McLaren Health Care Hit by Ransomware Attack, Disrupting Non-Emergency Care Across Michigan
On August 7, McLaren Health Care a 13-hospital system serving Michigan disclosed a cyberattack that forced the postponement of non-emergency care services. By August 16, the organization confirmed the incident was a ransomware attack, with ongoing disruptions affecting its network of 113 hospitals, surgery centers, oncology facilities, and clinics.
McLaren expects system outages to persist through the end of August as cyber forensic investigations continue. While the health system is assessing whether hackers accessed HIPAA-protected patient data, no ransomware group has claimed responsibility, and no stolen data has surfaced on the dark web.
Due to limited access to electronic health records, McLaren has advised patients to bring their own medical records including prescriptions and lab results to appointments. The full scope of the breach remains under investigation.
McLaren Health Care cybersecurity rating report: https://www.rankiteo.com/company/mclaren-health-care
"id": "MCL1787322898",
"linkid": "mclaren-health-care",
"type": "Ransomware",
"date": "8/2024",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'Patients requiring '
'non-emergency care',
'industry': 'Healthcare',
'location': 'Michigan, USA',
'name': 'McLaren Health Care',
'size': '13 hospitals, 113 facilities (including '
'surgery centers, oncology facilities, and '
'clinics)',
'type': 'Healthcare System'}],
'customer_advisories': 'Patients advised to bring their own medical records '
'to appointments',
'data_breach': {'data_exfiltration': 'Under investigation',
'personally_identifiable_information': 'Likely (patient '
'records)',
'sensitivity_of_data': 'High (health records)',
'type_of_data_compromised': 'HIPAA-protected patient data '
'(under assessment)'},
'date_detected': '2024-08-07',
'date_publicly_disclosed': '2024-08-07',
'description': 'McLaren Health Care, a 13-hospital system serving Michigan, '
'disclosed a cyberattack that forced the postponement of '
'non-emergency care services. The incident was later confirmed '
'as a ransomware attack, causing ongoing disruptions across '
'its network of hospitals, surgery centers, oncology '
'facilities, and clinics. System outages are expected to '
'persist through the end of August while cyber forensic '
'investigations continue. The health system is assessing '
'whether hackers accessed HIPAA-protected patient data, though '
'no ransomware group has claimed responsibility and no stolen '
'data has surfaced on the dark web.',
'impact': {'data_compromised': 'HIPAA-protected patient data (under '
'assessment)',
'downtime': 'Expected through end of August 2024',
'operational_impact': 'Postponement of non-emergency care '
'services, limited access to medical records',
'systems_affected': 'Electronic health records, network systems'},
'initial_access_broker': {'data_sold_on_dark_web': 'No evidence of data '
'surfacing on dark web'},
'investigation_status': 'Ongoing',
'ransomware': {'data_exfiltration': 'Under investigation'},
'references': [{'date_accessed': '2024-08-16',
'source': 'Cyber incident disclosure'}],
'regulatory_compliance': {'regulations_violated': 'Potential HIPAA violations '
'(under assessment)'},
'response': {'communication_strategy': 'Advising patients to bring their own '
'medical records to appointments',
'third_party_assistance': 'Cyber forensic investigations'},
'title': 'McLaren Health Care Ransomware Attack',
'type': 'Ransomware'}