- Journalists Assess Risks of Tick Bites, Wildfire Smoke, Rising Health Costs
- Jefferson Health sues Independence Blue Cross over nearly $100M in disputed payments
- 240 community hospital CEOs to know | 2026
- 4 behavioral health data breaches making headlines
- 17 recent hospital, health system president exits
- 5 federal behavioral health bills for leaders to watch
- HHS appeals decision vacating provisions of 2025 ACA marketplace rule
- Imagen Dental Partners adds Seattle practice
- Texas dental practice suffers data breach
- Health systems alter approaches to workforce housing
- ACA fallout hits for-profit health systems harder than expected
- 25 new behavioral health study findings to know
- Rural hospitals build scale to stay independent: Commonwealth Fund
- Lunch, low acuity and ‘family’: How ASCs beat the CRNA cost crunch
- HCA’s $1.2B ACA hit raises red flag for nonprofit health systems
- Where AI is delivering the biggest supply chain wins
- Northwell’s Lenox Hill Hospital Brain Tumor Center Gala raises $1.6M
- Florida dental office remains closed amid patient death investigation
- Lyon College dental school names inaugural medical director for pediatric program
- A massive month for ASC policy: 5 key updates
- 130+ DSO affiliations so far in 2026: State-by-state breakdown
- AHA releases SUD treatment toolkits
- 8 DSOs making headlines
- California unveils $109M for behavioral health supportive housing
- Idaho physician to pay $1.25M for Medicare, telemedicine fraud scheme
- Connecticut enacts sweeping CON reforms: 10 things to know
- The 1st physician specialty to top $600K
- 38% of teens use a substance by age 16: 5 study notes
- Why it’s time to ‘jettison’ Stark law
- Allina Health to open 620,000-square-foot surgery center
- Tenet Healthcare shrugs off ACA headwinds with sweeping Q2 outperformance, boosts 2026 guidance
- FDA Advisers Dismiss Safety Warnings, Back Four Peptide Treatments
- Frequent Marijuana Use Linked To Higher Stress Hormone Levels
- What's behind Aetna's investments to build provider trust
- New university initiative offers screening, referrals for endometriosis
- Peptide adcomm Day 2: Emideltide voted down in panel's 1st pushback
- HCA Healthcare's H1 ACA volume dropoffs 'almost one for one' shifted to uninsurance
- Novo escalates Lilly false advertising suit with planned bid to halt comparative ads
- Industry Voices—The new model for rural healthcare is already taking shape
- Amgen hands in data package in hopes of FDA hearing for Tavneos defense
- Another setback for Ipsen's Albireo portfolio as Bylvay flunks phase 3 trial
- Back Pain? Try Swimming, Study Says
- Ozempic Cuts Down Calorie Intake For At Least A Year, Even If Hunger Returns, Trial Finds
- Money Problems Might Make Your Brain Old Before Its Time, Study Suggests
- GSK’s first lung cancer approval, a new IPO path and more
- Merck stages expanded access to monthly HIV PrEP pill ahead of approval
- Black MS Patients Dying Younger Than White Ones, Study Finds
- Public Health Improvements Stall Amid Trump's DEI Crackdown
- ‘The Child Is Terrified’: Doctors on the Front Lines of a Measles Comeback Speak Out
- To Afford Aging in Place, Older Adults Turn to ‘Golden Girls’ Housing
- Watch: GOP Senator Says Trump’s Tariffs Could Mean Safer Drugs — For a Price
- Gastroenterologists flag clinical remission and its durability as unmet needs in IBD care: survey
- OpenAI makes Health in ChatGPT widely available, moving deeper into consumer health
- Many U.S. Schools Unprepared To Help Concussed Students Return To The Classroom
- Oral surgery platform buys back ownership stake from private equity firm
- Stamford Health opens EmPATH unit with follow-up care
- What will it take to truly fix anesthesia?
