Immune — Self Heal, an iStudio Technologies product

Healthcare · United States · October 2022

CommonSpirit Health Ransomware Attack

In October 2022, a ransomware attack on CommonSpirit Health — one of the largest U.S. hospital systems — disrupted electronic health records across multiple states and reportedly carried a financial impact near US$150 million.

What happened

In early October 2022, CommonSpirit Health — one of the largest nonprofit health systems in the United States, operating well over 100 hospitals across many states — confirmed that it had been hit by a ransomware attack. For an organization of that scale, an attack is never contained to a single building; the disruption spread across facilities and regions, affecting care in multiple states at once.

CommonSpirit responded by taking systems offline as a protective measure, a standard but painful step that trades immediate availability for containment. Electronic health record systems, patient portals, and other clinical applications became unavailable at affected facilities, forcing staff back onto manual, paper-based processes for an extended period.

The organization later disclosed that the attackers had accessed portions of its network and that patient data had been affected — reported at the time as involving more than 600,000 individuals — turning an operational crisis into a data-breach event as well.

The impact

The clinical impact of losing electronic health records across a multi-state system is profound. Clinicians lost quick access to medication histories, allergies, lab results, and care plans. Reporting following the incident described appointment delays, disruption to services, and at least one lawsuit alleging that the outage contributed to a medication-dosing error affecting a pediatric patient — a stark illustration of how an IT event becomes a patient-safety event.

Financially, CommonSpirit reportedly estimated the impact of the attack at around US$150 million, encompassing lost revenue, remediation, and the costs of operating degraded for an extended period. Recovery at that scale is not measured in days; affected systems and facilities were brought back over a span of weeks.

The breach of patient data added a long tail of regulatory notification and litigation to the immediate operational damage — a reminder that in modern ransomware, the encryption is often only half the story.

How the attack unfolded

  • Initial access: the precise entry point was not fully disclosed publicly, consistent with an ongoing investigation.
  • Lateral movement: the attackers reached portions of a very large, multi-facility network before detection.
  • Data access and exfiltration: patient information was accessed and reported affected, indicating data theft alongside disruption.
  • Encryption and impact: ransomware and the protective shutdown of systems disrupted EHR and clinical applications across multiple states.

The recovery

CommonSpirit restored systems in phases across affected regions, a process that stretched over weeks as the organization worked to bring facilities back safely and verify systems before reconnecting them.

The extended timeline reflected the reality of recovering a geographically distributed health system: every facility, application, and integration has to be validated clean, and doing that carefully takes time that translates directly into disrupted care.

How this attack could have been contained

The multi-state spread of disruption is the signature of an attack that moved laterally before it was caught. Immune's containment and microsegmentation are designed to confine an intrusion to a small corner of the network, so an incident at one facility does not cascade into a system-wide EHR outage.

Because patient data was exfiltrated, the case highlights the value of catching an attacker during the quiet reconnaissance and staging phase. Immune's deception traps and network monitoring are built to raise a high-confidence signal during exactly that window, before data leaves and encryption begins.

For the weeks of EHR downtime, Immune's self-healing recovery restores validated, immutable backups in clinical order — designed to bring the electronic health record back first and fast, rather than reconstructing a distributed estate by hand.

Sources

Figures are drawn from public reporting and official disclosures and are presented as reported or estimated; they may be updated as further details become public.

Protect against attacks like this

How to defend against healthcare ransomware

Don't let an attack become a shutdown

See how Immune detects ransomware in seconds, contains it before it spreads, and self-heals clinical systems from immutable backups.

Talk to us

See Immune protect your organization

Tell us about your environment and our team will show you exactly how Immune detects, contains, and self-heals through a ransomware attack — including the connected devices your current tools can't reach. We respond within one business day.

  • A working demo on a realistic scenario
  • Agentless coverage for medical and connected devices
  • On-premises and data-sovereignty deployment options
  • A frank look at where Immune fits alongside your stack

Request your demo

Tell us a little about your organization and we'll be in touch.

By submitting, you agree to be contacted about Immune. We respect your privacy and never share your details. See our privacy policy.