Once a network is infected, ransomware will encrypt files and lock users out, usually until a specified sum of money is paid. Ransomware has taken off in the past year among hackers, as it is effective and extremely difficult to trace, with the most noteworthy instance occurring in March at Hollywood (Calif.) PresbyterianMedicalCenter, which paid $17,000 to hackers after losing access to its EHR system for a week. The FBI and HHS recommend organizations do not pay up.
After coming across encrypted files in its internal network, the St. Mary Medical Center-owned organization sent notification letters to affected patients, according to the Bucks County Courier Times. In the letter, a hospital spokesperson said the organization could not guarantee patient records had not been accessed, and therefore is offering a year of free identity-theft protection and credit monitoring.
The organization is still investigating the source of the ransomware and stated in the letter that medical records were kept in a separate server and were not compromised.
More articles on data breaches:
June was the worst month so far for hospital data breaches
Midland Memorial Hospital investigating potential data breach of records left unsecured at physician’s home
Dignity Health data breached by third-party employee with fake nursing license
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.