CSIDB logo
Incident

Frederick Regional Health System

Incident posture

Attack window
Jan 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 18:49

Linked entities

Victim
Frederick Regional Health System
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jan 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Frederick Health identified suspicious activity affecting its IT systems and confirmed it was a ransomware attack, prompting immediate containment measures and the temporary shutdown of affected systems while collaborating with third‑party cybersecurity experts and notifying law enforcement. The organization kept its facilities open, using backup processes and downtime procedures, with only the Village Laboratory closed and the emergency department continuing to accept walk‑ins and EMS transports; medical group locations remained open for appointments, though the patient portal was unavailable and prescription refills had to be requested by phone, while officials assessed whether any personal data had been compromised and pledged to notify individuals if needed.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On January 27, 2025, Frederick Health detected suspicious activity affecting its information technology systems and subsequently confirmed that the activity was ransomware. The organization immediately initiated containment measures and proactively took affected systems offline to prevent further spread. Leadership notified law enforcement and engaged third‑party cybersecurity experts to assist with investigation and recovery. A statement from President and CEO Tom Kleinhanzl on February 6, 2025, reiterated that the ransomware event was identified on January 27 and that containment actions were underway.

While systems were being secured, Frederick Health kept all of its facilities open and continued to deliver patient care by activating established backup processes and downtime procedures. The emergency department remained operational for walk‑in arrivals and all emergency medical services transports, with coordination ongoing with EMS for any necessary temporary re‑routes. The Frederick Health Hospital and its emergency department continued to accept ambulance transports. In contrast, the Frederick Health Village Laboratory was temporarily closed, while all other laboratory locations within the system stayed open. The Frederick Health Medical Group maintained normal business hours at all of its locations, although some internal systems were offline, which could cause minor disruptions to appointments and prescription refills.

Throughout the incident, Frederick Health advised patients to bring personal medical information such as medication bottles, allergy details, and recent test results to appointments when possible, and to request prescription refills by calling provider offices directly because electronic prescription functions and the patient portal were unavailable. The organization continued to work with its cybersecurity partners to evaluate whether any personal data had been compromised and pledged to notify individuals in accordance with applicable law if such data were affected. Frederick Health reported that it was making significant progress in restoring systems and processes and anticipated emerging from the event stronger and more resilient.

Sources

Sources available to members: 1 source.

CSIDB