Skip to content Skip to navigation

Appalachian Regional Healthcare Hit with Cyber Attack, Systems Down for a Week

September 2, 2016
by Heather Landi
| Reprints
Click To View Gallery

Appalachian Regional Healthcare (ARH), a health system with hospitals in eastern Kentucky and southern West Virginia, is still in the process of trying to restore its systems following a cyber attack that was discovered Saturday, Aug. 27.

Last Saturday, ARH Spokesperson Melissa Cornett released a statement saying the health system was dealing with technical complications.

The ARH system of hospitals in Kentucky and West Virginia are operating under their Emergency Operations Plan due to a computer virus "that has limited our use of electronic web-based services and electronic communications," Cornett said in her statement on Aug. 27.

ARH operates 11 hospitals, two in West Virginia and nine in Kentucky.

On Tuesday, Cornett released a statement saying officials do not believe at this time private patient information has been compromised. “ARH continues to work with authorities and computer experts to address the problems and restore our systems to operational capacity as quickly as possible,” she stated.

“In the meantime, ARH would like to emphasize that we presently have no reason to believe that the protected health information or any financial information of our patients or employees has been accessed. Please be assured that ARH will investigate this fully, and will take prompt action to notify and protect patients and employees if it appears that their private information has been accessed.”

Since Saturday, ARH employees had been tracking patients and performing their jobs without access to any of the hospitals’ computerized systems, Cornett said Tuesday afternoon.

Cornett further stated, “ARH’s hospitals and other locations of care across eastern Kentucky and southern West Virginia remain open, and our staff is working hard to continue to provide the same level of quality healthcare to our patients while we recover from this cyber attack. We appreciate the extra efforts of our outstanding workforce, and the patience of the people we serve, as we work through the inconvenience of having computer systems out of service.”

Cornett said all ARH computers were shut down to prevent further spread of the virus and all paperwork is being managed manually. She said staff will assess all critical patients to determine if they should be transferred to another facility for care. Officials ask patients visiting a physician practice to bring all prescribed medications to upcoming appointments until further notice.

Local news station WYMT, a CBS affiliate, reported on Tuesday that federal authorities are investing the cyber attack at ARH. "A law enforcement source told CBS News that they are aware of a cyber breach at ARH. CBS News reports the incident appears to be ongoing. When asked whether it was a ransomware case, a situation in which hackers demand money, an FBI spokesman would not comment except to say ‘they cannot confirm or deny the existence or non-existence of an investigation,’” the WYMT report stated.

A number of hospitals have been hit with ransomware attacks in the past year, and the situation at ARH, with a computer virus requiring the shut-down of most of the computer systems, bears some similarity to those attacks. In February, Los Angeles-based Hollywood Presbyterian had to operate without its computer systems and without access to electronic health records for more than a week. The computer systems were only restored after the hospital paid hackers $17,000. In late March, the MedStar Health system, based in Columbia, Md., and serving the Washington-Baltimore corridor, also was hit with a ransomware attack and systems were down more than a week. MedStar Health officials denied that any ransom was paid related to the cyber attack on its computer networks.

Get the latest information on Cybersecurity and attend other valuable sessions at this two-day Summit providing healthcare leaders with educational content, insightful debate and dialogue on the future of healthcare and technology.

Learn More

Topics

News

CMS Extends Deadline for eCQM Data Submission

CMS is extending the deadline for eligible hospitals in the Hospital Inpatient Quality Reporting (IQR) and Meaningful Use programs to submit their electronic clinical quality measure (eCQM) data from 2016.

NorthShore Revalidated by HIMSS Analytics as Stage 7 Worthy

Due to its continued use of IT to improve patient care and reduce costs, Chicago-based NorthShore University HealthSystem has received Stage 7 revalidation on HIMSS’ acute care EMRAM and outpatient EMRAM for its hospitals and associated clinics.

Cybersecurity Consulting Firm CynergisTek Acquired by Auxilio

Austin, Tex.-based cybersecurity and privacy consulting firm CynergisTek has been acquired by Auxilio, Inc., a provider of document workflow solutions and IT security services based in Mission Viejo, California, in a deal valued at up to $34.3 million.

Healthcare Data Breaches: A Year in Review

The latest year-in-review Breach Barometer report from Protenus paints a stark picture—2016 average at least one health data breach per day, affecting more than 27 million patient records.

Healthcare Industry Could Save $9.4B with Full Adoption of Electronic Transactions

The healthcare industry continues to make modest progress toward full adoption of electronic business transactions, but significant gaps remain, representing an opportunity for $9.4 billion in savings, according to new data from the 2016 CAQH Index.

ONC Announces Phase 2 Winners of Consumer, Provider App Challenges

ONC today announced the Phase 2 winners for the Consumer Health Data Aggregator Challenge and the Provider User Experience Challenge.