Date: 19 August 2021
Title: Cyberattack Forces Memorial Health System to Cancel Surgeries, Divert Patients
Sources.
Cyberattack Forces Memorial Health System to Cancel Surgeries, Divert Patients | SecurityWeek.Com
Ionut Arghire
Not-for-profit integrated health organization Memorial Health System is in the process of restoring operations after falling victim to a cyberattack. On 15 August, the organization announced that it fell victim to a cyberattack that forced it to suspend “user access to information technology applications.” The incident disrupted clinical and financial operations, including suspended medical exams, canceled surgeries, and diverting patients to other facilities. They reached a negotiated solution and began restoring operations as quickly and as safely as possible. We are following a deliberate, systematic approach to bring systems back online securely and in a manner that prioritizes our ability to provide patient care.
The health system could “maintain safe and effective patient care” throughout the incident but said additional security improvements would be implemented to prevent similar incidents. While the information was not provided on the nature of the incident, it appears that ransomware might have been used, and a hospital statement suggests that the organization could negotiate with the attackers.
Bleeping Computer reported that the attack appears to have been carried out by a cybercrime group that uses Hive ransomware. The hackers, known for leaking information stolen from victims, claimed that they did obtain patient information.
What to do?
Ensure your Antivirus and Antimalware software is up to date and operational.
Ensure your firewalls are up to date and operational
Employ multi-factor authentication across the network
Perform routine backups with copies maintained in a safe, “air-gapped” location.
Train employees on Phishing and Phishing techniques
What can you do when this happens to you?
If you are the target of ransomware, immediately shut the network down.
Identify the source of the attack and the files compromised
Notify your local law enforcement cybersecurity unit and the FBI
Search for known ransomware keys
Rebuild the network from a known “Clean Backup.”
Sources.
Cyberattack Forces Memorial Health System to Cancel Surgeries, Divert Patients | SecurityWeek.Com
Ionut Arghire