Report: Alabama Hospitals Pay Hackers in Ransomware Attack

October 7, 2019

An Alabama hospital system that quit accepting new patients after a ransomware attack said Saturday it had gotten a key to unlock its computer systems.

A statement from DCH Health Systems didn’t say how the three-hospital system got the information needed to unlock its data. But The Tuscaloosa News quoted spokesman Brad Fisher as saying the hospital system paid the attackers.

“For ongoing security reasons, we will be keeping confidential specific details about the investigation and our coordination with the attacker,” Fisher told the newspaper.

The company stopped accepting new patients at its hospitals in Tuscaloosa, Northport and Fayette because of a ransomware attack that hit early Tuesday. New patients were sent to hospitals in Birmingham and Mississippi.

The medical center says the protected health information of more than 19,000 patients was exposed through the computer hacking attack.

It’s unclear exactly how many of the records might have been improperly viewed. But news outlets report that a statement issued Friday says UAB Medicine is notifying 19,557 patents that their personal information could be vulnerable.

A news release says hackers got into the records through a malicious email that looked like a request from an executive who wanted employees to fill out a survey. The hospitals said hackers used the ransomware variant Ryuk to lock its files, but the hack didn’t compromise the care of patients. Workers reverted to using paper files.

Instead, the email actually allowed hackers to get into workers’ email accounts and the payroll system. Cybercriminals attempted to divert workers automatic payroll deposits into an account controlled by hackers.

Hospitals continued diverting all but the most critically ill patients through the weekend, the statement said.

The three hospitals, which mostly serve west Alabama, have about 850 beds total and admitted more than 32,000 patients last year.

UAB Medicine says it discovered the attack in early August.

Topics Cyber Alabama

Was this article valuable?

Here are more articles you may enjoy.