CardioComm Solutions took systems offline after cyberattack

Organization
CardioComm Solutions
Exploit
Hacking
Industry
Medical Technology

CardioComm Solutions, a Canadian maker of electrocardiogram recording and reporting software, said on July 25, 2023 that it had been hit by a cyberattack and had taken its systems offline in response.

The company said its production server environments were affected. Its website and hosted services went dark, including the Global Cardio 3 ECG software, the GEMS Flex 12 and GEMS Home Flex upload services, the GEMS Mobile ECG app, and support for the HeartCheck CardiBeat handheld monitor.

CardioComm said there was no evidence that customer health information had been compromised, on the basis that its software runs on each client's own servers and that it does not collect patient health information from clients. It did initiate identity theft precautions in case employee personal information had been exposed.

The company engaged KPMG-EGYDE along with third party cybersecurity specialists and relevant authorities to determine the source and extent of any data breach. It warned that business operations would be disrupted for several days and potentially longer, depending on how quickly data could be restored and the production environment rebuilt.

CardioComm also said the incident would delay its already overdue annual financial statements, which it needed to file before the expiry of a cease trade order issued by the Ontario Securities Commission.

Sources