- 5 forces reshaping physician compensation in 2026
- Cardiologists’ pay averaged $575K in 2025, yet half feel underpaid: 10 stats to know
- New York unveils dashboard tracking mental health investments
- PDS Health-anchored retail pad in South Carolina sold for $3.7M
- 15 behavioral health services, facility closures | 2026
- Growth in a year the industry slowed: what Elevate Dental Partners is doing differently
- Philadelphia dentist whose patients were urged to get tested for HIV, hepatitis to reopen practice
- The unlicensed therapist 8 million kids are seeing
- Fierce Pharma Asia—Trump’s generic drug tariffs; Samsung Bio’s $1.8B acquisition; An unusual IPO
- New CMS data spotlight continued rise in No Surprises Act disputes
- Weekly Rundown: FDA names Dexcom as first TEMPO participant; Ardent Health tops 1M patient visits with ambient AI
- UPDATE: Peptides favored on 1st day of closely watched FDA compounding adcomm
- Nearly 1.6 Million Dozen Eggs Pulled From Shelves Over Salmonella Concerns
- Molina Healthcare plans more marketplace exits as ACA segment falters
- Organized Sports Help Enhance Motor Skills In Children With Autism
- Teal Health, UC Davis team up to expand HPV screening access
- D.C. appeals court sides with HHS in 340B drug discount program rebate challenge
- Roche defends 6B franc Vabysmo peak sales target despite another quarterly miss
- BeOne jumps aboard onshoring train with $300M to add small molecule production in US
- People Living Longer, But Spending More Years With Illness And Disability
- Exercise Underwhelms As A Hip Arthritis Treatment, Review Concludes
- Tongue Pacemaker Might Improve Sleep Apnea Patients' Health
- Poll: Costs Are Top Health Care Issue For Midterm Voters, But Fraud Tops GOP List
- Listen to the Latest ‘KFF Health News Minute’
- A Death Revives Concerns About Police Brutality Six Years After National Reckoning
- Public Health Improvements Stall Amid Trump’s DEI Crackdown
- FDA rebukes 2 Indian API plants over data controls, sanitation issues
- Australian biopharma Clinuvel to shed up to 20% of workforce in move to US
- J&J’s bispecific combo slashes myeloma progression risk by 89% in phase 3 trial
- ARS Pharma drafts NFL legend Drew Brees in allergy awareness push
- Teladoc Health unveils new virtual care model for employers, health plans that ties payment to results
- Anterior, Stellarus enter strategic partnership to speed up AI-driven prior authorizations
- Amid ACA subsidy fallout, half of Community Health Systems' Q2 volume gains were uninsured patients
- CMS appeals court decision behind 2026 MA star ratings recalculations
- Boulder Care awarded NIH grant to provide SUD care in complex settings
- Prosper Medical banks $16M to scale AI-driven concierge care platform
- CMS proposed rule lays groundwork for more OBBBA provider tax cutbacks
- Measles Cases Set 35-Year US Record With Months To Go In 2026
- Taylor Farms Faces Cyclospora Outbreak, Recalls And Political Questions
- GSK secures first lung cancer approval as FDA clears Jideytro in quick payoff from Nuvalent deal
- Cigna expands AI-powered care management programs for members
- Visana revamps well-woman visit to comprehensively address symptoms
- Headstands and Summervaults: A Statement on Crypto Vaults and Lending Strategies
- What to Expect at PODD 2026
- Candid Health secures $120M series D as investment in AI-powered RCM ramps up
- GLP-1 Use Surges Among Young People With Obesity
- FDA calls out Sanofi emails for giving 'misleading impression' of Beyfortus use in RSV
- Look out Ionis, here comes Arrowhead with promising hypertriglyceridemia data
- Trump floats countdown to 200% tariffs on generic drugs imported to US
- Summit Therapeutics updates ivonescimab survival data ahead of FDA decision date
- 1 In 4 Americans Stuck In Jobs For Health Insurance, Survey Finds
- How Does ADHD Affect Athletes' Concussion Risk?
