Fenway Health, a Boston community health center serving over 30,000 patients, experienced an IT incident that disrupted patient services last week.
What happened
In a notice displayed across its website, Fenway Health allegedly said it was responding to the incident and warned that MyChart messages and phone responses could be delayed. The organization also canceled its Sexual Health Walk-In Clinic on Friday, September 11 and directed people with urgent needs to seek care at an urgent care clinic. Fenway Health spokesperson Ryan Dunn described, “We have taken multiple steps to limit impacts to patient care,” in a statement provided to Axios, but did not confirm whether it resulted from a cyberattack.
Dunn said the healthcare organization had taken multiple steps to reduce the effects on patient care and was working with external IT specialists to restore normal operations. Fenway Health did not disclose when the incident was detected, which systems were affected, or whether appointments and prescription services experienced broader disruption. It also did not say whether patient information or sensitive data was accessed, acquired, or exposed. The organization had removed the IT warning from its website by Sunday, according to Axios, although the disappearance of the notice did not establish that every affected system had been restored.
What was said
The Axios report stated, “Fenway Health declined to confirm that it experienced a "cyber attack" after announcing its sexual health clinic was closed on Friday, but a spokesperson called the incident an "interruption to IT systems" in an emailed statement to Axios on Saturday.”
Why it matters
Fenway Health’s IT incident recalls a 2023 ransomware attack against Ardent Health Services that Paubox reported disrupted 30 hospitals across six states. Ardent shut down its network to contain the attack, taking Epic software and other clinical applications offline. Some hospitals diverted ambulances, rescheduled nonemergency procedures, and temporarily relied on manual processes. Fenway’s disruption appears more limited, the community health center warned that MyChart messages and telephone responses could be delayed, canceled one sexual health clinic session, and brought in external IT specialists. Unlike Ardent, Fenway has not identified its incident as a cyberattack or disclosed whether patient information was accessed.
A peer-reviewed study available through NCBI explains, “Downtime events disrupt the patient care process, deactivate safety measures, such as clinical decision support systems, and can compromise patient safety.” The researchers also found that laboratory results were reported an average of 62% later during electronic health record downtime than under normal operating conditions. Fenway has not reported laboratory delays or confirmed that its electronic health record became unavailable. The comparison nevertheless shows how interruptions affecting digital communication can expand into broader care delays when critical systems remain inaccessible, making contingency plans and clear patient updates essential throughout investigation and recovery.
See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)
FAQs
When is a third-party vendor considered a business associate?
Under HHS guidance, a vendor is generally a business associate when it creates, receives, maintains, or transmits PHI for a HIPAA covered entity.
Does every third-party IT incident count as a HIPAA breach?
No, an outage alone does not establish a breach, although an impermissible use or disclosure of unsecured PHI is presumed to be one unless a documented assessment finds a low probability of compromise.
How quickly must a business associate report a breach?
A business associate must notify the covered entity without unreasonable delay and no later than 60 days after discovering the breach, although its contract may require faster reporting.
