CSIDB logo
Incident

REMSA Health

Incident posture

Attack window
Feb 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 17:03

Linked entities

Victim
REMSA Health
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack temporarily disrupted computer operations at REMSA Health, specifically targeting the Computer-Aided Dispatch (CAD) system that provides supplementary support to emergency medical dispatchers and telephone services. The CAD system was knocked offline, though telephone services and 9-1-1 ground ambulance and Care Flight air ambulance operations remained unaffected, with no delays or adverse impacts to patient care. Other components of the organization's operations were also not affected by the incident. The CAD system has since been restored and is back up and running.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On February 1, 2025, REMSA Health, a regional emergency medical services provider based in Reno, Nevada, disclosed that a recent cyberattack had temporarily disrupted computer operations within the organization. The incident specifically affected the agency's Computer-Aided Dispatch (CAD) system, a technology platform that provides supplementary support to emergency medical dispatchers and telephone services. According to Alexia Jobson, REMSA Health's director of public relations, the CAD system was knocked offline by the attack, creating a period during which this particular component of the agency's technological infrastructure was unavailable. The disruption was limited in scope and duration, and REMSA Health moved quickly to address the situation and restore affected services.

The most important detail emphasized by REMSA Health was that the disruption did not extend to the agency's primary 9-1-1 ground ambulance dispatch operations or to the Care Flight air ambulance system. Jobson stated that patient care for these critical emergency services was never adversely impacted and that no delays in treatment occurred at any point during the incident. The telephone services that emergency medical dispatchers rely upon were also not affected by the cyberattack, meaning that the core communications channels used to coordinate emergency response remained operational throughout the event. Other components of REMSA Health's broader operations were likewise reported as unaffected by the issue. The organization did not disclose specific details about the nature of the cyberattack, how the intrusion was detected, or whether any patient or employee data was accessed or compromised, leaving questions about the precise mechanism of the attack unanswered in the available reporting.

Following the disruption, REMSA Health reported that the CAD system had been brought back online and was fully operational again at the time of the agency's public statement. The organization characterized the event as a temporary disruption rather than a sustained outage, and the successful restoration of the CAD system indicated that REMSA's information technology team was able to respond to the incident with sufficient speed to limit downtime. While the agency did not provide a timeline for the attack, the period of disruption, or the recovery process, the public messaging centered on the assurance that emergency medical services had continued without interruption and that the affected technology had been restored to normal function. No information was provided in the available source material regarding the type of cyberattack involved, whether it was a ransomware incident, a denial-of-service event, or another form of malicious activity, nor was there any indication of whether a threat actor had been identified, whether law enforcement had been contacted, or whether any forensic investigation was underway. The single source article covering the incident focused narrowly on the operational impact and REMSA Health's reassurances about uninterrupted patient care, rather than on the technical details of the attack itself or any broader cybersecurity implications for the organization or the regional emergency services infrastructure it supports.

Sources

Sources available to members: 1 source.

CSIDB