Side View Distance (copy)

Portneuf Medical Center pictured earlier this year.

A ransomware attack has prompted a Tennessee-based health care chain that operates 30 hospitals including Portneuf Medical Center in Pocatello to divert patients from some of its emergency rooms to other hospitals while postponing certain elective procedures.

Ardent Health Services said it took its network offline after the Nov. 23 cyberattack, adding in a statement that it suspended user access to information technology applications such as software used to document patient care.

More than half of Ardent’s 25 emergency rooms have resumed accepting some patients by ambulance or by fully lifting their “divert” status, Ardent spokesperson Will Roberts said. Divert status means hospitals have asked ambulances to take people needing emergency care to other nearby facilities. Roberts said hospitals nationwide have at times used divert status during flu season, COVID-19 surges, natural disasters and large trauma events.

The company said it could not yet confirm the extent of any compromised patient health or financial information. It reported the issue to law enforcement and retained third-party forensic and threat intelligence advisers, while working with cybersecurity specialists to restore IT functions as quickly as possible. There was no immediate timeline for resolving the problems.

Based in the Nashville, Tennessee, suburb of Brentwood, Ardent owns and operates 30 hospitals and more than 200 care sites with upwards of 1,400 aligned providers in Oklahoma, Texas, New Jersey, New Mexico, Idaho and Kansas.

PMC is still dealing with the problems caused by the cyber attack and issued the following update from Ardent on Monday: “We continue to work diligently to restore systems as quickly and as safely as possible. We look forward to sharing additional progress soon. In the meantime, we continue to care for our patients in our hospitals, emergency rooms and clinics.”

PMC issued this statement on Tuesday about its emergency room: “We continue to evaluate our ability to safely care for critically ill patients in our emergency room as we work to bring hospital systems back online.”

Ardent said each hospital is still providing medical screenings and stabilizing care to patients arriving at emergency rooms.

In Amarillo, Texas, William Spell said he and his mother have had flu-like symptoms for days but couldn’t make a doctor’s appointment through an online patient portal because of the cyberattack.

“We are trying to figure out other options as to what to do next,” said Spell, 34.

BSA Health System — the Ardent umbrella provider for Spell’s clinic and other facilities in the city — said it was working to restore its patient portal and system for video doctors’ visits. Spell said his doctor’s office could not tell him how long the outage might last and recommended trying an urgent care clinic.

“That’s just something we cannot do because urgent cares charge a lot of money just to walk through the door and be seen by a doctor,” Spell said. “There’s no way we can afford that.”

Ardent says it is still seeing patients in its clinics and is contacting them if rescheduling is necessary.

Several hospitals in Albuquerque, New Mexico, within Ardent’s Lovelace Health System have continued to divert some patients needing emergency care to other hospitals, Lovelace spokesperson Whitney Marquez said. They also rescheduled elective and other non-urgent surgeries.

In Topeka, Kansas, a hospital spokesperson confirmed the attack put the University of Kansas Health System-St. Francis on divert status. Meanwhile, the city’s other hospital, Stormont Vail, said it increased weekend staffing after patient volume began growing Friday.

There was no immediate claim of responsibility for the attack. Ransomware criminals do not usually admit to an attack unless the victim refuses to pay.

“The attack against Ardent Health is both egregious and quickly becoming the norm,” said analyst Allan Liska at the cybersecurity firm Recorded Future.

While some groups won’t attack hospitals, “they are greatly outnumbered by those who will and with the number of ransomware groups growing every day, the percentage who won’t attack hospitals is constantly decreasing,” Liska said.

The Idaho State Journal contributed to this report.

Recommended for you

Welcome to the discussion!

The Idaho State Journal invites you to take part in the community conversation. But those who don't play nice may be uninvited.

Comments that are:

  • off topic
  • defamatory
  • libelous
  • obscene
  • racist
  • abusive
  • threatening
  • an invasion of privacy (doxxing)
  • profane (including attempts to misspell profanity in order to get around the profanity filter)

will be deleted. Repeat offenders will lose commenting privileges.

Comments are opinions of the author only, and do not reflect the opinions or views of Idaho State Journal.