Cyber Incident Victim: Lawrence General Hospital
Date:
Sep 2020
Location:
United States of America
Summary
A Massachusetts hospital experienced a disruptive cybersecurity incident requiring systems to be taken offline for approximately 36 hours to secure data, prompting ambulance diversions to other facilities while walk-in emergency patients continued receiving care. Staff maintained operations through manual documentation, phone communications, and in-person coordination, implementing established downtime protocols typically reserved for planned maintenance. Clinical systems were restored following the incident, allowing normal patient care activities to resume.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
Lawrence General Hospital experienced a disruptive cybersecurity incident beginning on September 19, 2020, prompting an immediate operational response. The hospital took all systems offline for approximately 36 hours as a precautionary measure to secure data, activating established downtime procedures typically reserved for planned maintenance or emergencies. This system shutdown necessitated the diversion of ambulance traffic to other regional emergency centers during the outage period, though walk-in patients continued to receive care at the facility. Clinical staff maintained patient care operations through manual documentation methods, including handwritten medical forms, while relying on verbal communication via telephone and in-person meetings to coordinate treatment. Hospital leadership notified surrounding medical facilities and emergency responders about the activation of downtime protocols to facilitate coordinated ambulance rerouting.

The incident investigation remained ongoing as of October 1, 2020, with hospital officials working to determine the precise nature and scope of the security event. No specific details regarding potential data compromise or attacker methodology were disclosed in initial reports. Major clinical systems were restored to operational status following the 36-hour outage period, allowing the hospital to resume normal patient care activities. The response highlighted the implementation of pre-existing contingency plans designed for system disruptions, with the hospital spokesperson emphasizing that similar protocols were routinely employed during scheduled maintenance events. No further information was provided regarding long-term operational impacts, forensic findings, or potential data exposure resulting from the incident.
