By Jonathan Mattise

A ransomware attack has prompted a health care chain that operates 30 hospitals in six states to divert patients from at least some of its emergency rooms to other hospitals, while putting certain elective procedures on pause, the company announced.

In a statement Monday, Ardent Health Services said the attack occurred Nov. 23 and the company took its network offline, suspending user access to its information technology applications, including the software used to document patient care.

The Nashville, Tennessee-based company said it cannot yet confirm the extent of any patient health or financial information that has been compromised. Ardent says it reported the issue to law enforcement and retained third-party forensic and threat intelligence advisors, while working with cybersecurity specialists to restore IT functions as quickly as possible. There's no timeline yet on when the problems will be resolved.

Ardent owns and operates 30 hospitals and more than 200 care sites with upwards of 1,400 aligned providers in Oklahoma, Texas, New Jersey, New Mexico, Idaho and Kansas.

All of its hospitals are continuing to provide medical screenings and stabilizing care to patients arriving at emergency rooms, the company said.

“Ardent’s hospitals are currently operating on divert, which means hospitals are asking local ambulance services to transport patients in need of emergency care to other area hospitals,” the company said on its website. “This ensures critically ill patients have immediate access to the most appropriate level of care.”

The company said each hospital is evaluating its ability to safely care for patients at its emergency room, and updates on each hospital's status will be provided as efforts to bring them back online continue.

There was no immediate claim of responsibility for the attack. Ransomware criminals do not usually admit to an attack unless the victim refuses to pay.

A recent global study by the cybersecurity firm Sophos found nearly two-thirds of health care organizations were hit by ransomware attacks in the year ending in March, double the rate from two years earlier but a slight dip from 2022. Education was the sector most likely to be hit, with attack saturation at 80%.

Increasingly, ransomware gangs steal data before activating data-scrambling malware that paralyzes networks. The threat of making stolen data public is used to extort payments. That data can also be sold online. Sophos found data theft occurred in one in three ransomware attacks on healthcare organizations.

Analyst Brett Callow at the cybersecurity firm Emsisoft said 25 U.S. healthcare systems with 290 hospitals were hit last year while this year the number is 36 with 128 hospitals. “Of course, not all hospitals within the systems may have been impacted and not all may have been impacted equally,” he said. “Also, improved resilience may have improved recovery times.”

“We’re not in a significantly better position than in previous years, and it may actually be worse,” he said.

“We desperately need to find ways to better protect our hospitals. These incidents put patients' lives at risk — especially when ambulances need to be diverted — and the fact that nobody appears to have yet died is partly due to luck, and that luck will eventually run out,” Callow added.

Most ransomware syndicates are run by Russian speakers based in former Soviet states, out of reach of U.S. law enforcement, though some “affiliates” who do the grunt work of infecting targets and negotiating ransoms live in the West, using the syndicates’ software infrastructure and tools.

The Kremlin tolerates the global ransomware scourge, in part, because of the chaos and economic damage to the West — and as long its interests remain unaffected, U.S. national security officials say.

While industries across the spectrum have been hit by ransomware, a recent attack on China’s biggest bank that affected U.S. Treasury trading represented a rare attack on a financial institution.

Associated Press technology reporter Frank Bajak contributed to this report.

Share:
More In Technology
17 Digital Asset Firms Launch CMIC, Committing to Safer Markets and Working with Regulators
Soildus Labs, a market compliance and surveillance technology provider for crypto firms, has spearheaded the launch of the Crypto Market Integrity Coalition, a pledge committing to a safe and sensibly-regulated crypto industry. Kathy Kraninger, VP of Regulatory Affairs at Solidus Labs, discusses on Cheddar News' Closing Bell the biggest problems in the digital asset space that this new initiative plans to solve.
Chip Shortage Continues to Impact Automobile Production
The global chip shortage continues to weigh on the automotive industry. For example, Ford says it is suspending or cutting production at eight of its factories in North America through next week due to the shortage. Balu Balakrishnan, President and CEO of Power Integrations, joins Cheddar News' Closing Bell, where he elaborates on why the chip shortage has dragged into 2022.
Dan Ives: Apple is Likely 'Aggressively' Pursuing Peloton Takeover
Peloton has weathered a seemingly never-ending storm the past few months: PR blunders, sinking customer demand, and in recent weeks, reported cost-cutting and potential layoffs. Now, several companies are said to be in the mix as potential buyers: Amazon, Netflix, Disney, and Apple. How likely is it that one of these companies pursues a deal — and how likely is it that it will be Apple who buys Peloton? Dan Ives, Managing Director of Equity Research at Wedbush Securities, joins Closing Bell to discuss his thoughts about Apple pursuing a Peloton takeover,
Astra Scrubs NASA ELaNa 41 Space Launch, Sees Its Stock Fall
Astra aborted the launch for NASA ELaNa 41 Mission out of Cape Canaveral on Monday due to what was described as a minor issue, but the company's stock fell nearly 14 percent following the news. Jim Cantrell, CEO and co-founder of Phantom Space, which builds and launches spacecraft of its own, joined Cheddar to discuss the scrubbed mission. “The last thing you want is for this to go wrong, you're better to err on the side of safety expectations,” Cantrell explained, noting that the mission delay was a normal event.
Biden Administration Working To Address TikTok's Security Risk
The Biden Administration is set to revise federal rules to address potential security risks from foreign-owned apps, mainly Tiktok. This comes after the White House opted not to pursue a forced shutdown of the Chinese-owned video sharing platform. Under these new rules, federal oversight would be expanded to explicitly include apps that could be used by foreign adversaries to steal or otherwise obtain data. Senior Fellow at the Foundation for Defense of Democracies, Craig Singleton, joined Cheddar to discuss more.
Decentraland Hosts Its First Metaverse Wedding
The metaverse platform Decentraland hosted its first wedding over the weekend. The union was overseen by Rose Law Group, at the firm's virtual property, hosting witnesses including 2,000 guests. The ceremony endured some technical glitches before being completed.
Load More