Healthcare system's ransomware attack allowed by known security flaw

Last month’s attack on MedStar Health’s computer systems came through a well-known security vulnerability in an application server


The recent ransomware attack on MedStar Health’s computer systems came through from a well-known security vulnerability in an application server, according to an article on the Healthcare Finance website.

The  attack occurred after hackers discovered that MedStar uses JBoss, an application server with a recognized design flaw. The hackers used a virus-like software to scan the Internet for vulnerable JBoss servers.

Security researchers found that the JBoss application server was routinely misconfigured to allow unauthorized outside users to gain control.

The US government, Red Hat Inc., and other groups released warnings about the security issue in February 2007 and March 2010. MedStar could have fixed the vulnerability by installing a patch for the system or manually deleting two lines of software code. 

Read the article.

 

 



April 19, 2016


Topic Area: Safety


Recent Posts

Mature Dry Surface Biofilm Presents a Problem for Candida Auris

Multiple methods are described in the literature, but no consensus has been reached for disinfection efficacy tests against biofilms.


Sutter Health's Arden Care Center Officially Opens

With an adaptive reuse of an underutilized office building, the 70,000 square-foot facility was renovated to meet current healthcare standards.


Insight Hospital and Medical Center Falls to Data Breach

The investigation determined that an unauthorized individual accessed the network between August 22, 2025, and September 11, 2025.


The High Cost of Healthcare Violence

As workplace violence increases, healthcare facilities face mounting financial and operational disruptions- prompting legislative action.


EVS Teams Can Improve Patient Experience in Emergency Departments

A report confirmed that cleanliness of the ED was the third most impactful element on patient experience surveys.


 
 


FREE Newsletter Signup Form

News & Updates | Webcast Alerts
Building Technologies | & More!

 
 
 


All fields are required. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.