- TV Does Indeed Rot Your Brain, Study Says
- Tick-Borne Meat Allergy: Many Carry Alpha-Gal Antibodies Without Symptoms
- Agencies In New York And Beyond Pass The Buck On Opioid Cash Oversight
- American Scientists See Prosecutions as Part of Federal Campaign Against Them
- Trump’s Personnel Agency Says It Will Remove Some Identifying Info as It Sweeps Up Medical Records
- Biotech industry leaders file brief backing FDA against ‘malicious’ mifepristone challenge
- Remarks at the Small Business Capital Formation Advisory Committee Meeting
- Seeking Public Comment on Seeking Public Capital: Remarks Before the Small Business Capital Formation Advisory Committee
- Remarks to the Small Business Capital Formation Advisory Committee
- Cannabis Drinks Sold Next To Soda Are Sending Kids To The ER, Doctors Say
- Coffee May Lower Your Heart Disease Risk, But How Much Is Safe?
- More Than Half Of US Adults Should Be Offered Statins, Study Says
- Gait Training Can Help Knee Arthritis
- The Best Surgery For Pelvic Organ Prolapse?
- Doctors 'Cringe' At Possibility Of Documenting Which Medicaid Enrollees Are Too Sick to Work
- Compounded Ozempic, Zepbound Still Widely Available Despite End Of Drug Shortages
- Leadership Vacuum: Agencies in New York and Beyond Pass the Buck on Opioid Cash Oversight
- FDA: Iceberg Lettuce Recall Stands After False Positive For Cyclospora
- Why Do So Many Women Miss The Signs Of Perimenopause?
- Virtual Therapy Sessions Improve Lives Of Kids With Lupus
- More Evidence Links Sleep Apnea To Dementia And Memory Loss
- Study Links GLP-1 Medications To Rare Vision Issue
- Gut Bacteria May Hold Key To Preventing Severe Peanut Allergies
- Trump's CDC Nominee Praises Vaccines, Without Vowing Independence From RFK Jr.
- CDC Warns Of Parasite Outbreak Tied To Taco Bell Lettuce In 5 States
- The Best Vegetables For Your Heart May Depend On Your Sex
- One Type Of ADHD Med May Affect Kids' Weight
- Poll: Many Older Americans Unaware Of 988 Suicide Help Line
- ‘Substantially better than before’: Why India has golden opportunity to build on innovative R&D wins
- Statement on Regulation E-Delivery
- Paper Taper: Statement on Proposed Regulation E-Delivery
- Statement on Proposed Regulation E-Delivery
- Remarks before the American-Hellenic Chamber of Commerce
- Remarks at the Society for Corporate Governance Conference
- Zimmer Biomet to Hire 500 in India as New Bengaluru Technology Centre Drives AI and MedTech Innovation
- AdaptHealth Investigates Data Breach After Social Engineering Attack, Possible Link to ShinyHunters Emerges
- Statement on the 2026 Regulatory Agenda
- Applying Agentic AI to Healthcare Delivery: The Key to True Transformation
- From Compliance to Clinical Action: Fixing the Broken Loop in Post-Market Surveillance
- Regulatory tracker: AZ gains EU nod for camizestrant; China 1st to endorse Takeda's narcolepsy drug
- Remarks at the Economic Club of New York
Michigan healthcare freedom community forum
Ascension's hospitals in Michigan and across the country have reverted to paper systems. Their computer systems have been put down due to a cyberattack:
Cyberattack hits Ascension hospitals' computer networks: 'It's affecting everything'
By Kristen Jordan Shamus - May 9, 2024Ascension hospitals in Michigan and across the U.S. were hit Wednesday by a cyberattack that disrupted its computer network which continued to affect its clinical operations Thursday morning, leading the nonprofit, St. Louis-based health system to urge its business partners to sever online connections to its system.
"We detected unusual activity on select technology network systems, which we now believe is due to a cyber security event," Ascension said in a statement posted on its website. "At this time we continue to investigate the situation. We responded immediately, initiated our investigation and activated our remediation efforts. Access to some systems have been interrupted as this process continues.
