Hospital Pays Ransom Over Cyber Attack

Incident affected the protected health information of nearly 57,400 individuals

By Linda Lybert, Special to Healthcare Facilities Today


To pay or not to pay?

For healthcare IT managers facing a ransomware attack that threatens valuable patient and research data, that’s the question. The recent decision by a Massachusetts-based hospital to pay a ransom in exchange for promises by the attackers to destroy stolen data spotlights the difficult choice.

Sturdy Memorial Hospital in Massachusetts says that on Feb. 9, it identified a security incident that disrupted the operations of some of its IT systems, according to GovInfo Security.

“In exchange for a ransom payment, we obtained assurances that the information acquired would not be further distributed and that it had been destroyed," the organization said in a statement. The hospital reported the incident to law enforcement officials and regulators. The Department of Health and Human Services' HIPAA Breach Reporting Tool website says the incident affected the protected health information of nearly 57,400 individuals.

The hospital says its analysis of the incident determined the stolen files contained information belonging to Sturdy patients, as well as some patients of several local healthcare providers.



June 11, 2021


Topic Area: Information Technology


Recent Posts

ISSA Introduces Healthcare Platform to Advance Safer, Cleaner Patient Environments

This new resource integrates training, research and cross-sector collaboration to raise care standards and improve patient outcomes.


Third-Party Tracking Settlement is a Compliance Wake-Up Call for Healthcare Facilities Managers

Mount Sinai Health System agrees to a $5.3 million settlement to resolve claims it improperly shared patient data with Facebook through tracking tools.


ECU Health Behavioral Health Hospital Hosts Ribbon-Cutting Ceremony for New Facility

The new facility features 144 beds and a healing environment for behavioral health patients.


Aspire Rural Health System Reports Data Security Incident

Upon detecting the unauthorized activity, Aspire immediately worked to contain the incident and launched a thorough investigation.


Fatal Flaws: Strategies for Active Attackers

Anything that goes wrong with the response is the liability exposure of the organization — not the employee and not the police.


 
 


FREE Newsletter Signup Form

News & Updates | Webcast Alerts
Building Technologies | & More!

 
 
 


All fields are required. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.