To pay or not to pay?
For healthcare IT managers facing a ransomware attack that threatens valuable patient and research data, that’s the question. The recent decision by a Massachusetts-based hospital to pay a ransom in exchange for promises by the attackers to destroy stolen data spotlights the difficult choice.
Sturdy Memorial Hospital in Massachusetts says that on Feb. 9, it identified a security incident that disrupted the operations of some of its IT systems, according to GovInfo Security.
“In exchange for a ransom payment, we obtained assurances that the information acquired would not be further distributed and that it had been destroyed," the organization said in a statement. The hospital reported the incident to law enforcement officials and regulators. The Department of Health and Human Services' HIPAA Breach Reporting Tool website says the incident affected the protected health information of nearly 57,400 individuals.
The hospital says its analysis of the incident determined the stolen files contained information belonging to Sturdy patients, as well as some patients of several local healthcare providers.
Building Sustainable Healthcare for an Aging Population
Froedtert ThedaCare Announces Opening of ThedaCare Medical Center-Oshkosh
Touchmark Acquires The Hacienda at Georgetown Senior Living Facility
Contaminants Under Foot: A Closer Look at Patient Room Floors
Power Outages Largely Driven by Extreme Weather Events