Community Health Systems reports GoAnywhere hacked

Community Health Systems filed with the Securities and Exchange Commission that it was notified by a third-party vendor for secure file transfer of an incident that resulted in unauthorized disclosure of its patient data.

WHY IT MATTERS

The GoAnywhere managed file transfer platform first warned about a zero-day remote code injection exploit on February 1, according to the technical bulletin posted by noted security researcher Brian Krebs on Infosec.exchange

“The attack vector of this exploit requires access to the administrative console of the application, which in most cases is accessible only from within a private company network, through [virtual private network] or by allow-listed IP addresses (when running in cloud environments, such as Azure or AWS),” according to the Fortra bulletin Krebs accessed and shared.

Franklin, Tennessee-based CHS is one of the largest publicly-traded hospital systems in the United States. Its portfolio contains 79 acute-care hospitals and more than 1,000 other sites of care, such as physician practices, urgent care centers, imaging, cancer centers and more spread across 16 states, according to its website.

Patient care was not affected, according to CHS.

“The company believes that the Fortra breach has not had any impact on any of the company’s information systems and that there has not been any material interruption of the company’s business operations, including the delivery of patient care,” CHS said in the Feb. 13 SEC filing posted on its website.

According to a February 10 report on Bleepingcomputer, the Clop ransomware gang claimed to be behind a wave of 130 attacks where they breached the popular MFT platform and stole data.

“The security flaw, now tracked as CVE-2023-0669, enables attackers to gain remote code execution on unpatched GoAnywhere MFT instances with their administrative console exposed to Internet access,” says Bleepingcomputer.

The story alleges that Clop reached out to the publication to claim responsibility for the attacks and say that they stole the data over a 10-day period. Clop also said that they were able to move laterally through the networks, but decided against deploying ransomware payloads. 

CHS was the first to report a data breach in the GoAnywhere attacks, according to the publication’s February 14 report. 

THE LARGER TREND

Worms targeting undetected vulnerabilities are now typically coupled with executing ransomware shutdowns in a highly-selective fashion.

This is not the first time, however, that CHS has dealt with exposure of protected health information. 

In 2014, hackers compromised administrative credentials to gain access to CHSPSC, the management company owned by and providing business-associate services to CHS hospitals and physician clinics.

The FBI notified CHSPSC that its health information management system was accessed through its virtual private network. 

From April to August of that year, the cybercriminals tapped into 237 covered entities served by CHSPSC, and exfiltrated the PHI of more than six million people, according to the U.S. Department of Health and Human Services.

In 2020, the healthcare delivery company paid a $2.3 million settlement to the Office for Civil Rights for potential HIPAA violations in a dispute that followed over noncompliance.

Zero-day threats are ever-present. HHS has advised the healthcare sector to patch early, patch often.

The Health Sector Cybersecurity Coordination Center recently warned that Clop ransomware is also sending infected files disguised as medical images in phishing attacks on medical facilities.

ON THE RECORD

“The company may have incurred, and may incur in the future, expenses and losses related to this incident that are not covered by insurance,” CHS said in the filing.

In a separate SEC filing on February 15, the private healthcare company reported fourth quarter 2022 net operating revenues totaling $3.142 billion.

Andrea Fox is senior editor of Healthcare IT News.
Email: af**@***ss.org

Healthcare IT News is a HIMSS Media publication.

Read More
Luz Mayoral

Latest

Eyewitness Recalls ‘Tragic’ Hit-and-Run That Killed Ex-Penn State Player’s Fiancee & Left Him on Life Support

What began as a routine walk through a quiet Colorado neighborhood turned into an unimaginable tragedy for former Penn State football player Kyle Vasey and his fiancée, Corinne More. On June 3, a pickup truck veered onto a sidewalk and struck the couple, leaving More dead and Vasey fighting for his life. One bystander who

Texas Southern Football Releases Multi-Venue 2026 Home Schedule

HOUSTON — A clearer picture is emerging of where Texas Southern University will play its home football games in 2026. A school representative contacted HBCU Legends and said the schedule has not been finalized and remains subject to change. As Texas Southern marks its centennial next year, the football program is framing this season's multi-venue

