On Wednesday, January 31, based on evidence of suspicious activity and consistent with best practices, Lurie Children’s Health took their systems offline, including phone, e-mail, electronic medical records system, and MyChart, a patient family portal. They did this to protect the information of their patients, workforce and organization.
They can confirm that their network was accessed by a known criminal threat actor.
Related: HHS Releases Voluntary Cybersecurity Performance Goals
They have been working closely, around the clock, with outside and internal experts and in collaboration with law enforcement, including the FBI. This is an active and ongoing investigation. As an academic medical center, their systems are highly complex, and these incidents can take time to resolve.
Throughout this period, all Lurie Children’s locations have remained open, accepting and caring for patients with as few disruptions as possible.
They implemented their emergency preparedness plans, including downtime procedures throughout the organization.
How Efficiency Checklists Help Hospitals Save Energy, Water and Money
Intermountain Healthcare Receives $50M Gift for Standalone Children's Hospital
Arrowhead Regional Medical Center Reports Data Breach via Third Party
Safety Synergy: Infection Prevention That Protects Patients and Workers
Prefabricated Wall Panels Speed UCF Lake Nona Medical Center Construction