RSC and Carol Davila Hospital: How 100 Romanian hospitals switched to pen and paper to defeat a national cyber-attack

RSC and Carol Davila Hospital: How 100 Romanian hospitals switched to pen and paper to defeat a national cyber-attack

Romanian Hospitals Hit by Massive Ransomware Attack, Forcing Return to Pen and Paper

On 10 February 2024, a ransomware attack crippled 100 hospitals across Romania, disrupting critical medical systems and forcing staff to revert to pen-and-paper record-keeping. The attack targeted Hippocrates, a widely used medical software system developed by Bucharest-based firm RSC, which manages patient records, lab results, pharmacy logistics, and payroll.

The BackMyData ransomware strain encrypted files, rendering them unusable, and demanded a €160,000 (£138,000) bitcoin ransom. Hospitals reported the first signs of infection on Sunday morning, with Pitești Children’s Hospital among the earliest affected. Surgeon Oana Goidescu, on shift at Buzău Hospital, described the chaos: "All lab tests, radiology requests, and medication records were gone it wasn’t just a list of patients."

With systems offline, IT teams and the National Cyber Security Directorate (DNSC) scrambled to contain the breach. Authorities issued an emergency order to disconnect hospitals from the internet, halting the malware’s spread. Cybersecurity firm Bitdefender noted that hospitals are prime targets for ransomware gangs due to their critical services and high-pressure environments, increasing the likelihood of payment.

Despite the disruption, no deaths or serious patient harm were reported. Staff at Carol Davila Hospital in Bucharest developed offline workarounds, including Excel spreadsheets and paper records, to maintain care. Vlad Paic, a hospital representative, credited Romania’s recent digital transition for easing the shift back to analog methods.

By 15 February, most hospitals had restored systems from backups and resumed near-normal operations, though some data was permanently lost. The DNSC refused to pay the ransom, a decision praised by cybersecurity experts. Dan Cimpean, head of Romania’s Cyber-Security Directorate, emphasized the growing risks of digital dependency, stating, "The more technology you have, the greater the risk."

The attack mirrored global trends, including a $22 million ransom payment by U.S. firm Change Healthcare in a separate incident. While Romanian authorities have not identified the attackers, four Russians were later arrested outside Russia in connection with other healthcare cybercrimes. The FBI has since declared healthcare the most targeted sector in critical infrastructure.

The response rapid containment, media coordination, and backup reliance has become a case study for disaster planners worldwide. However, the incident underscored vulnerabilities in medical software supply chains, with experts warning that such attacks are increasing in frequency and severity.

Source: https://www.bbc.com/news/articles/c4gyk756mzlo

Victor Babes Hospital Bucharest cybersecurity rating report: https://www.rankiteo.com/company/victor-babes-hospital-bucharest

RSC cybersecurity rating report: https://www.rankiteo.com/company/rsc

"id": "VICRSC1782196273",
"linkid": "victor-babes-hospital-bucharest, rsc",
"type": "Ransomware",
"date": "2/2024",
"severity": "100",
"impact": "7",
"explanation": "Attack that could injure or kill people"
{'affected_entities': [{'industry': 'healthcare',
                        'location': 'Romania',
                        'name': 'Pitești Children’s Hospital',
                        'type': 'hospital'},
                       {'industry': 'healthcare',
                        'location': 'Romania',
                        'name': 'Buzău Hospital',
                        'type': 'hospital'},
                       {'industry': 'healthcare',
                        'location': 'Bucharest, Romania',
                        'name': 'Carol Davila Hospital',
                        'type': 'hospital'},
                       {'customers_affected': '100 hospitals',
                        'industry': 'healthcare IT',
                        'location': 'Bucharest, Romania',
                        'name': 'RSC (Hippocrates software developer)',
                        'type': 'software company'}],
 'customer_advisories': 'Hospitals advised patients about potential delays and '
                        'data risks due to the attack.',
 'data_breach': {'data_encryption': 'yes (ransomware encryption)',
                 'personally_identifiable_information': 'yes',
                 'sensitivity_of_data': 'high',
                 'type_of_data_compromised': 'patient records, lab results, '
                                             'pharmacy logistics, payroll'},
 'date_detected': '2024-02-10',
 'date_publicly_disclosed': '2024-02-10',
 'date_resolved': '2024-02-15',
 'description': 'On 10 February 2024, a ransomware attack crippled 100 '
                'hospitals across Romania, disrupting critical medical systems '
                'and forcing staff to revert to pen-and-paper record-keeping. '
                'The attack targeted Hippocrates, a widely used medical '
                'software system developed by Bucharest-based firm RSC, which '
                'manages patient records, lab results, pharmacy logistics, and '
                'payroll. The BackMyData ransomware strain encrypted files, '
                'rendering them unusable, and demanded a €160,000 (£138,000) '
                'bitcoin ransom.',
 'impact': {'brand_reputation_impact': 'significant',
            'data_compromised': 'patient records, lab results, pharmacy '
                                'logistics, payroll',
            'downtime': '5 days',
            'identity_theft_risk': 'high',
            'operational_impact': 'forced return to pen-and-paper '
                                  'record-keeping, disrupted medical services',
            'systems_affected': 'Hippocrates medical software system'},
 'investigation_status': 'ongoing',
 'lessons_learned': 'The incident underscored vulnerabilities in medical '
                    'software supply chains and the growing risks of digital '
                    'dependency in critical infrastructure. The response '
                    'highlighted the importance of rapid containment, media '
                    'coordination, and backup reliance.',
 'motivation': 'financial gain',
 'post_incident_analysis': {'corrective_actions': 'Improved backup strategies, '
                                                  'enhanced monitoring, and '
                                                  'development of offline '
                                                  'workarounds for critical '
                                                  'services',
                            'root_causes': 'Vulnerabilities in medical '
                                           'software supply chains, lack of '
                                           'robust cybersecurity measures in '
                                           'healthcare IT systems'},
 'ransomware': {'data_encryption': 'yes',
                'ransom_demanded': '€160,000 (£138,000) in bitcoin',
                'ransom_paid': 'no',
                'ransomware_strain': 'BackMyData'},
 'recommendations': 'Enhance cybersecurity measures for healthcare IT systems, '
                    'improve supply chain security, and develop robust offline '
                    'workarounds for critical services.',
 'references': [{'date_accessed': '2024-02-15',
                 'source': 'Cybersecurity news reports'}],
 'response': {'communication_strategy': 'media coordination',
              'containment_measures': 'disconnected hospitals from the '
                                      'internet, emergency order to halt '
                                      'malware spread',
              'incident_response_plan_activated': 'yes',
              'recovery_measures': 'offline workarounds (Excel spreadsheets, '
                                   'paper records)',
              'remediation_measures': 'restored systems from backups',
              'third_party_assistance': 'Bitdefender, National Cyber Security '
                                        'Directorate (DNSC)'},
 'stakeholder_advisories': 'Authorities warned about the increasing frequency '
                           'and severity of ransomware attacks on healthcare '
                           'institutions.',
 'title': 'Romanian Hospitals Hit by Massive Ransomware Attack, Forcing Return '
          'to Pen and Paper',
 'type': 'ransomware'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.