At the Corbeil-Essonnes hospital, the shock wave of a major cyberattack

Crossing the packed waiting room, Sébastien Rouget, the head of the pediatric emergency department at the Sud-Francilien hospital center (CHSF), makes an observation that resonates throughout Ile-de-France: “As everywhere, we are saturated by the bronchiolitis epidemic which started almost a month earlier than the usual seasonality. »

Like everywhere ? In this public establishment in Corbeil-Essonnes (Essonne), the tension linked to the epidemic encounters another situation which is still deteriorating. The huge hospital center, radiating over a health territory of 700,000 inhabitants, had to activate its “white plan” on August 21, due to a major cyberattack. He barely recovers.

For two months, the computer system was paralyzed. In these 110,000 square meters of halls, bedrooms and corridors, it was necessary to do without tools, software and digital files, and return to the“earlier era”, as the staff say. That of pen and paper.

Complaint and ransom

In pediatric emergencies, it was necessary to accept treatment times “lengthened” and an “regulation” young patients, with the support of the call center at 15, “further upstream”, explains Sébastien Rouget: “That means directing the lightest cases to the on-call medical center, and the most complex situations, on the contrary, to other establishments. » All this in the context of an acute crisis in the hospital system. “In doing so, we managed to keep the reception and consultations open, continues the young doctor, and that is in many ways a feat. But sincerely, I wouldn’t have imagined it would last this long. »

At the nephrology secretariat of the CHSF, in Corbeil-Essonnes (Essonne), on October 16, 2022. Since the cyberattack, the diagnoses have been recorded by the doctors on cassette, then transcribed.
The health reports, carried out at the Corbeil-Essonnes hospital, were written manually and must then be entered by the medical staff.

Eight weeks, therefore, punctuated by trying stages for the 3,600 members of the hospital community: that of the filing of a complaint, first, at the end of August. The investigation opened by the Paris prosecutor’s office and entrusted to the gendarmes of the Center for the Fight against Digital Crime (C3N), is still in progress. Stage of the claim, then, by the cybercriminal group Lockbit, which demanded 10 million euros in ransom, sum reduced, since, below 1 million. Another complex step: that of the dissemination on the dark web, at the end of September, of a compressed archive of 11 gigabytes of confidential data, concerning patients but also staff.

Read also: Cyberattack against the Corbeil-Essonnes hospital: what we know about the data released

“We know that 10% of our data volume is in the hands of this group, but who is concerned, who is not? We don’t have the answer.” concedes Gilles Calmes, the director of the CHSF. The establishment wrote a letter, accompanied by a standard letter of complaint, to the 700,000 people potentially targeted. Illuminated panels above the main reception inform visitors of the situation as soon as they arrive. Without alarming them more than that, it seems: ” I trustreports Samia (she requested anonymity), who came with her three children, including the two youngest, for a consultation. Anyway, I don’t see where else to go. »

You have 69.22% of this article left to read. The following is for subscribers only.

source site-27