Cyber Incident Victim: REMSA Health
Date:
Feb 2025
Location:
United States of America
Summary
A cyberattack temporarily disrupted computer operations at REMSA Health, specifically impacting its Computer-Aided Dispatch system used for supplementary support of emergency medical dispatchers. While the CAD system was affected, core telephone services and dispatcher functions remained operational, ensuring no delays or adverse impacts to patient care for 911 ground ambulance or air ambulance services. The organization confirmed other operational components were unaffected, and the compromised system was subsequently restored to normal functionality.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
A cyberattack disrupted computer operations at REMSA Health in early February 2025, temporarily affecting the organization's Computer-Aided Dispatch (CAD) system. The CAD system provides supplementary support to emergency medical dispatchers but does not directly handle telephone services or primary dispatch functions. REMSA Health confirmed the disruption occurred but emphasized that core emergency response capabilities remained fully operational throughout the incident. Specifically, the 9-1-1 ground ambulance services and Care Flight air ambulance operations maintained normal response times and patient care standards without delays. Alexia Jobson, REMSA Health's Director of Public Relations, stated that no other components of their operations were compromised by the cyber incident. The attack exclusively targeted the CAD infrastructure, which assists dispatchers with secondary functions rather than direct emergency communication channels. REMSA Health did not observe any impact on patient care delivery or emergency response coordination during the outage. The organization's public statements focused on maintaining service continuity despite the technical disruption.

REMSA Health restored the CAD system following the cyberattack, though the timeline for full recovery and specific remediation steps were not publicly disclosed. The organization reiterated that critical systems remained isolated from the affected CAD environment, preventing cascading failures across their network. No data breaches or unauthorized access to medical records were reported in connection with the incident. REMSA Health's communications highlighted the containment of operational impacts to non-critical dispatch support systems while preserving uninterrupted emergency medical services. The restored CAD system resumed normal function after remediation, with no mention of ongoing disruptions or residual effects following recovery. Agency representatives confirmed all services were operating at standard capacity post-restoration without elaborating on long-term consequences or additional security measures implemented.
