Healthcare · United States · October 2022
CommonSpirit Health Ransomware Attack
In October 2022, a ransomware attack on CommonSpirit Health — one of the largest U.S. hospital systems — disrupted electronic health records across multiple states and reportedly carried a financial impact near US$150 million.
What happened
In early October 2022, CommonSpirit Health — one of the largest nonprofit health systems in the United States, operating well over 100 hospitals across many states — confirmed that it had been hit by a ransomware attack. For an organization of that scale, an attack is never contained to a single building; the disruption spread across facilities and regions, affecting care in multiple states at once.
CommonSpirit responded by taking systems offline as a protective measure, a standard but painful step that trades immediate availability for containment. Electronic health record systems, patient portals, and other clinical applications became unavailable at affected facilities, forcing staff back onto manual, paper-based processes for an extended period.
The organization later disclosed that the attackers had accessed portions of its network and that patient data had been affected — reported at the time as involving more than 600,000 individuals — turning an operational crisis into a data-breach event as well.
The impact
The clinical impact of losing electronic health records across a multi-state system is profound. Clinicians lost quick access to medication histories, allergies, lab results, and care plans. Reporting following the incident described appointment delays, disruption to services, and at least one lawsuit alleging that the outage contributed to a medication-dosing error affecting a pediatric patient — a stark illustration of how an IT event becomes a patient-safety event.
Financially, CommonSpirit reportedly estimated the impact of the attack at around US$150 million, encompassing lost revenue, remediation, and the costs of operating degraded for an extended period. Recovery at that scale is not measured in days; affected systems and facilities were brought back over a span of weeks.
The breach of patient data added a long tail of regulatory notification and litigation to the immediate operational damage — a reminder that in modern ransomware, the encryption is often only half the story.
How the attack unfolded
- Initial access: the precise entry point was not fully disclosed publicly, consistent with an ongoing investigation.
- Lateral movement: the attackers reached portions of a very large, multi-facility network before detection.
- Data access and exfiltration: patient information was accessed and reported affected, indicating data theft alongside disruption.
- Encryption and impact: ransomware and the protective shutdown of systems disrupted EHR and clinical applications across multiple states.
The recovery
CommonSpirit restored systems in phases across affected regions, a process that stretched over weeks as the organization worked to bring facilities back safely and verify systems before reconnecting them.
The extended timeline reflected the reality of recovering a geographically distributed health system: every facility, application, and integration has to be validated clean, and doing that carefully takes time that translates directly into disrupted care.
How this attack could have been contained
The multi-state spread of disruption is the signature of an attack that moved laterally before it was caught. Immune's containment and microsegmentation are designed to confine an intrusion to a small corner of the network, so an incident at one facility does not cascade into a system-wide EHR outage.
Because patient data was exfiltrated, the case highlights the value of catching an attacker during the quiet reconnaissance and staging phase. Immune's deception traps and network monitoring are built to raise a high-confidence signal during exactly that window, before data leaves and encryption begins.
For the weeks of EHR downtime, Immune's self-healing recovery restores validated, immutable backups in clinical order — designed to bring the electronic health record back first and fast, rather than reconstructing a distributed estate by hand.
Sources
Figures are drawn from public reporting and official disclosures and are presented as reported or estimated; they may be updated as further details become public.
Related incidents
More ransomware attacks
The February 2024 ransomware attack on Change Healthcare disrupted medical claims and payments nationwide, affecting an estimated 100 million people and becoming one of the costliest healthcare cyberattacks on record.
In May 2024, a ransomware attack on Ascension — one of the largest U.S. health systems with 140+ hospitals — forced a return to manual processes for weeks and disrupted clinical care across multiple states.
Protect against attacks like this
How to defend against healthcare ransomware
Don't let an attack become a shutdown
See how Immune detects ransomware in seconds, contains it before it spreads, and self-heals clinical systems from immutable backups.
