Two days into a cyberattack on his hospital system, Nate Couture reached the end of his cyber incident plan.
“We make these incident response plans and we feel great about them,” Couture, the University of Vermont Health Network chief information security officer, told other heath care cyber professionals at a recent conference. “At the end of them, they have a box that usually says something like, ‘And then IT recovers the systems.’”
But it would be 24 more days from where the plan ended until the Vermont health system was able to bring its electronic medical record system back online. It would be 110 days until they finished restoring software applications. And more than 200 days later, they’d still be dealing with the backlog of paper records.
This article is exclusive to STAT+ subscribers
Unlock this article — and get additional analysis of the technologies disrupting health care — by subscribing to STAT+.
Already have an account? Log in
Already have an account? Log in
To submit a correction request, please visit our Contact Us page.
STAT encourages you to share your voice. We welcome your commentary, criticism, and expertise on our subscriber-only platform, STAT+ Connect