↩︎

  3. Bajak, Frank. “Hacked Hospital Chain Says All 250 US Facilities Affected.” AP NEWS. Associated Press, October 1, 2020. https://apnews.com/article/virus-outbreak-malware-software-1d76456bea2036b97d3a83f81e43dabe. ↩︎

  4. Bajak, Frank. “FBI Warns Ransomware Assault Threatens Us Health Care System.” AP NEWS. Associated Press, October 29, 2020. https://apnews.com/article/fbi-ransomware-healthcare-system-7531ca8d2742d855cd374213d111821c. ↩︎

HealthLifestyleNewsIllinois News

Associated Press Twitter

News and content from The Associated Press, which has been covering the world's most important stories since 1846.


Related

Supreme Court upholds cash-free bail in Illinois, takes effect in September

Supreme Court Chief Justice Mary Jane Theis ordered that the halt on the law be lifted 60 days after Tuesday's opinion, on Sept. 18, 2023.

Supreme Court upholds cash-free bail in Illinois, takes effect in September

Mississippi River crests at Davenport, testing barriers

The peak was slightly lower than forecast but still high enough to test the region's flood defenses and to keep officials on guard. Many larger cities have flood walls but Davenport relies on temporary sand-filled barriers and allows the river to flood in riverfront parks.

Mississippi River crests at Davenport, testing barriers

`Multiple fatalities' on Illinois highway following crashes

The crashes occurred late in the morning and involved 40 to 60 passenger cars and multiple tractor-trailers, two of which caught fire, Illinois State Police Maj. Ryan Starrick said.

`Multiple fatalities' on Illinois highway following crashes