"Our care teams are trained for these kinds of disruptions and have initiated procedures to ensure patient care delivery continues to be safe and as minimally impacted as possible. There has been a disruption to clinical operations, and we continue to assess the impact and duration of the disruption."
With computers offline, 'It's like the 1980s or 1990s'
Employees noticed the computer network problems about 7 a.m. Wednesday, said three workers who spoke on the condition of anonymity out of fear of job repercussions.
"There was a security concern, so they shut down the system," one physician told the Free Press. "It's affecting everything."
Another Ascension Michigan doctor said: "We have no access to medical records, no access to labs, no access to radiology or X-rays, no ability to place orders.
"We have to write everything on paper. It's like the 1980s or 1990s. You go to the X-ray room to look at the X-rays on film, you call the lab they tell you what the results are over the phone. So it's just much more cumbersome, but we do have training for these moments."
A nurse told the Free Press on Wednesday evening that Ascension hospitals were still accepting patients by ambulance who were medically unstable and in need of lifesaving treatment. But those who were more stable and could be taken to other nearby hospitals for care were diverted because of the computer network outage.
"I just hope it doesn't last very long because certainly patient care will be negatively impacted," a physician said. "The data that shows that during computer network downtime, your risk of an adverse event goes up."
Ascension said it is working with Mandiant, a cybersecurity consulting company, to investigate and help determine what information, if any, was compromised in the cyberattack.
"Should we determine that any sensitive information was affected, we will notify and support those individuals in accordance with all relevant regulatory and legal guidelines," Ascension said in a statement.
Attack comes as Ascension aims to spin off Michigan hospitals
A Catholic health system, Ascension has 140 hospitals and 40 senior care facilities across 19 states and the District of Columbia. It reported in May that it had 134,000 employees.
In Michigan, the health system operates 15 acute-care hospitals, but is in the midst of trying to close deals that would split off eight of its southeastern Michigan hospitals and combine them with Detroit-based Henry Ford Health. Additionally, three of its hospitals in mid-Michigan and northeastern Michigan, along with a stand-alone emergency center and nursing home, are to be acquired by Midland-based MyMichigan Health.
Ascension St. John Hospital in Detroit, left, and MyMichigan Medical Center Sault in Sault Ste. Marie.
If those deals are completed, only the following Ascension Michigan hospitals will remain as part of the health system's national holdings:Ascension Allegan Hospital in Allegan
Ascension Borgess Hospital in Kalamazoo
Ascension Borgess-Lee Hospital in Dowagiac
Ascension Borgess-Pipp Hospital in PlainwellBreaches threaten protected health information, more
Cyberattacks are becoming increasingly common in health care, often affecting protected health information along with other data, such as account numbers, Social Security numbers, phone numbers and addresses.
In April, Cherry Street Services Inc., also known as Cherry Health, alerted 180,747 Michigan residents that their personal information had been compromised in a ransomware attack that occurred on Dec. 21.
"Third-party forensic experts were retained to assist in an investigation of the nature and scope of the breach," said Danny Wimmer, press secretary for state Attorney General Dana Nessel. "While unable to pinpoint (the) root cause of the breach, through the investigation Cherry was able to discern the types of data compromised: full name, address, date of birth, phone number, health insurance information, patient ID number, provider name, service date, diagnosis/treatment information, prescription information, financial account information and/or Social Security Numbers, and the identity of the persons impacted."
That's not all.
More than 1 million Michiganders were affected by a cybersecurity breach at Welltok Inc., a software company contracted to provide communication services for Corewell Health's southeastern Michigan properties along with a healthy lifestyle portal for Priority Health, an insurance plan owned by Corewell. Though the breach occurred in May 2023, it wasn't until November 2023 that people were notified.
A ransomware attack took down the computer network at McLaren Health Care's 14 Michigan hospitals in late August and early September 2023, affecting about 2.5 million patients. The health system acknowledged that it also could have leaked some patient data onto the dark web. A ransomware gang known as BlackCat/AlphV claimed responsibility for the cyberattack, posting online that it stole 6 terabytes of McLaren's data.
