Menu
Browse

Cyber Incident Victim: Aprima

Date:

Apr 2021

Location:

United States of America

Summary

A ransomware attack compromised MedNetwoRX, a data center partner supporting CompuGroup Medical's Aprima electronic health record platform, causing prolonged system outages for hosted clients. The incident disrupted EHR access for over two weeks, with service restoration still pending for some customers, following the attackers' compromise of the vendor's primary systems, disaster recovery site, and backup infrastructure.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

A ransomware attack targeting MedNetwoRX, a data center partner of CompuGroup Medical, disrupted access to Aprima electronic health record (EHR) systems for multiple customers beginning on April 22, 2021. The incident caused extended service outages affecting hosted Aprima clients, with some remaining without access for over two weeks. CompuGroup Medical acknowledged the attack in an April 27 email to customers signed by CEO Derek Pickell, attributing the incident to a "sophisticated criminal organization" that compromised the hosting vendor's infrastructure. The attackers executed a coordinated strike against primary systems, disaster recovery infrastructure, and backup repositories, significantly impeding restoration efforts. This multi-faceted compromise left affected healthcare providers unable to access critical patient records through the Aprima platform during the initial attack phase.

Cyber Incident Image

The sustained disruption impacted operations for an unspecified number of healthcare organizations relying on the hosted EHR service, with restoration efforts still ongoing when reported on April 30. Attackers deliberately targeted MedNetwoRX's redundant systems and backup storage, eliminating conventional recovery options and prolonging downtime. CompuGroup Medical's communications confirmed the ransomware's comprehensive impact on their partner's technical environment without specifying whether data exfiltration occurred. Service restoration proceeded incrementally, with some clients regaining access before others, though the complete remediation timeline extended beyond the two-week mark. The incident demonstrated the operational vulnerabilities inherent in third-party hosting arrangements when critical infrastructure components face simultaneous compromise.

Sources
Sources available to members
1 source