Ascension St. Vincent’s legacy EHR system hit by ransomware attack

Brunswick, Ga.-based Ascension St. Vincent’s Coastal Cardiology’s legacy systems were encrypted by ransomware. 

Advertisement

On Aug. 15, the practice learned that a “security event” had caused ransomware to be deployed on its legacy systems, according to a breach notification from Ascension. 

An investigation into the incident revealed that an unauthorized user gained access to systems within the legacy Coastal Cardiology network, used by Ascension to retain data, including patient information, in order to meet regulatory requirements. 

Ascension submitted a breach notification to HHS on Oct. 14.

The legacy EMRs contained patients’ personal information and treatment data tied to Coastal Cardiology visits held prior to Oct. 5, 2021, such as demographic details, insurance information, Social Security numbers, clinical information and billing data.

But, because the system was encrypted, Ascension cannot fully determine what kind of information was affected.

Ascension said it does not believe the information has been misused or taken from the system. 

As a precaution, Ascension said it would give all affected patients a free two-year membership to credit monitoring and identity theft detection services.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Register to Attend Webinar

The hidden cost of lost clinical time and how leading health systems are responding

Friday, August 7
12:00 PM - 1:00 PM CDT

Presenters: Kassaundra McKnight-Young, Zebra TechnologiesGregory Carras, Zebra TechnologiesJennifer Gene, Levata

Advertisement

Next Up in Cybersecurity

Advertisement

Comments are closed.