Full Report
Dysruption Hub reports what sounds like a very serious cyberattack affecting the University of Mississippi Medical Center (UMMC): University of Mississippi Medical Center said a cybersecurity attack knocked multiple IT systems offline Thursday, cutting off access to its Epic electronic medical records platform and prompting the Jackson-based system to close clinics and cancel outpatient care.... Source
Analysis Summary
# Incident Report: UMMC Systems Outage and Clinic Closures
## Executive Summary
A major cybersecurity attack targeted the University of Mississippi Medical Center (UMMC) on February 19, 2026, forcing the healthcare provider to take critical IT systems offline. The incident necessitated the closure of all 35 statewide clinics and the cancellation of outpatient care due to the loss of access to the Epic electronic medical records (EMR) platform. While the full scope of data compromise is still being assessed, the immediate impact has resulted in a total disruption of clinical operations.
## Incident Details
- **Discovery Date:** February 19, 2026
- **Incident Date:** February 19, 2026 (Early morning)
- **Affected Organization:** University of Mississippi Medical Center (UMMC)
- **Sector:** Healthcare
- **Geography:** Jackson, Mississippi, USA (and 35 statewide clinic locations)
## Timeline of Events
### Initial Access
- **Date/Time:** Thursday, February 19, 2026, early morning.
- **Vector:** Undisclosed (Investigation ongoing).
- **Details:** Employees reported a compromise affecting the totality of the organization's IT systems.
### Lateral Movement
- **Details:** Specific movement techniques are not yet public, but the attack reached critical infrastructure, including the Epic EMR platform and internal communication systems.
### Data Exfiltration/Impact
- **Impact:** Critical medical record systems were rendered inaccessible; multiple IT systems were knocked offline to prevent further spread.
### Detection & Response
- **Discovery:** Staff detected the outage in the early morning hours when EMR systems became unresponsive.
- **Response Actions:** UMMC leadership initiated a shutdown of IT systems, closed all 35 clinics, canceled outpatient appointments, and sent non-essential staff home.
## Attack Methodology
- **Initial Access:** Undisclosed/Pending Investigation.
- **Persistence:** Not disclosed.
- **Privilege Escalation:** Not disclosed.
- **Defense Evasion:** Not disclosed.
- **Credential Access:** Not disclosed.
- **Discovery:** Not disclosed.
- **Lateral Movement:** Not disclosed.
- **Collection:** Not disclosed.
- **Exfiltration:** Potential data exfiltration is a risk in such outages, but unconfirmed at this stage.
- **Impact:** System Downtime/Resource Exhaustion; Denial of Service to medical records.
## Impact Assessment
- **Financial:** High (Loss of revenue from canceled outpatient care and clinic closures; potential recovery/remediation costs).
- **Data Breach:** Unconfirmed but suspected (Epic EMR access was compromised).
- **Operational:** Severe (All 35 clinics closed; outpatient services halted; EMR offline).
- **Reputational:** High (Statewide news coverage and disruption to patient care).
## Indicators of Compromise
- **Network indicators:** None currently disclosed.
- **File indicators:** None currently disclosed.
- **Behavioral indicators:** Unauthorized system-wide outages and inability to authenticate to the Epic platform.
## Response Actions
- **Containment:** Disconnection of IT systems from the network; closure of physical clinic locations.
- **Eradication:** In progress.
- **Recovery:** Restoration of electronic medical records (Epic) is the primary priority.
## Lessons Learned
- **Redundancy:** Reliance on a centralized EMR system creates a single point of failure that can paralyze an entire healthcare system if compromised.
- **Business Continuity:** The incident highlights the need for robust "downtime procedures" that allow clinical care to continue even during a total IT blackout.
## Recommendations
- **Implement Network Segmentation:** Ensure that administrative and clinical networks (like Epic) are isolated to prevent lateral movement.
- **Enhanced Monitoring:** Deploy Endpoint Detection and Response (EDR) to identify early-morning anomalous behavior before system-wide impact.
- **Offline Backups:** Ensure that immutable, offline backups of medical records and critical databases are maintained to facilitate recovery from potential ransomware.
- **Regular Pressure Testing:** Conduct tabletop exercises specifically focused on "Hospital Total Downtime" scenarios.