Stryker is continuing to respond to a global network disruption affecting its Microsoft environment that began March 11, though the incident has not disrupted U.S. hospital operations, according to the American Hospital Association.
Here are 10 things to know about the cyberattack and how it’s impacting health systems:
- In a March 12 update posted on its website, Stryker said it is working to understand the full impact of a cyberattack on its internal environment. The company, which manufactures hospital equipment ranging from defibrillators to ambulance cots used by hospitals and health systems across the U.S., said it has no indication of ransomware or malware and believes the incident is contained.
- CNN reported March 11 that pro-Iran hackers claimed responsibility for the cyberattack, though Stryker has not confirmed that attribution.
- John Riggi, national adviser for cybersecurity and risk at the American Hospital Association, told Becker’s the AHA is aware of reports of the cyberattack against Stryker and is actively exchanging information with hospitals and the federal government to understand the nature of the threat and assess any potential impact on hospital operations.
- “At this time, we are not aware of any direct impacts or disruptions to U.S. hospitals as a result of this attack,” Mr. Riggi said. “That may change as hospitals evaluate services, technology and supply chain related to Stryker and as the duration of the incident continues.”
- Stryker said the disruption has not affected its LIFEPAK devices, which include defibrillators and cardiac monitors used by emergency responders and hospitals.
- The company also said its LIFENET system, which transmits patient data such as electrocardiograms from ambulances to hospitals, continues to function normally. The company added that some electronic patient care record vendors or hospital systems may have temporarily paused data transmissions as a precaution.
- A spokesperson for Somerville, Mass.-based Mass General Brigham told Becker’s the health system is reviewing the disruption but has taken steps to maintain care operations.
- A Cleveland Clinic spokesperson told Becker’s the health system uses Stryker equipment and is evaluating any potential impacts while monitoring the situation. “Patient care is continuing at all Cleveland Clinic locations,” the spokesperson said.
- Renton, Wash.-based Providence also uses Stryker and told Becker’s that, out of an abundance of caution, the health system’s cybersecurity team has restricted connectivity with Stryker devices, systems and applications while the incident continues to evolve. “At this time, there is no indication of compromise to Providence systems,” the spokesperson said.
- A spokesperson for St. Louis-based BJC Health told Becker’s that it has found no impact to the organization, but is continuing to monitor the situation closely.
The cyberattack comes as Mr. Riggi told Becker’s earlier this month that the war involving the United States, Israel and Iran could prompt Iran, its proxies or self-radicalized individuals to attempt cyberattacks in the U.S.
At the time, Mr. Riggi said the AHA was not aware of any specific credible threats targeting U.S. healthcare organizations but urged them to remain vigilant.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.