Palomar Health Medical Group cyberattack knocked outpatient systems offline for months
- Organization
- Palomar Health Medical Group
- Exploit
- Hacking
- Industry
- Healthcare
Palomar Health Medical Group, a primary and specialty care provider in North San Diego County, California, identified suspicious activity on its network on May 5, 2024 and took the affected systems offline while third-party cybersecurity specialists investigated.
The disruption hit the medical group's outpatient operations rather than the Palomar Health district hospitals. Palomar Medical Center Escondido and Palomar Medical Center Poway continued to operate. Phones, fax lines and the online patient portal went down across the group's clinics, including the affiliated Graybill Medical Group offices, leaving patients unable to book appointments or request prescription refills online and clinicians without access to electronic records.
Weeks after the intrusion the group still had no timeline for full restoration and told patients to expect delays and to attend in person. On July 18, 2024, more than two months on, it said it had made significant strides and had brought medical records, phone systems and the patient portal back online. Palomar did not publicly describe the cause beyond calling it a cybersecurity incident, though it later said the attack may have rendered certain files unrecoverable.
A later forensic review placed the intruder in the network from April 23 to May 5, 2024 and found that files containing patient names, addresses, dates of birth, Social Security numbers, medical and health insurance information had been accessible.