Will Bettridge, Ted Lasso and the embodiment of a Virginia football player

Will Bettridge is about to become Virginia’s all-time leading scorer.  He is like a goldfish, according to former Virginia kicker Matt Ganyard. “I think about what makes a great kicker,” Ganyard said in an interview with UVA On SI. “And then looking at Will, he absolutely embodies it. Thinking back to the Ted Lasso quote

The NFL’s Changing Landscape: Why Talent Evaluation Matters More Than Ever

The NFL’s Changing Landscape: Why Talent Evaluation Matters More Than Ever The National Football League remains the most popular sports competition in the United States, attracting millions of viewers every season and generating enormous interest among fans, analysts, scouts, and bettors alike. While star quarterbacks and championship contenders often dominate headlines, the foundation of every

Newsletter

Don't miss

Eyewitness Recalls ‘Tragic’ Hit-and-Run That Killed Ex-Penn State Player’s Fiancee & Left Him on Life Support

What began as a routine walk through a quiet Colorado neighborhood turned into an unimaginable tragedy for former Penn State football player Kyle Vasey and his fiancée, Corinne More. On June 3, a pickup truck veered onto a sidewalk and struck the couple, leaving More dead and Vasey fighting for his life. One bystander who

Texas Southern Football Releases Multi-Venue 2026 Home Schedule

HOUSTON — A clearer picture is emerging of where Texas Southern University will play its home football games in 2026. A school representative contacted HBCU Legends and said the schedule has not been finalized and remains subject to change. As Texas Southern marks its centennial next year, the football program is framing this season's multi-venue

Will Bettridge, Ted Lasso and the embodiment of a Virginia football player

Will Bettridge is about to become Virginia’s all-time leading scorer.  He is like a goldfish, according to former Virginia kicker Matt Ganyard. “I think about what makes a great kicker,” Ganyard said in an interview with UVA On SI. “And then looking at Will, he absolutely embodies it. Thinking back to the Ted Lasso quote

The NFL’s Changing Landscape: Why Talent Evaluation Matters More Than Ever

The NFL’s Changing Landscape: Why Talent Evaluation Matters More Than Ever The National Football League remains the most popular sports competition in the United States, attracting millions of viewers every season and generating enormous interest among fans, analysts, scouts, and bettors alike. While star quarterbacks and championship contenders often dominate headlines, the foundation of every

The Importance of Chris Barnes’ First Watch List Mention at Oklahoma State

Three schools in three years was probably not how Chris Barnes wanted to start his college football career. Now at Oklahoma State, he hopes this decision sticks. Barnes began his college football career at Washington State in 2024 as a redshirt and he followed that by transferring to Wake Forest in 2025. Why does a

Business delegation visits Kazakhstan to strengthen economic and trade cooperation

Astana, Kazakhstan, Jun 2, 2026 - (ACN Newswire) - A business delegation led by the Chief Executive of the Hong Kong Special Administrative Region (HKSAR), John Lee, and organised by the Hong Kong Trade Development Council (HKTDC), began its visit to Astana, the capital of Kazakhstan, on 1 June. During the visit, a total of 43

13 Real Business Trip Stories That Prove Work Travel Collects More Stories Than Miles

Real business trips almost never go the way the itinerary promised. They start with a confidently-packed suitcase and an eight-page agenda, and somewhere between the airport gate and the hotel breakfast they quietly turn into something nobody could have invented — equal parts comedy, chaos, and unscheduled adventure. These 13 real business trip moments are exactly that kind of work-trip plot

Your business texts could look like scam messages from July 1 if you don’t act now

From July 1, any branded SMS your business sends without a registered sender ID will be labelled “Unverified” and grouped with scam messages.  What’s happening: From 1 July 2026, any business or organisation that sends SMS using a branded name, such as “MyShop” or “AcmeServices”, instead of a phone number, must have that sender ID