A ransomware attack has impacted several Ultimate Kronos Group services that hospitals and other organizations use to manage their employees and payrolls, the HR management company has confirmed. According to an alert issued yesterday by the Health Information Sharing and Analysis Center, UKG has alerted impacted customers that the attack affects the Kronos Private Cloud, which includes UKG Workforce Central, UKG TeleStaff, Healthcare Extensions, and Banking Scheduling Solutions. Many hospitals and health systems depend on Kronos for timekeeping, scheduling and payroll. 

John Riggi, senior advisor for cybersecurity and risk, said, “A lack of the availability of those services could be quite disruptive for health care providers, many of whom are experiencing surges of COVID-19 and flu patients. We have received several reports from the field indicating that some hospitals and health systems have been impacted by this ransomware attack against Kronos. This attack once again highlights the need for robust third-party risk management programs that identify mission-critical dependencies and downtime preparedness. If mission-critical third-party services are made unavailable due to a cyberattack, it may result in disruptions to hospital operations. As such, we urge all third-party providers that serve the health care community to examine their cyber readiness, response and resiliency capabilities.” 
 

Related News Articles

Headline
 AHA Friday voiced support for the Protecting and Transforming Cyber Health Care Act (S. 3983/H.R. 7084), legislation that would require medical device…
Headline
The National Security Agency, Cybersecurity and Infrastructure Security Agency and FBI this week urged U.S. organizations to apply available patches,…
Headline
The Senate Health, Education, Labor and Pensions Committee last week held a hearing on how to strengthen cybersecurity in the health care and education…
Headline
The Cybersecurity and Infrastructure Security Agency yesterday directed federal agencies to take emergency action to prevent cyber actors from exploiting…
Headline
Cybersecurity authorities in the United Kingdom, Australia, Canada, New Zealand and the United States today urged companies that deliver, operate or manage…
Headline
The Cybersecurity and Infrastructure Security Agency and FBI yesterday updated their February advisory on destructive malware targeting organizations in…