And in late August 2023, the University of Michigan shut down its campus computer network after a hacker got access to the personal information of students and applicants, alumni and donors, employees and contractors, as well as the personal health information of research study participants, and patients of the University Health Service and the School of Dentistry.
This has become all too common. You have to wonder what kind of clown show health care data IT has become. The United States was supposed to be the leader in IT technology, but is clearly deficient. DEI at work?
That's quite a list of Michigan hospitals hit in the past year. Maybe journalists should report the shorter list of who has NOT been hit, and find out why??
Another Ascension Michigan doctor said: "We have no access to medical records, no access to labs, no access to radiology or X-rays, no ability to place orders.
Data breaches are bad, of course.
But as for operability, WE TOLD THEM THIS FIFTEEN YEARS AGO. Sorry to yell, but can they hear us now?
It has always been people who make healthcare work - not computers. And mandated EHRs that served patients and clinicians well have always been the exception rather than the rule.
No computers means people talk to each other more. This is actually a good thing for all of us. We should do more of it.
Patient perspective from Fox2 Detroit.
News video available at the hyperlink.
Ascension hospital cyber attack disrupts patient's visit for potential cancer diagnosis
SOUTHFIELD, Mich. (FOX 2) - A patient at Ascension Providence checked himself into the Southfield hospital this week amid fears that his cancer had returned. Instead, he found himself witnessing the fallout from a cyber attack that targeted more than a hundred hospitals around the U.S.
The chaos was on display Wednesday while Zackery Lopez waited hours for pain medication - a request that went unanswered for seven hours before a nurse finally brought him some relief.
During that time, Lopez said he saw patients checking themselves out of Ascension Providence, located on Nine Mile.
"Right now it is crazy. Nurses are running around. Doctors are running around. There’s no computers whatsoever they can use," he said. "So, they’re actually using charts."
Using the physical copy of someone's medical data wouldn't be an issue for Lopez if he wasn't concerned that his personal information was at risk. But he told FOX 2 he hasn't gotten a satisfying answer.
"They really didn’t tell me if it was protected or not," he said. "They really kind of just brushed it off when I asked them. They say they’re trying to get everything back on, back on track."
Lopez first checked himself into Ascension on Tuesday around 2 p.m. due to internal bleeding. He got admitted by a doctor, but was told he would have to wait for a room. As of Wednesday night, he still hadn't gotten into a room.
According to the hospital group, 140 Ascension locations are affected by the cyber attack, as well as 40 senior living facilities.
In a statement to FOX 2, the hospital said it first noticed "unusual activity" on its network on Wednesday.
"Our care teams are trained for these kinds of disruptions and have initiated procedures to ensure patient care delivery continues to be safe and as minimally impacted as possible. We have notified the appropriate authorities and are working to fully investigate what information, if any, may have been affected by the situation."
Bridge Michigan adds to the story.
Audio and images omitted here for space, remain available in the hyperlink.
Cyberattack forces Ascension hospitals in Michigan to reroute patients
May 10, 2024 | Robin Erb
Hackers on Wednesday broke into the patient health records and other systems at the Ascension hospital chain.
That put at risk medical information at the health-care giant’s 15 Michigan hospitals and caused at least one to send arriving patients elsewhere.
Patients should write down medications and symptoms, an Ascension spokesperson told Bridge Friday.
One of the nation's largest hospital chains remained under a cyber threat as the workweek closed — an attack that cut off access to the system’s electronic health records system, disrupted phones as well as scheduling and testing processes, and forced the rerouting of at least some Michigan patients. The attack also suspended some non-emergency elective procedures, tests and appointments.
What the weekend will hold is unclear.
Investigators are “working around the clock” to contain the breach and “restore our systems,” according to a statement by Ascension Thursday evening. “Our investigation and restoration work will take time to complete, and we do not have a timeline for completion.”
Ascension Michigan spokesperson Airielle Taylor said Friday the health system was “still detecting unusual activity.”
