Cyber Incident Victim: Mt. Graham Regional Medical Center
Date:
Sep 2023
Location:
United States of America
Summary
Mt. Graham Regional Medical Center experienced a ransomware attack that disrupted communication and information systems, prompting an investigation involving law enforcement and external experts to assess potential patient data compromise. The hospital activated downtime procedures to maintain patient care with minimal operational impact, successfully restoring internal system access and online patient portals while ensuring payroll and accounts payable continuity. Initial findings confirmed the medical records system remained uncompromised, though a comprehensive review of other systems for potential data exposure is ongoing, with commitments to notify affected individuals if breaches are identified. Staff efforts and redundancy measures facilitated recovery while sustaining critical healthcare services for the community.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On September 27, 2023, Mt. Graham Regional Medical Center (MGRMC) in Safford, Arizona, experienced a cybersecurity incident disrupting its communication and information systems. The 25-bed critical access hospital—serving approximately 50,000 residents across Graham and Greenlee Counties—publicly disclosed the event on September 28, initiating an investigation with law enforcement and external cybersecurity experts. Immediate measures included implementing downtime procedures to maintain clinical operations, relying on established redundancies to minimize patient care disruptions. The hospital advised current and former patients to monitor financial accounts and personal data, offering a dedicated community relations phone line for inquiries. By October 2, MGRMC reported progress in restoring system access for staff and recovering patient information, emphasizing that the outage caused limited operational impact due to contingency planning.

Subsequent updates revealed the incident as a ransomware attack, with internal systems and online patient portals fully restored by October 13. MGRMC activated its Incident Command and recovery teams, maintaining payroll and accounts payable throughout the disruption. An external forensic firm determined the electronic medical records system remained uncompromised, though broader system reviews continued to assess potential data exposure. The hospital reiterated its commitment to direct patient notification if breaches were confirmed. Recovery efforts involved extensive staff overtime, with MGRMC crediting its community-owned operational resilience for minimizing service interruptions across emergency, inpatient, and outpatient departments during the three-week restoration period. No patient data compromise had been verified as of the final public update.
