Ascension: 'Systems Are Being Restored' After Cyberattack (2024)

'While we expect this process will take time to complete, we are making progress and systems are being restored in a coordinated manner at each of our care sites,’ Ascension said in an update over the weekend.

Ascension: 'Systems Are Being Restored' After Cyberattack (1) Days after a ransomware attack paralyzed Ascension health system, shutting down its electronic health records system and forcing it to divert emergency care at some of its hospitals, the organization said this weekend its systems are being restored.

“While our restoration work continues in earnest, our focus is on restoring systems as safely as possible,” the St. Louis-based health system said in an update on Saturday that confirmed the ransomware attack. “While we expect this process will take time to complete, we are making progress and systems are being restored in a coordinated manner at each of our care sites. We will continue to share updates on our recovery process.”

Ascension also said that it was in close contact with the FBI and the U.S. Cybersecurity and Infrastructure Security Agency (CISA), and “we are sharing relevant threat intelligence with the Health Information Sharing and Analysis Center (H-ISAC) so that our industry partners and peers can take steps to protect themselves from similar incidents.”

[RELATED STORY: Ascension Data Breach: Health System Says Clinical Operations Disrupted]

The FBI told CRN in a statement that it was “aware of the situation” and declined to comment further. CRN has reached out to Ascension and CISA for further comment.

On Friday, CNN, citing four sources, reported that Ascension suffered a ransomware attack with signs that the Russian-linked Black Basta group was behind the data breach.

That same day, the H-ISAC sent out an alert to its health sector member organizations saying that Black Basta “has recently accelerated attacks against the healthcare sector.”

CISA, the Department of Justice and the Department of Health and Human Services that same day sent out an advisory detailing Black Basta, which it said is considered a ransomware-as-a-service variant and first identified in April 2022. Ransomware a service is a subscription-based model that allows affiliates to use predeveloped ransomware tools to execute ransomware attacks, according to security vendor Palo Alto Networks.

The group, according to authorities, not only executes ransomware but also exfiltrates sensitive data, operating a cybercrime marketplace to publicly release it should a victim fail to pay a ransom.

As of May 2024, Black Basta affiliates have impacted over 500 organizations around the world, according to federal authorities.

Previous victims of its attacks include Dish Network, the American Dental Association, business process services firm Capita and tech firm ABB.

Ascension, a nonprofit and Catholic health system with 140 hospitals in the U.S., said May 8 that it initially detected “unusual activity on select technology network systems.” Ascension referred to the data breach as a “cybersecurity incident” at the time and said that it was working “around the clock with internal and external advisors to investigate, contain, and restore our systems following a thorough validation and screening process.”

In addition to its electronic health records system being unavailable, the health system said that its MyChart system wasn’t functional. MyChart allows patients to access their medical records and communicate with healthcare providers. Ascension said some phone systems and various systems to order certain tests, procedures and medications were also not working.

Michael Goldstein, president and CEO of Fort Lauderdale, Fla.-based LAN Infotech, told CRN that with a cyberattack on a health sector-related organization, “there’s a lot of data that could go out there. If you think about when we go to a hospital or medical facility, all the information that we have to give them. When it causes some disruption, it becomes national. It kind of gets those attackers, if they leave a footprint, the publicity that they’re looking for.... I always look at healthcare and public utilities as big targets. This looks like a large number of hospitals that were affected from this group.”

The nonprofit had already said that it was using Mandiant to assist in the investigation and remediation process.

“It’s almost like déjà vu all over again,” Luis Alvarez, president and CEO of Salinas, Calif.-based Alvarez Technology Group, told CRN. “It looks like a mirror image of Change Health,” referring to the cyberattack earleir this year against a unit within UnitedHealth Group subsidiary Optum, which led to major disruptions for U.S. pharmacies and patients, according to reports. The attack forced UnitedHealth to pay a $22 million ransom and admit that a lack of multifactor authentication on a Change Healthcare server enabled the attack to succeed.

“It continues to happen in a number of industries,” Alvarez said. “Healthcare is more notable because impacts are felt much quicker. I do give Ascension credit for immediately informing their partners and saying, ‘Hey you might want to disconnect your systems from ours because we don’t know how far this is going.’ Unlike the Change Healthcare [attack] where there was a lot of fog of war-type stuff where people were wondering what’s going on, how this might be affecting us. I give Ascension credit for being very open and very transparent.”

Ascension: 'Systems Are Being Restored' After Cyberattack (2024)

References

Top Articles
How To Redeem Wu Points
Homiletics In The Sierra Foothills
Fiskars X27 Kloofbijl - 92 cm | bol
Craigslist Monterrey Ca
Noaa Charleston Wv
Restored Republic January 20 2023
Alan Miller Jewelers Oregon Ohio
Lexington Herald-Leader from Lexington, Kentucky
How Much Is 10000 Nickels
Lichtsignale | Spur H0 | Sortiment | Viessmann Modelltechnik GmbH
Prices Way Too High Crossword Clue
Jet Ski Rental Conneaut Lake Pa
Culos Grandes Ricos
Degreeworks Sbu
Indiana Immediate Care.webpay.md
Mlb Ballpark Pal
Craigslist Pets Sac
ocala cars & trucks - by owner - craigslist
Hanger Clinic/Billpay
Jbf Wichita Falls
Craigslist Pinellas County Rentals
Why Is 365 Market Troy Mi On My Bank Statement
Saritaprivate
Christina Steele And Nathaniel Hadley Novel
Vegas7Games.com
Riherds Ky Scoreboard
Rogue Lineage Uber Titles
Pay Stub Portal
Wheeling Matinee Results
Where Can I Cash A Huntington National Bank Check
Shaman's Path Puzzle
Giantess Feet Deviantart
That1Iggirl Mega
Philadelphia Inquirer Obituaries This Week
Craigslist Tulsa Ok Farm And Garden
PruittHealth hiring Certified Nursing Assistant - Third Shift in Augusta, GA | LinkedIn
301 Priest Dr, KILLEEN, TX 76541 - HAR.com
Letter of Credit: What It Is, Examples, and How One Is Used
Wilson Tattoo Shops
Joey Gentile Lpsg
Alpha Labs Male Enhancement – Complete Reviews And Guide
844 386 9815
Phmc.myloancare.com
Minterns German Shepherds
Bedbathandbeyond Flemington Nj
Shannon Sharpe Pointing Gif
Steam Input Per Game Setting
Motorcycle For Sale In Deep East Texas By Owner
Mytmoclaim Tracking
Predator revo radial owners
San Pedro Sula To Miami Google Flights
The Love Life Of Kelsey Asbille: A Comprehensive Guide To Her Relationships
Latest Posts
Article information

Author: Horacio Brakus JD

Last Updated:

Views: 5312

Rating: 4 / 5 (51 voted)

Reviews: 82% of readers found this page helpful

Author information

Name: Horacio Brakus JD

Birthday: 1999-08-21

Address: Apt. 524 43384 Minnie Prairie, South Edda, MA 62804

Phone: +5931039998219

Job: Sales Strategist

Hobby: Sculling, Kitesurfing, Orienteering, Painting, Computer programming, Creative writing, Scuba diving

Introduction: My name is Horacio Brakus JD, I am a lively, splendid, jolly, vivacious, vast, cheerful, agreeable person who loves writing and wants to share my knowledge and understanding with you.