By Jonathan Mattise

A ransomware attack has prompted a health care chain that operates 30 hospitals in six states to divert patients from at least some of its emergency rooms to other hospitals, while putting certain elective procedures on pause, the company announced.

In a statement Monday, Ardent Health Services said the attack occurred Nov. 23 and the company took its network offline, suspending user access to its information technology applications, including the software used to document patient care.

The Nashville, Tennessee-based company said it cannot yet confirm the extent of any patient health or financial information that has been compromised. Ardent says it reported the issue to law enforcement and retained third-party forensic and threat intelligence advisors, while working with cybersecurity specialists to restore IT functions as quickly as possible. There's no timeline yet on when the problems will be resolved.

Ardent owns and operates 30 hospitals and more than 200 care sites with upwards of 1,400 aligned providers in Oklahoma, Texas, New Jersey, New Mexico, Idaho and Kansas.

All of its hospitals are continuing to provide medical screenings and stabilizing care to patients arriving at emergency rooms, the company said.

“Ardent’s hospitals are currently operating on divert, which means hospitals are asking local ambulance services to transport patients in need of emergency care to other area hospitals,” the company said on its website. “This ensures critically ill patients have immediate access to the most appropriate level of care.”

The company said each hospital is evaluating its ability to safely care for patients at its emergency room, and updates on each hospital's status will be provided as efforts to bring them back online continue.

There was no immediate claim of responsibility for the attack. Ransomware criminals do not usually admit to an attack unless the victim refuses to pay.

A recent global study by the cybersecurity firm Sophos found nearly two-thirds of health care organizations were hit by ransomware attacks in the year ending in March, double the rate from two years earlier but a slight dip from 2022. Education was the sector most likely to be hit, with attack saturation at 80%.

Increasingly, ransomware gangs steal data before activating data-scrambling malware that paralyzes networks. The threat of making stolen data public is used to extort payments. That data can also be sold online. Sophos found data theft occurred in one in three ransomware attacks on healthcare organizations.

Analyst Brett Callow at the cybersecurity firm Emsisoft said 25 U.S. healthcare systems with 290 hospitals were hit last year while this year the number is 36 with 128 hospitals. “Of course, not all hospitals within the systems may have been impacted and not all may have been impacted equally,” he said. “Also, improved resilience may have improved recovery times.”

“We’re not in a significantly better position than in previous years, and it may actually be worse,” he said.

“We desperately need to find ways to better protect our hospitals. These incidents put patients' lives at risk — especially when ambulances need to be diverted — and the fact that nobody appears to have yet died is partly due to luck, and that luck will eventually run out,” Callow added.

Most ransomware syndicates are run by Russian speakers based in former Soviet states, out of reach of U.S. law enforcement, though some “affiliates” who do the grunt work of infecting targets and negotiating ransoms live in the West, using the syndicates’ software infrastructure and tools.

The Kremlin tolerates the global ransomware scourge, in part, because of the chaos and economic damage to the West — and as long its interests remain unaffected, U.S. national security officials say.

While industries across the spectrum have been hit by ransomware, a recent attack on China’s biggest bank that affected U.S. Treasury trading represented a rare attack on a financial institution.

Associated Press technology reporter Frank Bajak contributed to this report.

Share:
More In Technology
Religious Leaders Sign Fairplay Petition to Call on Meta to Cancel Instagram for Kids
More than 70 religious leaders have come together to sign a letter to urge Mark Zuckerberg and Meta to halt plans for Instagram for Kids. The signers claim that this new platform, currently on pause, could cause spiritual harm to young people. Lucy Kidwell, the screen-free week coordinator for the nonprofit that organized the letter, Fairplay, joined Cheddar News to discuss the issue on Safer Internet Day. "It's not necessarily the content, even, that's on these platforms, but more the structure of the app itself," she said. "It's all focused on comparison, promoting yourself, putting forward this image of perfection and this beautiful life that's really harmful to kids who can't really separate what's real and what's fake and who may not be emotionally mature enough to handle something so complicated."
Amazon Warehouse in Alabama to Begin Second Union Election
Amazon warehouse workers in Alabama are set to begin voting to unionize for a second time after workers at the facility in the town of Bessemer overwhelmingly voted against forming a union during an election early last year; but in November, the National Labor Relations Board overturned the vote, upholding a union challenge of the results which argued that Amazon undermined the conditions for a fair election. Another round of ballots will now be mailed out to works at the warehouse for a so-called re-run election. Director of Labor and Employment Studies at San Francisco State University John Logan and National Field Director for Our Revolution Mike Oles joined Cheddar News' Closing Bell to discuss.
Google Teams With Khan Academy to Promote Safer Internet Day
February 8 is Safer Internet Day, and Google has partnered with online education organization Khan Academy to release a courseload focused on internet safety. The partnership includes a $5 million donation towards content development from Google, with modules to be made available in various languages throughout 2022. Founder of Khan Academy, Sal Khan, joined Cheddar News to discuss the partnership. "We need to get to a world where everyone of all ages has a chance to learn and practice and feel good that they can navigate the internet in a safe way,” said Khan.
Big Tech Firms Like Amazon, Google Accused of Exaggerating Climate Actions
Big tech companies such as Amazon and Google are garnering criticism for failing at their proposed climate pledges, most of which rely on carbon offsets — a potential loophole where companies pay others to address their omissions. Gilles Dufrasne, policy officer at Carbon Market Watch, joined Cheddar News to explain the organization's negative evaluation. "The objective here is not to bash companies and say everybody is doing the wrong thing," he said. "The objective is to also provide lessons, and there are some companies that are doing the right thing."
John Warren
Assessing the environmental impact of mining cryptocurrency.
Markets Open Lower On Weak Meta Earnings
U.S. markets opened lower as disappointing Meta earnings dragged down the tech-heavy Nasdaq. Today, investors will be watching for Amazon's Q4 earnings report set for release after the market close. Greg Swenson, Founding Partner, Brigg Macadam joined Cheddar's Opening Bell to discuss.
Load More