Axis Health System investigates Rhysida ransomware attack in Colorado

Organization
Axis Health System
Exploit
Ransomware
Industry
Healthcare

Axis Health System, a nonprofit that operates 13 behavioral health, substance use treatment and primary care facilities across southwest and western Colorado, confirmed it had been the target of a cyberattack after the Rhysida ransomware group claimed responsibility on October 10, 2024.

Rhysida demanded 25 bitcoin, valued at roughly $1.58 million to $1.6 million at the time, and set a deadline of October 17. The group posted screenshots of files it said had been taken from the Axis network and threatened to auction the data if it was not paid. Reporting indicated the material included patient and employee records.

Axis said that on discovering the activity it followed its incident response protocol, took steps to stop the unauthorized access and began investigating the nature and scope of the incident. The organization notified the FBI and engaged an outside contractor to carry out the investigation.

The primary care patient portal was unavailable during the period, and patients were directed to contact their clinics directly to reach providers. The Durango Herald reported that Axis attributed the portal outage to unrelated causes and said all other affected systems had been restored by the morning of October 15, while The Record reported the portal went offline as a result of the incident.

Axis said that if it determined patient data had been affected, individuals would be notified directly by mail. The organization declined to give further detail while the investigation continued and offered no estimated completion date.

Sources