The notorious LockBit ransomware group has listed New Jersey-based healthcare provider Capital Health as a victim on its data leak site.
In November last year, Capital Health Medical Centre, a regional academic medical facility that runs two hospitals, namely the Regional Medical Centre in Trenton and the Capital Health Medical Centre in Hopewell, suffered a significant cyber attack that caused operational disruptions.
In a data security incident notification posted on its website, Capital Health
said that the cyber security incident caused network outages at all the healthcare facilities it managed. Immediately after identifying the incident, Capital Health launched an internal investigation with assistance from third party cyber security experts to understand the nature and scope of the same.
CHMC said that along with assessing the situation, safeguarding data, and working to regain system functionality, it also notified law enforcement authorities about the incident.
“Capital Health continues to make safely delivering patient care our highest priority. All Capital Health ERs remain open to those needing emergency care and our teams continue to provide the appropriate treatment for their medical condition. Both hospitals continue to admit and treat patients who need inpatient care and services.
“With our continued focus on delivering safe patient care, we made some changes to elective surgical and procedure schedules, but there is now minimal impact on surgical schedules. Outpatient radiology is currently not available, and neurophysiology and non-invasive cardiology testing will be rescheduled,” the healthcare provider said.
Capital Health added that all the “Capital Health Medical Group practices remain open for all patient visits, as do all other locations such as LIFE and CARES.”
Recently, the infamous LockBit ransomware group claimed responsibility for the cyber attack on Capital Health and listed the healthcare provider as a victim on its data leak site.
According to a screenshot shared by Brett Callow, a threat analyst at Emsisoft, the group intends to show its humane side by not encrypting the hospital’s internal network. Instead, it “just stole over 10 million files” that accounted for over 7 terabytes of medically confidential data worth $250,000.
LockBit gave Capital Health a deadline of 9th January to pay a ransom, failing which it has threatened to publish the stolen database. In an update on its website, Capital Health said that it has restored the affected systems, and all services are now available at its facilities.