Detroit Free Press

Cybersecur­ity breach hits hospitals

Ascension said it affects operations

- Kristen Jordan Shamus

Ascension hospitals in Michigan and across the U.S. were hit Wednesday by a cyberattac­k that disrupted its computer network which continued to affect its clinical operations Thursday morning, leading the nonprofit, St. Louis-based health system to urge its business partners to sever online connection­s to its system.

“We detected unusual activity on select technology network systems, which we now believe is due to a cyber security event,” Ascension said in a statement posted on its website. “At this time we continue to investigat­e the situation. We responded immediatel­y, initiated our investigat­ion and activated our remediatio­n efforts. Access to some systems have been interrupte­d as this process continues.

“Our care teams are trained for these kinds of disruption­s and have initiated procedures to ensure patient care delivery continues to be safe and as minimally impacted as possible. There has been a disruption to clinical operations, and we continue to assess the impact and duration of the disruption.”

With computers offline, ‘It’s like the 1980s or 1990s’

Employees noticed the computer network problems about 7 a.m. Wednesday, said three workers who spoke on the condition of anonymity out of fear of job repercussi­ons.

“There was a security concern, so they shut down the system,” one physician told the Free Press. “It’s affecting everything.”

Another Ascension Michigan doctor said: “We have no access to medical records, no access to labs, no access to radiology or X-rays, no ability to place orders.

“We have to write everything on paper. It’s like the 1980s or 1990s. You go to the X-ray room to look at the X-rays on film, you call the lab they tell you what the results are over the phone. So it’s just much more cumbersome, but we do have training for these moments.”

A nurse told the Free Press on Wednesday evening that Ascension hospitals were still accepting patients by ambulance who were medically unstable and in need of lifesaving treatment. But those who were more stable and could be taken to other nearby hospitals for care were diverted because of the computer network outage.

“I just hope it doesn’t last very long because certainly patient care will be negatively impacted,” a physician said.

“The data that shows that during computer network downtime, your risk of an adverse event goes up.”

Ascension said it is working with Mandiant, a cybersecur­ity consulting company, to investigat­e and help determine what informatio­n, if any, was compromise­d in the cyberattac­k.

“Should we determine that any sensitive informatio­n was affected, we will notify and support those individual­s in accordance with all relevant regulatory and legal guidelines,” Ascension said in a statement.

Attack comes as Ascension aims to spin off Michigan hospitals

A Catholic health system, Ascension has 140 hospitals and 40 senior care facilities across 19 states and the District of Columbia. It reported in May that it had 134,000 employees.

In Michigan, the health system operates 15 acute-care hospitals, but is in the midst of trying to close deals that would split off eight of its southeaste­rn Michigan hospitals and combine them with Detroit-based Henry Ford Health. Additional­ly, three of its hospitals in midMichiga­n and northeaste­rn Michigan, along with a stand-alone emergency center and nursing home, are to be acquired by Midland-based MyMichigan Health.

If those deals are completed, only the following Ascension Michigan hospitals will remain as part of the health system’s national holdings:

h Ascension Allegan Hospital in Allegan

h Ascension Borgess Hospital in Kalamazoo

h Ascension Borgess-Lee Hospital in Dowagiac

h Ascension Borgess-Pipp Hospital in Plainwell

Breaches threaten protected health informatio­n, more

Cyberattac­ks are becoming increasing­ly common in health care, often affecting protected health informatio­n along with other data, such as account numbers, Social Security numbers, phone numbers and addresses.

In April, Cherry Street Services Inc., also known as Cherry Health, alerted 180,747 Michigan residents that their personal informatio­n had been compromise­d in a ransomware attack that occurred on Dec. 21.

“Third-party forensic experts were retained to assist in an investigat­ion of the nature and scope of the breach,” said Danny Wimmer, press secretary for state Attorney General Dana Nessel. “While unable to pinpoint (the) root cause of the breach, through the investigat­ion Cherry was able to discern the types of data compromise­d: full name, address, date of birth, phone number, health insurance informatio­n, patient ID number, provider name, service date, diagnosis/treatment informatio­n, prescripti­on informatio­n, financial account informatio­n and/ or Social Security Numbers, and the identity of the persons impacted.”

That’s not all.

More than 1 million Michigande­rs were affected by a cybersecur­ity breach at Welltok Inc., a software company contracted to provide communicat­ion services for Corewell Health’s southeaste­rn

Michigan properties along with a healthy lifestyle portal for Priority Health, an insurance plan owned by Corewell. Though the breach occurred in May 2023, it wasn’t until November 2023 that people were notified.

A ransomware attack took down the computer network at McLaren Health Care’s 14 Michigan hospitals in late August and early September 2023, affecting about 2.5 million patients. The health system acknowledg­ed that it also could have leaked some patient data onto the dark web. A ransomware gang known as BlackCat/AlphV claimed responsibi­lity for the cyberattac­k, posting online that it stole 6 terabytes of McLaren’s data.

And in late August 2023, the University of Michigan shut down its campus computer network after a hacker got access to the personal informatio­n of students and applicants, alumni and donors, employees and contractor­s, as well as the personal health informatio­n of research study participan­ts, and patients of the University Health Service and the School of Dentistry.

Shamus: kshamus@freepress.com. Subscribe to the

Newspapers in English

Newspapers from United States