Skip to content Skip to navigation

USC’s Keck Medical Center Reports Ransomware Attack

September 26, 2016
by Rajiv Leventhal
| Reprints

The Los Angeles-based Keck Medical Center, part of the University of Southern California, has confirmed that two if its servers were hit with ransomware last month, leading to encrypted files that employees could not access.

According to a statement from the organization released last week, “The attack was quickly contained and isolated to prevent the spreading of malware to other servers.” Data from the encrypted servers was fully restored within several days and no ransom was paid, according to the organization. Officials stated that there is no evidence that data was retrieved or accessed as a result of this ransomware.

“Typically, ransomware is used to deny users access to their information in order to quickly extract money from the data owners—not to steal data. However, as a precaution, we are providing this notice to patients or other individuals whose health or other personal information was in the encrypted folders.”

What’s more, the infected servers do not store Keck's electronic medical record (EMR). Instead, many of the encrypted folders are departmental files that contain internal operational documents such as templates, training manuals, and human resource materials. Sensitive data did however include demographic information, date of birth, identifiable health information, including treatment and diagnosis for some patients, and in some cases, social security numbers.

Regarding the ransomware crisis that is continuing to plague healthcare and other industries, the issue of paying the ransom or not has been a hot one. Recently, the Tulsa, Okla.-based Saint Francis Health System decided not to act on a ransom demand when it was victimized by a breach earlier this month in which approximately 6,000 names and addresses were compromised.

Get the latest information on Cybersecurity and attend other valuable sessions at this two-day Summit providing healthcare leaders with educational content, insightful debate and dialogue on the future of healthcare and technology.

Learn More

Topics

News

Trump Administration Appoints Peter Severino to Head Office for Civil Rights

Roger Severino, a former staffer at The Heritage Foundation, has been appointed as the director of the Office of Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS).

ACP: EHRs Have Great Benefits, but Raise Ethical Questions, Too

Electronic health records (EHRs) should facilitate high value patient-centered care, strong patient-physician relationships, and effective training of future physicians, but they also raise ethical questions, the ACP wrote.

Allegheny Health Network, VA Pittsburgh Integrate EMR Systems

Allegheny Health Network (AHN), based in Pittsburgh, and VA Pittsburgh Healthcare System (VAPHS), have announced the successful integration of their electronic medical record (EMR) platforms.

Wisconsin Urology Group Notifies Patients of Data Breach Due to Ransomware Attack

Wauwatosa, Wis.-based Metropolitan Urology Group has notified its patients of a breach of unsecured patient health information due to a ransomware attack back in November 2016.

Study: For Post-Op Patients, Mobile Apps for Follow-Up Care Led to Fewer In-Person Visits

For patients undergoing ambulatory surgery, those who used a mobile app for follow-up care attended fewer in-person visits post- operation than patients who did not use the app, according to a study in JAMA Surgery.

Information Blocking is Routine and Fairly Widespread, Survey of HIEs Finds

In a survey, 50 percent of HIE leaders said electronic health record (EHR) vendors "routinely" engage in information blocking, and 25 percent reported that hospitals and health systems routinely engage in business practices that interfere with electronic health information exchange.