Date: 19 August 2021

Title:  Cyberattack Forces Memorial Health System to Cancel Surgeries, Divert Patients 

Sources.

Cyberattack Forces Memorial Health System to Cancel Surgeries, Divert Patients | SecurityWeek.Com

Ionut Arghire

Not-for-profit integrated health organization Memorial Health System is in the process of restoring operations after falling victim to a cyberattack.  On 15 August, the organization announced that it fell victim to a cyberattack that forced it to suspend “user access to information technology applications.” The incident disrupted clinical and financial operations, including suspended medical exams, canceled surgeries, and diverting patients to other facilities.  They reached a negotiated solution and began restoring operations as quickly and as safely as possible. We are following a deliberate, systematic approach to bring systems back online securely and in a manner that prioritizes our ability to provide patient care.

The health system could “maintain safe and effective patient care” throughout the incident but said additional security improvements would be implemented to prevent similar incidents.  While the information was not provided on the nature of the incident, it appears that ransomware might have been used, and a hospital statement suggests that the organization could negotiate with the attackers.

Bleeping Computer reported that the attack appears to have been carried out by a cybercrime group that uses Hive ransomware. The hackers, known for leaking information stolen from victims, claimed that they did obtain patient information.

What to do?

Ensure your Antivirus and Antimalware software is up to date and operational.

Ensure your firewalls are up to date and operational

Employ multi-factor authentication across the network

Perform routine backups with copies maintained in a safe, “air-gapped” location.

Train employees on Phishing and Phishing techniques

What can you do when this happens to you?

If you are the target of ransomware, immediately shut the network down.

Identify the source of the attack and the files compromised

Notify your local law enforcement cybersecurity unit and the FBI

Search for known ransomware keys

Rebuild the network from a known “Clean Backup.”

Sources.

Cyberattack Forces Memorial Health System to Cancel Surgeries, Divert Patients | SecurityWeek.Com

Ionut Arghire