25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Estes Park Health Ransomware Attack Highlights Risks of Paying Ransoms

Estes Park Health (EPH) in Colorado has suffered a ransomware attack that resulted in widespread file encryption across the network.

The attack was noticed by employees on Sunday June 2, 2019 who reported that their computers were behaving strangely. EPH contacted its on-call IT technician who logged in and experienced the same issues, as the ransomware systematically encrypted files on the network. EPH, Chief Information Office, Gary Hall, witnessed the ransomware locking files and taking control of programs on his computer, according to a recent report in the Estes Park Trail Gazette.

IT staff responded quickly and started locking systems down, but it was not possible to prevent widespread file encryption. Software in the clinic was the first to go offline, followed by its digital imaging software, which stores all X-rays and other medical images. The attack wiped out the network and its phone service.

EPH activated its incident response center and switched to emergency mode procedures while its computer system was down. EPH uses software that constantly monitors the network and detects any attempts to exfiltrate data. Between the attack commencing and access being terminated, the event logs show no attempts were made to exfiltrate data. EPH believes the main motivation behind the attack was extortion through the prevention of access to critical files.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

EPH holds a cybersecurity insurance policy that covers attacks such as this. EPH used a cyber security firm recommended by its insurance company. The firm gave advice on recovery and helped manage the response.

The IT company made contact with the attackers and the ransom demand was paid. The keys to unlock the encrypted files were provided and EPH has been able to regain access to the encrypted files.

The ransom amount has not been disclosed publicly. EPH will be required to pay a $10,000 deductible. The investigation into how access was gained to its network is ongoing.

A Warning to all Healthcare Organizations

Boardman, OH-based N.E.O Urology recently announced that it had been attacked with ransomware. The decision was taken to pay the $75,000 ransom demand. Even with the keys, the extent of the encryption was such that it took more than 3 days to decrypt its files.

In that case, recovery was possible but the decision to pay a ransom is not without risk. The attackers may not hold viable keys to unlock the encryption and, as EPH discovered, payment of the ransom does not always guarantee an easy recovery.

EPH said an initial ransom payment was made and keys were supplied to unlock files. However, while unlocking files, EPH found further files had been encrypted. EPH had to then contact the attackers and make a further payment in order to get the keys to unlock all encrypted files.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist