Cyber Incident Victim: Evangelisches Krankenhaus Lippstadt
Date:
Mar 2021
Location:
Germany
Summary
A cyberattack using external malware disrupted the entire IT infrastructure of Evangelical Hospital in Lippstadt, forcing an immediate halt to patient admissions except for severe emergencies, obstetrics, and maternity cases. Elective procedures and planned inpatient stays were canceled, with affected patients redirected to neighboring facilities or instructed to contact secretariats by phone. Emergency care for life-threatening conditions continued, while other acute patients were diverted elsewhere. Current inpatients and expectant mothers received uninterrupted care. The hospital collaborated with law enforcement and external specialists to resolve the incident, filed criminal charges, and restricted communications to phone-only during the outage.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 3 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On March 30, 2021, the Evangelical Hospital in Lippstadt (EVK) experienced a disruptive cyberattack involving external malware that compromised its entire IT infrastructure. The attack was detected in the morning, prompting immediate system shutdowns to contain further damage. Critical patient documentation systems were rendered inoperable, forcing the hospital to implement a near-total admission freeze. Only severe emergency cases, active obstetrics patients, maternity ward admissions, and premature infant care remained operational. All elective surgeries and planned inpatient stays were canceled indefinitely, with affected patients instructed to reschedule via telephone through department secretariats starting the following day. Emergency patients with life-threatening conditions received initial stabilization in the EVK emergency room before being transferred to other facilities, while non-critical acute cases were redirected to Trinity Hospital or neighboring institutions. The hospital’s phone systems remained functional, but email communications were completely disabled throughout the incident.

Patient care for existing inpatients continued without interruption, and obstetric services for active deliveries or pregnancy complications were maintained. The hospital coordinated with regional emergency medical services and nearby healthcare facilities to manage patient diversions. EVK administrators filed criminal charges with local police and engaged both law enforcement and external cybersecurity specialists to investigate the attack and restore systems. Operational disruptions persisted indefinitely as recovery efforts continued, with no public attribution or confirmed motive for the attack provided in initial statements. The incident caused significant service limitations across all hospital departments except specified critical care units, demonstrating broad impacts on clinical operations and community healthcare access.
