Dive Brief:
- Ten days after a cyberattack disrupted its network, 10 locations at South Carolina health system AnMed remain closed, including several outpatient imaging facilities.
- The nonprofit health system initially closed 83 of its facilities in response to a cyberattack on Jul. 26, which involved malware and forced it to temporarily take down its MyChart patient portal and other computer systems.
- AnMed did not respond to a request for comment and hasn’t said when it expects the health system to fully reopen.
Dive Insight:
AnMed, which consists of the 461-bed AnMed Medical Center in Anderson, South Carolina and more than 60 physician practices across South Carolina and Georgia, has kept its urgent care and emergency services locations open throughout the incident. Clinicians still have the ability to access medical records and prescribe medications on a temporarily limited basis, according to an FAQ page.
The health system said it’s working with specialists and federal authorities to determine whether any patient data was impacted. Still, some patients have received suspicious communications, such as MyChart appointment reminders, that appeared to have come from AnMed but actually were generated outside of the system, AnMed said.
“While we have no evidence that patients have been targeted by anyone with malicious intent as a result of this incident, we encourage patients and members of the community to remain cautious with electronic messages that appear to originate from AnMed,” the health system said.
The extended recovery time reflects a growing trend in healthcare cyberattacks. When a health system recovers from an attack, it typically switches to manual processes, such as paper forms and records.
The University of Mississippi Medical Center reopened its clinics more than a week after a ransomware attack in late February forced its electronic health record system offline and limited access to email and phone calls. Similarly, an April cyberattack at Signature Healthcare in Massachusetts impacted the organization’s EHR system, patient portal, and retail prescription processing, resulting in ambulance diversions and more than a week of downtime procedures.
That prolonged recovery, known in the industry as “downtime,” happens more often than it should, and is not something patients should have to get accustomed to, said Baxter Lee, president at healthcare cybersecurity company Clearwater.
“When recovery stretches this far, it is usually a sign that something in the preparation, whether that is the backups, incident response planning and testing, was not where it needed to be,” he said. “That is a gap our industry has to close, not something we should keep excusing as normal.”
Still, downtime is sometimes necessary to contain an attack and ensure malware doesn’t continue to spread.
“Every incident is different, but extended recovery periods have become more common as healthcare organizations take a deliberate approach to restoring systems,” said Jason Griffin, managing director at Nordic, a cybersecurity company.
“That process takes time, but it's critical to avoid reinfection or introducing additional risk while patient care is underway,” Griffin said.
Healthcare data breaches, most of which are caused by cyberattacks, cost an average of $6.6 million per incident, according to research from IBM. Small health systems, under-resourced hospitals and independent practices might feel the impact of a cyberattack or breach more acutely, given that they tend to have less cash reserves than larger multi-hospital systems