Ransomware attack on UMMC causes 20% drop in revenue due to delayed patient care
As a result of a February ransomware attack that shut down non-emergency operations for more than a week, University of Mississippi Medical Center (UMMC) saw a 20% drop in revenue for the month, budget reports show.
Mississippi Today was the first to report the news. According to their coverage, UMMC fell $34.2 million short of its budget estimates, likely the result of the health system shutting down its clinics and postponing elective surgeries as it moved to pen-and-paper backups during what was confirmed to be a ransomware attack.
Notably, UMMC said it’s still working to merge paper records with its electronic systems—some of which contain payment information and are expected to bring revenue numbers up a bit.
During the cyberattack, UMMC was forced to shut down all of its clinics in the state, including those for all primary and specialty care services.
According to Mississippi Today, 650 elective surgeries were delayed during the nine days of downtime, and UMMC is still attempting to address the backlog. Many have been rescheduled, the hospital CFO told the outlet.
Operating hours at the clinics have been temporarily extended to increase the number of patients that can be seen per day. Operating room hours, too, have been extended.
For more, including interviews with UMMC executives, read Mississippi Today’s full coverage by clicking here.
Data dump hits dark web
The cyberattack on UMMC’s network, which was confirmed in a Facebook post by the organization to involve the deployment of ransomware, left it without email and phone lines, as systems were shut down to stop the spread.
Staff were also unable to access the electronic health record. Still, it wasn’t clear if hackers were able to gain access to sensitive patient data or any data at all on UMMC servers.
Last week, however, an infamous ransomware gang called Medusa took credit for the attack, posting on their dark web blog an ad for a data trove said to be from the academic health system. It posted screenshots seeming to prove it had the goods, though it’s not clear how large the data trove was or specifically what it contained.
The hackers offered up the trove to the highest bidder for $800,000—or UMMC could pay to have it deleted for the same price. A deadline was set for March 20, at which time, presumably, the information would either be auctioned off on the black market or released on the dark web openly, as is common with these types of data breaches.
Medusa is a big player in the cybercrime arena. In less than two years, it’s been linked to more than 200 cyberattacks, impacting a variety of industries and the public sector.
UMMC has not confirmed the data trove is real and did not respond to HealthExec’s requests for comment.
