Ransomware Attack Disrupts Critical Services for 100+ Nursing Home Providers
A ransomware attack on Virtual Care Provider Inc. (VCPI), a Milwaukee-based technology firm, has severely disrupted operations for over 110 nursing home and long-term care organizations across 45 states. The attack, detected on November 18, encrypted servers and cut off access to patient medical records, internet services, payroll systems, and medication ordering for facilities relying on VCPI’s cloud hosting and security services.
Hackers deployed Ryuk ransomware, spread via the TrickBot virus, and demanded a $14 million Bitcoin ransom. VCPI estimates 20% of its servers were compromised, affecting 80,000 computers used by its clients. The company has engaged a third-party cybersecurity firm to assist with recovery, prioritizing systems for electronic health records (EHR), email, and active directory access.
VCPI president Zachary Koch confirmed the attack as a "highly sophisticated" incident, stating the company is working to restore operations while enhancing security measures. CEO Karen Christianson warned of life-threatening risks for patients if critical data remains inaccessible, noting that some facilities may face closure if billing systems aren’t restored in time. One small assisted living facility risks shutting down by December 5 if Medicaid billing isn’t processed.
The attack mirrors recent Ryuk ransomware incidents targeting healthcare providers, including a French hospital forced to revert to manual record-keeping and an Alabama health system that paid hackers for decryption keys. Cybersecurity experts attribute the attacks to unpatched vulnerabilities like EternalBlue and BlueKeep, emphasizing that many victims fail to implement basic security updates.
VCPI has stated it cannot afford the ransom demand, leaving affected facilities to navigate prolonged disruptions in care and administrative functions. The investigation remains ongoing.
vcpi, a DAS Health Company cybersecurity rating report: https://www.rankiteo.com/company/vcpi
"id": "VCP1781271884",
"linkid": "vcpi",
"type": "Ransomware",
"date": "11/2019",
"severity": "100",
"impact": "7",
"explanation": "Attack that could injure or kill people"
{'affected_entities': [{'customers_affected': '110+ nursing home and long-term '
'care organizations',
'industry': 'Healthcare IT',
'location': 'Milwaukee, Wisconsin, USA',
'name': 'Virtual Care Provider Inc. (VCPI)',
'type': 'Technology firm'}],
'attack_vector': 'TrickBot virus',
'data_breach': {'data_encryption': 'Yes (Ryuk ransomware)',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High (health records, personally '
'identifiable information)',
'type_of_data_compromised': 'Patient medical records, payroll '
'data, medication ordering data'},
'date_detected': '2019-11-18',
'description': 'A ransomware attack on Virtual Care Provider Inc. (VCPI), a '
'Milwaukee-based technology firm, severely disrupted '
'operations for over 110 nursing home and long-term care '
'organizations across 45 states. The attack encrypted servers '
'and cut off access to patient medical records, internet '
'services, payroll systems, and medication ordering for '
'facilities relying on VCPI’s cloud hosting and security '
'services.',
'impact': {'brand_reputation_impact': 'Severe',
'data_compromised': 'Patient medical records, payroll systems, '
'medication ordering data',
'identity_theft_risk': 'High (patient data exposed)',
'operational_impact': 'Disrupted operations for 110+ nursing home '
'and long-term care organizations; potential '
'facility closures',
'systems_affected': 'Servers, electronic health records (EHR), '
'email, active directory access, billing '
'systems'},
'investigation_status': 'Ongoing',
'lessons_learned': 'Failure to implement basic security updates and patch '
'vulnerabilities like EternalBlue and BlueKeep can lead to '
'severe disruptions and life-threatening risks for '
'healthcare providers.',
'motivation': 'Financial gain',
'post_incident_analysis': {'corrective_actions': 'Restoring systems, '
'enhancing security '
'measures, prioritizing '
'critical data access',
'root_causes': 'Unpatched vulnerabilities '
'(EternalBlue, BlueKeep), lack of '
'basic security updates'},
'ransomware': {'data_encryption': 'Yes',
'ransom_demanded': '$14 million (Bitcoin)',
'ransom_paid': 'No',
'ransomware_strain': 'Ryuk'},
'recommendations': 'Implement regular security updates, enhance monitoring, '
'and prioritize patch management to prevent ransomware '
'attacks.',
'references': [{'source': 'Cyber incident report'}],
'response': {'recovery_measures': 'Restoring operations and enhancing '
'security measures',
'remediation_measures': 'Prioritizing restoration of EHR, email, '
'and active directory access',
'third_party_assistance': 'Engaged a third-party cybersecurity '
'firm'},
'title': 'Ransomware Attack Disrupts Critical Services for 100+ Nursing Home '
'Providers',
'type': 'Ransomware',
'vulnerability_exploited': ['EternalBlue', 'BlueKeep']}