Colombian healthcare provider Keralty suffered a ransomware attack that affected IT operations, websites, scheduling of medical appointments, and other daily operations.As one of Colombia’s leading healthcare providers, Keralty operates an international network of 12 hospitals and 371 medical centres in Latin America, the US, Spain, and Asia along with its subsidiaries, Colsanitas, Sanitas USA, and EPS Sanitas.Recently, Keralty reported a ransomware attack that affected its internal systems as well as those of its subsidiaries: EPS Sanitas and Colsanitas. Keralty confirmed that the ransomware attack crippled its IT operations, websites, scheduling of medical appointments, and other daily operations.According to local media, patients had to wait for more than 12 hours to receive medical treatment and some even lost consciousness due to a lack of medical attention.In an auto-translated statement, Keralty said, “The computer servers of the Keralty Group companies have been the object of a cyberattack, which has generated technical failures in our systems. From the moment it was identified, we have been working 24 hours a day, both from the technical team and from the medical and administrative team, to provide continuity of care to our members.“Likewise, from the beginning, this situation was brought to the attention of the competent authorities and the respective criminal investigation has been initiated. In order to maintain attention to our users, from Keralty We continue to implement the necessary contingency plans to maintain the service.”While the healthcare provider did not confirm who was behind the ransomware attack, a Twitter user posted a screenshot of the malware that reportedly affected Keralty’s systems, suggesting that the ransomware attack was carried out by the RansomHouse gang.This is the same ransomware group that breached eight Italian districts in July and encrypted its internal network. The gang also targeted semiconductor company AMD in January and stole up to 450 GB of business-sensitive data.Commenting on the ransomware attack targeting Keralty, Simon Chassar, Chief Revenue Officer at Claroty, said, “The disruption of IT systems caused by the RansomHouse ransomware group against Keralty’s Colombian hospitals is further evidence to show the continued rise in attacks on the healthcare industry and the dangerous impacts it can have on patient care and business availability.“Ransomware attacks on IT operations can create a devastating, and sometimes fatal, impact on patient care, seen here with waiting times extending over 12 hours causing some patients to faint due to a lack of medical attention.“While unconfirmed whether cyber-physical systems were hit in this attack, threat actors know they can affect patient services by hitting these systems. Healthcare systems operate as converged ‘flat’ networks with IT and OT (operational technology) systems, as well as Internet of Medical Things (IoMT) all communicating on the same network; this exposes healthcare organisations to new cyber threats and vulnerabilities, which can impact patient care severely.“Organisations urgently need to protect their business availability and network systems so that ransomware attacks are not the downfall of patient care. Healthcare providers must update procedures for OT systems, IoT, and IoMT devices, and implement network segmentation with asset class network segmentation policies to alleviate the impacts of ransomware attacks,” Chassar added.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543