CommonSpirit Health, one of the largest hospital systems in the United States, took systems offline on 2 October 2022 following a ransomware attack. Reporting places initial unauthorised access on 16 September. More than 100 facilities were affected, a figure the organisation later updated to 164.
Electronic health record access was interrupted. Appointments and procedures were cancelled, postponed or rescheduled, the patient portal was suspended, and prescription processing moved to offline procedures. The personal data of more than 623,700 patients was reported exposed. The incident was subsequently reported to have cost around $160 million.
The Record Count Is Not The Harm
623,700 people had data exposed, and that is the number a breach regime records. It is not the number that describes what happened.
The harm here was to people who were not in that count at all — patients whose procedure moved, whose prescription was handled on paper, whose clinician worked without the full record in front of them. We have argued at 24-1231, 22-0224 and 22-0301 that availability harm goes uncounted because no regime asks for it, and healthcare is where the gap between the counted and the actual is widest.
Paper Is The Continuity Plan
The fallback when the record system stops is clinicians writing on paper and carrying it. That works, up to a point, and the point is reached quickly in a system of this size.
We have recorded the same design assumption at 26-0728, where critical infrastructure operators were told to plan for degraded operation rather than for prevention, and at 22-1202. Degraded-mode planning is the only realistic posture, and it is measured in how long the degraded mode holds — here, weeks.
Sixteen Days Before Anyone Noticed
Reported access on 16 September; systems taken down on 2 October. The intruders had over two weeks inside a hospital network before the effect became visible.
We have recorded at 26-0802 that a quarter of its files cannot establish an entry route at all, and no route was published here either. What is published is the dwell, and the dwell in a hospital is the interval during which patient systems were reachable by someone who had already decided to stop them.
Compiled from contemporaneous reporting and the organisation’s subsequent notifications, listed below. No ransomware operation is named — none was authoritatively attributed. Contemporaneous accounts described clinical conditions in strong terms, including anonymous posts attributed to staff; those are not carried as findings here because they are not verifiable. This desk searched for documented clinical-harm cases attributed to this incident and did not establish any, and records that rather than implying them. Graded high. Corrections: corrections@forensicpost.com.