It has been quite frankly a terrible week for those across the healthcare sector. Multiple different healthcare organizations have suffered ransomware attacks, each with widespread ramifications. This occurs when attackers lock up sensitive data and hold it hostage until the organization pays a ransom.
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has reported a 264% increase in ransomware incidents reported to them over the past five years. With the sheer amount of data that healthcare companies are tasked with collecting and storing, as well as the frequently sensitive nature of this data, this is unsurprising. This data makes healthcare organizations a prime target for extortion, and hackers have absolutely been taking advantage of this.
This has especially been seen in the last week alone, with a number of different healthcare organizations across the world being hit by, or releasing more information about, their ransomware attacks.
Mental health data exposed in NHS ransomware attack
On May 7, NHS Dumfries and Galloway confirmed that a large amount of personally identifying information belonging to both staff and patients had been published to the dark web. This data included the mental health information of children and was leaked following a ransomware attack launched against the organization.
The cyber attack took place on March 15 after a ransomware gang hacked into NHS Dumfries and Galloway’s computer system and stole a large amount of data.
After the attack, hackers began leaking the data on the dark web as “proof” it had been stolen, with a promise that more would be leaked if a ransom was not paid. This has also resulted in children’s mental health data being leaked in an “utterly abhorrent criminal act” in the words of the Chief Executive for NHS Dumfries and Galloway Julie White.
Due to the amount of data stolen, thousands of people could be impacted.
Ascension hospital network taken down by cyber attack
In the United States, ransomware also ran riot against healthcare organizations. On May 8, a serious cybersecurity incident impacting the Ascension hospital network was reported.
The hospital’s entire system was allegedly taken down during the incident, suggesting that a ransomware attack was responsible for the disruption. According to those in the hospital at the time of the incident, doctors were using cellphones to communicate with staff and paper charts were being used. These are both tasks usually undertaken by the hospital’s computer network.
Ascension is currently investigating the cyber attack, and has said that some systems continue to be disrupted.
Ransomware gang extorts NRS Healthcare
Another UK-based ransomware attack was that of mobility aid manufacturer NRS Healthcare. This week saw more information about this attack coming to light.
The attack, which took place on March 29, took all of NRS Healthcare’s services offline. Ransomware group RansomHUB took to the dark web to take responsibility for disabling its phone lines, email, and websites. The group also claimed to have stolen 578 GB of data and said that in order to get the de-encryption key and “resolve” the data breach, NRS Healthcare needs to contact them “as soon as possible”.