A ransomware attack forced the University of Mississippi Medical Center to take major systems offline, disrupting its phone network, broader IT environment, and Epic electronic health record platform. UMMC closed all 35 clinics across Mississippi, canceled appointments including chemotherapy and elective procedures, and shifted staff to paper documentation while keeping hospitals and emergency departments open. The medical center said it was working with the FBI, outside cybersecurity specialists, and vendors to investigate the intrusion and restore operations.
UMMC later reopened clinics as systems were gradually brought back online, but the fallout extended beyond the immediate outage. Subsequent reporting said the incident may have exposed the organization to potential federal privacy-law issues, raising questions about whether protected health information was adequately safeguarded during the attack. The case highlights how ransomware against healthcare providers can quickly disrupt patient care, delay treatment, and create regulatory risk alongside operational recovery.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
A later report said UMMC may have violated federal privacy law in connection with the ransomware incident, indicating possible compliance concerns tied to the attack and its handling. This represented a new development beyond the initial outage and recovery reporting.
Following the outage caused by the ransomware attack, the University of Mississippi Medical Center reopened its clinics and resumed broader operations. Coverage published in late February and early March reported the reopening as the next major operational milestone after the shutdown.
In response to the cyberattack, UMMC closed all 35 clinics across Mississippi and canceled appointments, including chemotherapy and elective procedures, while hospitals and emergency departments remained open. Staff shifted to paper documentation to continue time-sensitive care.
The University of Mississippi Medical Center suffered a ransomware attack that disrupted its phone systems, Epic electronic health records platform, and broader IT network. UMMC took affected systems offline and began investigating with cybersecurity specialists, vendors, and law enforcement including the FBI.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
wlbt.com
Open sourcecybersecuritydive.com
Open sourcehealthcaredive.com
Open sourcenpr.org
Open sourceapnews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.