CSIDB logo
Incident

Allscripts

Incident posture

Attack window
Jan 2018
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-09-27 01:29

Linked entities

Victim
Allscripts
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Nov 2017
Discovered
Undetermined
Disclosed
Jan 2018
Resolved
Pending

Summary

Allscripts experienced a ransomware attack that disabled several applications hosted in its Raleigh and Charlotte data centers, including the Professional EHR platform and its electronic prescribing of controlled substances service. Additional impacted functions comprised InfoButton, regulatory reporting, clinical decision support, direct messaging and Payerpath. The company stated it was working to restore the systems from backups and had found no evidence that client data had been exfiltrated. An investigation was ongoing while services remained unavailable.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

As of August 4, 2017, hackers had been responsible for 75 healthcare breaches, and in November 2017 a ransomware attack disrupted North Carolina’s healthcare system. On January 18, 2018, Allscripts reported that a ransomware attack had taken down some of the applications hosted in its Raleigh and Charlotte, North Carolina data centers. The company stated that its Allscripts Professional EHR was unavailable to customers whose instances were hosted in those facilities. Additionally, instances of its electronic prescribing of controlled substances system were also affected.

Beyond the core EHR and e‑prescribing services, users reported that other functions such as InfoButton, regulatory reporting, clinical decision support, direct messaging, and Payerpath had been down since the morning of the incident. Allscripts indicated that it expected to restore the impacted systems quickly from backups. The company had not posted any acknowledgment of the outage on its website or social media channels. An Allscripts media contact provided a statement saying the firm was investigating a ransomware incident that had impacted a limited number of its applications. The contact added that Allscripts was working diligently to restore the systems and to ensure client data remained protected.

The statement further noted that, although the investigation was ongoing, there was currently no evidence that any data had been removed from the systems. Allscripts expressed regret for the inconvenience caused by the temporary outage. The article concludes with the observation that the company had not publicly acknowledged the downtime beyond the media contact’s statement.

Sources

Sources available to members: 1 source.

CSIDB