The cybersecurity firm CrowdStrike July 24 posted online a preliminary post-incident following a non-malicious global technology outage which began July 19 and affected many industries, including health care. The outage, which was caused by an undetected error in a rapid response content configuration update to CrowdStrike鈥檚 Falcon platform, impacted millions of Microsoft computers and had varying effects on hospitals and health systems across the country. The CrowdStrike report includes an overview of the incident remediation actions and preliminary learnings. The company says it will issue a full root cause analysis report.  
 
The AHA was in touch with leaders at Microsoft and CrowdStrike immediately following the outage to urgently relay clinical and operational disruptions occurring in hospitals across the country. On July 19, AHA shared a Cybersecurity Advisory with members with initial information about the outage, as well as another Advisory on July 21 with a recovery tool from Microsoft to aid in the recovery of systems.  
 
鈥淲e are pleased and proud to report that through a massive and non-stop 鈥榓ll hands-on deck鈥 deployment of resources, hospitals and health systems rose to the occasion and have made tremendous progress in restoring mission critical systems and patient care services,鈥 said John Riggi, AHA鈥檚 national advisor for cybersecurity and risk. 鈥淭hrough a combination of manual restoration of millions of computers by hospitals and special updates provided by Microsoft and CrowdStrike, the restoration process has greatly accelerated. Some effects, although diminished, still continue 鈥 and the true impact to hospitals and health systems may not be known for weeks. We continue to work closely with Microsoft and CrowdStrike leadership to assist in focused efforts for restoration. We also acknowledge and appreciate CrowdStrike鈥檚 prioritization to assist hospitals for recovery, in the interest of public health and safety.鈥

Related News Articles

Headline
The National Security Agency April 23 released a report on operational technology systems that includes recommendations for security policies and technical鈥
Chairperson's File
Public
Cybersecurity and physical threats are unfortunately significant enterprise risks for health care, regardless of size or location. Every hospital, physician鈥
Headline
The Cybersecurity and Infrastructure Security Agency April 17 released guidance to reduce risks associated with a reported breach of Oracle cloud services.鈥
Headline
The National Counterintelligence and Security Center, the FBI, and the Defense Counterintelligence and Security Center yesterday released guidance on鈥
AHA Cyber Intel
While the rate of cyberattacks on hospitals has risen dramatically, the severity of the impacts has also grown exponentially. Let鈥檚 look at the state of cyber鈥
Headline
The House Energy and Commerce Oversight and Investigations Subcommittee April 1 discussed cybersecurity threats in legacy medical devices during a hearing. The鈥