A suspected cyber incident at Fenway Health in Boston, Massachusetts, delayed patient messages and phone responses last week as the community health center worked to restore normal operations.
Fenway warned patients Friday that responses through MyChart, its online patient portal, and by phone could be delayed as the organization responded to what it called an IT incident.
The multiday disruption, Fenway’s work with outside IT experts and its decision not to rule out a cyberattack indicate possible cyber involvement. Neither Fenway nor another authoritative source has publicly identified the cause.
Fenway also canceled a Friday morning sexual health walk-in clinic session in Boston and directed people with urgent needs to local urgent care clinics. Its notice did not explicitly attribute the cancellation to the suspected cybersecurity incident.

“We have taken multiple steps to limit impacts to patient care,” Ryan Dunn, a Fenway Health spokesperson, told Axios Saturday.
Dunn said Fenway was working with outside IT experts to resume operations and described the event as an interruption to its IT systems.
Asked whether the interruption was a cyberattack, Fenway did not rule out that possibility, Axios reported. Dunn also did not answer questions about when the incident began, how it affected appointments or MyChart correspondence, or whether patient or other sensitive data was compromised.
The organization had removed its broad IT notice from its website by Sunday, according to Axios, but had not issued a public all-clear. The dated clinic cancellation notice remained visible on Fenway’s sexual health clinic page Sunday.
Fenway’s notice did not identify specific affected facilities. The organization operates clinical and community programs in Boston and Cambridge.
Fenway Health serves more than 30,000 patients and provides medical, behavioral health, dental, pharmacy and other services. It has a longstanding focus on LGBTQIA+ people and other underserved communities.
Fenway has not disclosed the incident’s cause, identified the systems affected or said whether patient or other sensitive data was compromised.