Dickinson County Health System (DCHS), with hospitals and clinics in Michigan’s Upper Peninsula and northern Wisconsin, was recently hit with ransomware. On October 17, DCHS discovered “malicious software (commonly known in the industry as ransomware)” that “disrupted access to computer systems at [its] hospitals and clinics.” Such attacks against covered entities (CEs) and business associates are all too common nowadays. RELATED: Coronavirus Cyberattacks: How to Protect Yourself
What happened?
DCHS hasn’t released an official announcement but did provide a general statement to news networks. Upon discovery of the ransomware, DCHS took immediate steps to shut down the affected system to isolate the problem. The breach is currently under investigation and until DCHS restores its computers, it will operate under contingency procedures. Nearly all patient care services (including emergency) are still functioning; staff switched to paper copies (versus digital records) in the meantime. DCHS CEO Chuck Nelson stated:We are treating this matter with the highest priority and are responding by using industry best practices while implementing aggressive protection measures. While we investigate, our top priority is maintaining our high standards for patient care throughout our system.
At this time, DCHS believes that the threat actors have not accessed or taken any protected health information (PHI). RELATED: Is a Name PHI? While DCHS notified the proper authorities right away, the breach has not been added to the U.S. Department of Health and Human Services Office for Civil Rights’ (OCR) Breach Portal yet.