Related:
Henry Ford, Ascension Michigan to partner in latest health care shift
Experts: Henry Ford, Ascension Michigan venture likely to impact care, costs
University of Michigan restores internet access, still mum on security issueOn Thursday, patients arriving at Ascension Macomb-Oakland Hospital were rerouted under a diversion protocol, Taylor said.
But such problems “fluctuated,” she said. Other locations were not under a diversion protocol, but it was not clear if that would change, she said.
She said patients are advised to “have your medications written down and have your symptoms written down.”
The problems began Wednesday when the St. Louis-based hospital system “detected unusual activity on select technology network systems,” determining it to be a “cybersecurity event,” according to a statement released early Thursday.
That included patient records on MyChart, which allows patients to see their records, schedule appointments and talk with providers.
Ascension advised that its business partners “temporarily suspend the connection to the Ascension environment” until further notice.
The chain on Thursday sought to reassure the public that Ascension staff “are trained for these kinds of disruptions and have initiated procedures to ensure patient care delivery continues to be safe and as minimally impacted as possible.”
To divert patients from some locations throughout the 140-hospital system to other hospitals. Ascension has hospitals in 19 states, including 15 in Michigan. It also operates 40 senior living facilities.
The Ascension breach is the latest from a “constant threat and attack” by cyberattackers, said one cybersecurity expert that works with Michigan hospitals.
“Because it’s an ecosystem in which information is shared, it’s a system that can be vulnerable” to attack, said Eric Eder, president of CyberForce|Q, which operates the Michigan Healthcare Security Operations Center and works with the Michigan Health & Hospital Association, an effort in which hospitals and health-care systems share information as quickly as possible during a breach.
Eder declined to comment on the attack on Ascension. But speaking in generalities, he said attacks on health care are usually sophisticated and well-coordinated among many individuals, using bots and other automated means to search out a system’s vulnerabilities.
“There’s this image of the hacker over a laptop in a hoodie,” he said.
Rather, “it’s a more coordinated effort with a mix of automated systems and human actors.”
Ascension is working with Mandiant, a third-party cybersecurity firm and subsidiary of Google, to assist in the investigation, according to its statement early Thursday.
Hospital officials said they were trying to determine “what, if any” information had been breached.
“Should we determine that any sensitive information was affected, we will notify and support those individuals in accordance with all relevant regulatory and legal guidelines,” according to Ascension’s statement.
It's the latest in bad news for the health-care giant, which in recent months has shed properties after reporting a $3 billion loss in 2023.
In October, Detroit-based Henry Ford Health and Ascension Michigan announced their “joint venture” in which eight Ascension properties in southeast and mid-Michigan will take on the Henry Ford Health identity. And in March, Ascension agreed to shed three more hospitals, selling locations in Saginaw, Tawas and Standish to Midland-based MyMichigan Health.
Ascension personnel at Providence Rochester Hospital are getting skittish about continuing operations before the computer hack is resolved:
Ascension staff petition for safety precautions amid ransomware attack
By Kate Wells | May 27, 2024More than 100 people have signed a petition circulating among medical staff at Ascension Providence Rochester Hospital seeking a reduction in elective surgeries and non-emergent patient admissions, as well as more training, during the ongoing fallout from a ransomware attack.
Nearly three weeks after the ransomware attack seriously disrupted basic functioning at Ascension’s 140 hospitals nationwide, including 15 in Michigan, doctors and nurses throughout the state have been raising serious concerns about the impact to patient care. They still don’t have access to patients’ medical records. Safety protocols intended to reduce the risk of medication errors have been temporarily removed or disabled. Crucial lab and test results are taking hours or getting lost completely. And elective surgeries and patient transfers are still happening, despite some staff’s concerns.
“We, the members of Local 40 at Ascension Providence Rochester Hospital, are deeply concerned about the current challenges faced by our healthcare professionals due to the cyber hack incident and subsequent lack of access to patients’ electronic medical records,” the petition reads. It’s addressed to Ascension CEO Joseph Impicciche, Michael Wiemann, the president of Ascension Michigan, and other national and local administrators.
