
CommonSpirit Health ransomware attack: Questions and answers
The health system continues to deal with a cyberattack that has affected some systems and led to some patient appointments being canceled or rescheduled.
CommonSpirit Health continues to deal with
A nonprofit, Catholic health system based in Chicago, CommonSpirit operates 140 hospitals and more than 1,500 care sites in 21 states. CommonSpirit offered an
Here are some key questions on the ransomware attack.
Q: When did CommonSpirit Health report the incident?
A: CommonSpirit first reported what it described as an IT security issue on Oct. 5. CommonSpirit issued an update on Oct. 12 confirming that it is dealing with a ransomware attack.
Q: Are hospitals and clinics open?A: Yes. CommonSpirit says its facilities are serving patients, even as the system works to restore systems.
Q: Are patients being affected?
A: In an Oct. 17 update, CommonSpirit said, “There is no impact to clinic, patient care and associated systems at Dignity Health, Virginia Mason Medical Center, TriHealth or Centura Health facilities.” CommonSpirit said other parts of the system “have seen impacts on operations” and the organization is working to restore the systems.
CommonSpirit says it is working “to facilitate clinician and patient communication, document patient care, and support our caregivers in following safety processes and standards.”
Q: What is happening with patient portals?
A: Due to the cyberattack, CommonSpirit has had to take some systems offline, including patient portals. “We apologize for this inconvenience and are working diligently every day to bring systems online and restore full functionality as quickly and safely as possible,” CommonSpirit said.
Q: Are electronic health records offline?
A: CommonSpirit says it has taken electronic health records offline, along with patient portals and other systems, to deal with the breach and maintain care.
Virginia Mason Franciscan Health said in
Q: What is CommonSpirit doing to restore systems?
A: CommonSpirit crews are working to get affected systems back online. The organization has also consulted leading cybersecurity experts.
Q: Has patient information been accessed?
A: The health system said it is conducting an investigation to determine if there are any data impacts.
Health systems are required under federal law to report any breach of private health information involving 500 people or more to the U.S. Department of Health and Human Services.
Q: When will all systems be restored and the problems resolved?A: CommonSpirit has yet to provide an estimate. The system said it is working to resolve the issues and resume full operations as quickly, and safely, as possible.
Q: Has CommonSpirit notified authorities?A: Yes, the system said it has contacted law enforcement, but CommonSpirit hasn’t specified which agencies are involved and investigating.
Q: How common are cyberattacks at hospitals and health systems?
A: Hospitals across the country have been hit by cyberattacks. Two out of three healthcare IT professionals (67%) said their organizations had a significant cybersecurity incident in the past 12 months, according to the
Millions of Americans have had their records breached across America. In the first half of the year, health department data indicates there were 337 breaches involving a minimum of 500 patient records, but some of those attacks have affected hundreds of thousands of people.
Many hospitals have also had to deal with
Q: Is the MercyOne health system affected?
A: MercyOne, based in Iowa, said it has been impacted by the CommonSpirit ransomware attack.
MercyOne Central Iowa said in a








































