A cyberattack took many of Signature Healthcare’s electronic systems offline on 6 April 2026. The Brockton, Massachusetts hospital diverted ambulances to other facilities, took electronic health records and its patient portal offline, and could not fill prescriptions at its retail pharmacies. Chemotherapy infusion services were cancelled. Surgeries and procedures were reported as continuing.
Files containing names and protected health information were reported stolen. Staff worked on paper, and the hospital indicated downtime procedures would continue for roughly two weeks.
Cancelled Infusions Are The Sentence To Sit With
Most healthcare ransomware coverage, including a good deal of ours, discusses record counts and notification obligations. This file contains a different category of harm.
Chemotherapy is scheduled against a protocol. Delays are sometimes clinically tolerable and sometimes not, and the decision requires the patient’s records — which were offline. The people affected experienced this as a phone call telling them not to come in.
Diversion Moves The Load, It Does Not Remove It
Ambulance diversion works by sending patients to neighbouring facilities, which absorb the additional volume alongside their own. It is the correct decision and it is not free: journey times lengthen, and receiving hospitals operate above plan for the duration.
This desk filed the limit case at Hospital Caribbean Medical Center in 26-0218 — where the assumption that there is somewhere to divert to does not hold. A Massachusetts hospital has neighbours. A regional one may not.
Two Weeks Is The Number That Should Inform Planning
Downtime procedures for a fortnight is far beyond what most tabletop exercises rehearse. A day of paper is manageable. Two weeks means paper records accumulate that must later be reconciled into the electronic record, and the reconciliation itself introduces clinical risk.
The published estimate of around $900,000 per day in US healthcare downtime cost, filed at 26-0304, gives a sense of the financial scale over that period — before any consideration of the clinical consequences.
Compiled from public reporting, listed below. A ransomware group is reported to have claimed the attack and later withdrawn the claim; we do not treat that as attribution. We have not reviewed clinical records or outcomes and are not asserting patient harm. Corrections: corrections@forensicpost.com.