“In light of these circumstances, we demand that immediate safety precautions be implemented to ensure the well-being of both our members and the patients under our care … including but not limited to:
1. **Unit Shift Huddles**:
Implement daily unit shift huddles to ensure effective communication, coordination, and information sharing among healthcare professionals regarding patient care, safety protocols, and any emerging issues.
2. **Training Sessions**:
Conduct regular training sessions for staff members to enhance their knowledge and skills in navigating the challenges posed by the ongoing cyber hack incident and operating without access to electronic medical records.
3. **Weekly Progress Reports**:
Provide weekly progress reports to update staff members on the status of efforts to resolve the cyber hack incident, restore access to electronic medical records, and address any safety concerns or staffing issues.
4. **4:1 Nurse-to-Patient Ratio**:
Maintain a maximum 4:1 nurse-to-patient ratio until the matter is fully resolved to ensure that patients receive the level of care and attention they require, despite the challenges faced by our healthcare professionals.
5. **Reduction in Elective Surgeries & Non-Emergent Admissons**:
Temporarily reduce elective surgeries and non-emergent admissions to alleviate the strain on resources and prioritize care for critical patients.
These safety precautions are essential to safeguarding the well-being of both our members and the patients we serve during this challenging time. It is imperative that the hospital administration takes immediate action to address these concerns and prioritize the safety and quality of care for all individuals involved.
We, the undersigned, stand united in demanding these safety precautions be implemented without delay and call upon the hospital administration to prioritize the well-being of both staff and patients throughout this challenging period.”
A spokesperson for Ascension did not respond to the specifics in the petition, but sent a version of the same language the health system posted on its website on May 24:
"Ascension continues to work around the clock with industry-leading cybersecurity experts to safely restore operations across our network. We are hopeful that after the weekend, our patients and clinicians will see progress across our points of care. Many of our vendors and partners have also started the process of reconnecting to our network and resuming services with Ascension, which should help to accelerate our overall recovery.
"Despite the challenges posed by the recent ransomware attack, patient safety continues to be our utmost priority. We are grateful to our dedicated clinicians and care teams who are providing care under challenging circumstances. The compassion and resilience they have displayed throughout this event is truly remarkable and is emblematic of Ascension’s mission to improve the health of the individuals and communities we serve."
Ascension's IT department expects electronic records restoration in Michigan by June 14th. Will it be a full restoration?
Ascension to restore Michigan electronic health record systems by June 14
By Hannah Mackay - June 5, 2024The Ascension health care system is working to restore electronic health record systems in Michigan hospitals by the end of next week, more than a month after a national cyberattack was detected.
Electronic record systems have already been restored at Ascension hospitals, physician offices and care sites in Florida, Alabama, Austin, Tennessee and Maryland markets and the health care system, according to an update posted Wednesday.
"Based on what we have learned about this process to date, we are working toward completing (electronic health record) restoration across our entire ministry by the end of the week ending June 14," the health care system said.
Ascension Rx retail, home delivery and specialty pharmacy sites in Michigan also have returned to normal operations, and providers can again transmit prescriptions to pharmacies electronically, according to an announcement Tuesday.
Ascension first detected unusual activity in its technology network systems on May 8 and determined it was a cybersecurity event. Initially, the electronic health records system, MyChart, some phone systems, and some systems used to order tests, procedures and medications were unavailable and Ascension facilities switched to downtime procedures or manual protocols like using paper records and processing everything by hand.
"As we have previously communicated, restoring Electronic Health Record (EHR) access has been among the top priorities of our recovery process," Ascension said. "As EHR is restored across the entirety of our networks, clinicians will be able to access patient records as they did prior to this incident."
Some elective procedures and appointments temporarily were paused last month and emergency services were diverted from several hospitals to ensure cases were triaged. All Ascension Michigan emergency departments currently are open and accepting transfers, according to a regional update. Diagnostic imaging and testing have been temporarily delayed at some local facilities to ensure resources are focused on inpatient and emergency services.
