Heywood Healthcare, a nonprofit healthcare system in North Central Massachusetts, experienced a significant cyberattack that forced the organization to take its IT network offline. The incident affected both Heywood Hospital in Gardner, a 134-bed facility, and Athol Hospital, a 25-bed critical access hospital in Athol, as well as associated medical groups and care facilities. As a direct result of the attack, the hospitals were unable to accept emergency care patients transported by ambulance, leading to the diversion of ambulances to other facilities. Radiology and laboratory services, including CAT scan imaging, were rendered unavailable, impacting the hospitals' ability to provide critical diagnostic services. The Central Massachusetts Emergency Medical Systems Corp. issued guidance for ambulances to transport stroke patients to the next nearest primary stroke service hospital, as the affected hospitals' imaging services would be down until further notice. In addition to clinical disruptions, the cyberattack also impacted communication systems, with email and phone services affected, further complicating coordination and response efforts. Despite these challenges, Heywood Healthcare continued to care for inpatients already admitted to both hospitals. The organization did not disclose the specific nature of the cyberattack, such as whether it involved ransomware or data exfiltration, but the operational impact was severe enough to necessitate a full network shutdown. The incident highlights the vulnerability of healthcare infrastructure to cyber threats and the cascading effects on patient care and regional emergency response. Local authorities and healthcare partners were notified, and contingency plans were activated to manage patient care and redirect emergency services. The disruption to radiology and laboratory services not only affected emergency care but also routine diagnostics for existing patients. The hospitals' inability to accept ambulance patients placed additional strain on neighboring healthcare facilities, which had to absorb redirected emergency cases. The attack underscores the importance of robust business continuity and disaster recovery planning in the healthcare sector. Heywood Healthcare's response included ongoing assessment and restoration efforts, though no timeline for full service restoration was provided. The incident also raised concerns about the security of patient data, though no evidence of data compromise was reported at the time. The healthcare system's transparency in communicating with the public and emergency services was noted as a critical component of the response. The event serves as a reminder of the critical interdependencies between IT systems, clinical operations, and emergency medical services in modern healthcare environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Two hospitals in Massachusetts were reported as experiencing service disruptions caused by a cyberattack. The available references do not provide additional technical details, victim names, or response actions beyond the disruption itself.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.