DHSS Press Release: Detection & analysis phase of cyberattack response complete; vital records section back online
Alaska Department of Health sent this bulletin at 08/04/2021 10:35 AM AKDTFOR IMMEDIATE RELEASE
Media contacts: Clinton Bennett, DHSS, 907-269-4996, clinton.bennett@alaska.gov
Detection and analysis phase of cyberattack response complete; vital records section back online, working through backlog
August 4, 2021 ANCHORAGE – The Alaska Department of Health and Social Services (DHSS) has completed the first step of a three-step process used to respond to the attack of its information technology infrastructure. With the completion of the detection and analysis phase, DHSS’ security partners have identified those responsible for conducting the attack as a highly sophisticated group known to conduct complex cyberattacks against organizations such as state governments and health care entities.
Shortly after the attack was discovered in May, DHSS retained FireEye, a leading cybersecurity firm that provides incident response consulting services through Mandiant, to help conduct an in-depth investigation and assist with the recovery process. At this time, the investigation has found no indications that this was a ransomware attack and there is no current evidence that Alaskans’ protected health information or personally identifiable information was stolen.
“The type of group behind this disruptive attack is a very serious operation with advanced capabilities,” said Commissioner Adam Crum. “DHSS is intensely focused on responding to the attack and we continue to work with our security partners and the state Office of Information Technology to restore services as quickly and safely as possible.”
“This was not a ‘one-and-done’ situation, but rather a sophisticated attack intended to be carried out undetected over a prolonged period. The attackers took steps to maintain that long-term access even after they were detected,” said DHSS Technology Officer Scott McCutcheon. “In addition to getting everything back up and running, our team is taking strong, preventative actions and developing more robust incident response capabilities so we can quickly respond to any future cyberattacks.”
DHSS is focused on continuing through the three steps of its response:
- Detection and analysis: Phase completed.
- Containment, eradication and recovery: Significant progress has been made in removing the attacker from DHSS systems and we have no evidence of the attacker being active in our environment at this time. Recovery work continues to build back resilient systems and restoring services. A firm timeline on full restoration of services is not yet known as the Information Technology Incident Response Team is developing and implementing new processes and technologies to provide more secure and resilient services.
- Post-incident activity: DHSS will further strengthen its processes, tools and people to be more resilient to future cyberattacks. Recommendations for future security enhancements and any additional funding needs will be provided to Commissioner Crum.
DHSS continues to focus on bringing services back online with priority given to those services in very high demand. The first system brought back online was the Electronic Vital Records System used by the Health Analytics and Vital Records Section (HAVRS) to fulfill requests for vital records such as birth, death and marriage certificates. With access to the system restored on July 26, HAVRS has been transitioning back to automated processes and addressing the backlog of work created by the outage.
Both the Juneau and Anchorage Vital Records Offices have restored most of their certificate services, with a few limitations in place so staff can focus on processing the backlog orders. There is no timeline for how long it will take to eliminate the backlog, but this task is a priority for HAVRS, and staffing has been adjusted to work through the process as quickly as possible. More details about limitations and current capabilities at HAVRS are posted online at dhss.alaska.gov/dph/vitalstats/pages/.
As systems move closer to coming back online, DHSS recognizes this lengthy outage of many of its online services has been disruptive to Alaskans but again asks for everyone’s patience as we work through this ongoing situation. Staff are working as efficiently as they can to process requests in a timely manner; however, in many cases, the procedures they have been following take longer due to the need to perform tasks manually.
For phone assistance during business hours (8 a.m. - 4:30 p.m.), please contact the department at 907-269-7800 or download this detailed list of contacts for divisions, sections and programs. Many divisions have temporary webpages available with their most critical information and forms at dhss.alaska.gov.
For questions specific to COVID-19, the COVID-19 vaccine helpline is available at 907-646-3322 from 9 a.m. - 6:30 p.m. on weekdays, and 9 a.m. - 4:30 p.m. on weekends. You may also email covid19vaccine@alaska.gov for help or visit the temporary COVID-19 section of the DHSS website at dhss.alaska.gov/dph/epi/id/pages/COVID-19/default.aspx.
# # #
Attachments: Frequently asked questions, press release