Meanwhile, appointments at Ascension Michigan sites are taking place as planned, although patients may experience delays due to the transition to manual systems, the health care system said.
"To help with delays, patients should bring notes on symptoms and a list of current medications, including prescription numbers or bottles," the update said. "In the event that appointments need to be rescheduled, an Ascension associate will contact patients directly."
Ascension's investigation into the cybersecurity event and the restoration of additional systems remains underway, the healthcare system said Wednesday. They previously announced they were working with forensic experts from three cybersecurity firms, Mandiant, CYPFER, and Palo Alto Networks Unit 42, to investigate the attack.
Ascension is mailing data breach notifications to 5,599,699 people compromised by a May cyberattack linked to the Black Basta RaaS ransomware operation. Ascension will offer victims 24 months of free identity theft protection, including monitoring, and a $1,000,000 insurance reimbursement policy:
Ascension: Health data of 5.6 million stolen in ransomware attack
By Sergiu Gatlan - December 20, 2024Ascension, one of the largest private U.S. healthcare systems, is notifying nearly 5.6 million patients and employees that their personal and health data was stolen in a May cyberattack linked to the Black Basta ransomware operation.
The health network reported a total revenue of $28.3 billion in 2023 and operates 140 hospitals and 40 senior care facilities across the United States.
The company now mails data breach notifications to 5,599,699 affected individuals via the United States Postal Service. Starting Thursday, December 19, Ascension also offers affected people 24 free months of IDX identity theft protection services, including CyberScan monitoring and a $1,000,000 insurance reimbursement policy.
Ascension says it notified law enforcement and government partners, such as CISA and the FBI, of the breach after detecting the May 8 attack.
"Upon discovering the unauthorized activity, we initiated an investigation with the assistance of leading cybersecurity experts," Ascension states in the breach notification letters. "Through this investigation, we found evidence that on May 7 and 8, a cybercriminal obtained a copy of certain files containing personal information of our patients and associates."
Since the breach, Ascension's investigation has revealed that some of the stolen files contained patients' and employees' names and information across one or more of the following categories (the specific type of exposed information varies from one individual to another):
1. Medical information, such as medical record numbers, dates of service, types of lab tests, or procedure codes,
2. Payment information encompassing credit card information or bank account numbers,
3. Insurance information containing Medicaid/Medicare IDs, policy numbers, or insurance claims,
4. Government identification information, including Social Security numbers, tax identification numbers, driver's license numbers, or passport numbers,
5. And other personal information, such as dates of birth or addresses.After the incident, Ascension revealed that the ransomware breach was caused by an employee who downloaded a malicious file onto a company device. However, it believes this was likely an "honest mistake," given that the employee thought they were downloading a legitimate file.
The ransomware attack impacted Ascension's MyChart electronic health records system, phones, and systems for ordering tests, procedures, and medications. It also forced the healthcare giant to take some devices offline on May 8 to contain what it initially described as a "cyber security event."
Following the incident, Ascension employees had to keep track of procedures and medications on paper, as they could no longer access patients' electronic records. The company also had to pause some non-emergent elective procedures, tests, and appointments and divert emergency medical services to other healthcare units to prevent triage delays.
While the healthcare giant has yet to link the May attack to a ransomware operation, CNN linked the Black Basta cybercrime gang to the incident (the ransomware group has yet to add Ascension to its data leak site). Days after the breach, the Health Information Sharing and Analysis Center (Health-ISAC) also warned that Black Basta "has recently accelerated attacks against the healthcare sector."
Since the operation emerged in April 2022, Black Basta has breached the networks of many high-profile victims, including German defense contractor Rheinmetall, outsourcing giant Capita, U.S. government contractor ABB, and the Toronto Public Library.
Joint research from Elliptic and Corvus Insurance shows that the ransomware gang collected over $100 million from more than 90 victims until November 2023.
Get MHF Insights
News and tips for your healthcare freedom.
We never spam you. One-step unsubscribe.






















