Skip to content

Gritman Medical Center cybersecurity incident

Summary

Gritman Medical Center logo

Gritman Medical Center described an electronic-systems outage that closed multiple outpatient clinics beginning April 1, 2026, while its hospital and emergency department remained open. Clinics reopened April 6, although four rural sites still had phone outages; the provider called the event a cybersecurity incident but reported no successful system access or known patient-data compromise in its preliminary findings.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

  • Phone service disruption

    Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Scheduling disruption

    Appointment, booking, reservation, dispatch, staffing, or other scheduling functions were unavailable or impaired.

  • Healthcare operations disrupted

    Clinical, diagnostic, pharmacy, patient-care, medical-record, or other healthcare operations were materially affected.

  • Facility closure

    One or more offices, schools, clinics, stores, plants, branches, or other facilities closed because of the incident.

Incident narrative

Analyst assessment

Gritman Medical Center described an electronic-systems outage beginning April 1, 2026, that closed multiple primary and specialty clinics while its hospital and emergency department remained open. In an April 3 update, Gritman called the event a cybersecurity incident and said electronic systems were returning. Our reporting documented the clinic disruption and phased recovery.

DysruptionHub assesses with high confidence that cyber involvement is confirmed because the affected health system used cyber-specific language for the incident. That classification does not establish malicious access, ransomware or a particular mechanism. Gritman said its preliminary findings showed no successful access to its electronic systems and no compromise of patient or other secure data, while an external forensic review was planned.

Operational significance

The outage canceled or rescheduled outpatient appointments and closed multiple clinics, although the hospital, emergency department and later QuickCARE remained available. Becker’s Hospital Review reported that all offices and clinics reopened on regular schedules April 6, but phone lines remained down at Kendrick Family Medicine, Potlatch Family Medicine, Troy Family Medicine and LCSC Warrior Health in Lewiston. Those four municipalities are included as impacted locations because the report identified continuing incident-related service loss at named facilities.

Disclosure posture

Gritman’s April 2 notice disclosed the operational outage without a cause. Its April 3 update then characterized the event as a cybersecurity incident, described recovery and reported preliminary no-access and no-compromise findings. This affected-organization disclosure preceded external cyber characterization and supports an OC-OD classification.

Current status

The incident is presumed resolved. All offices and clinics had reopened by April 6, but four sites still had phone outages in the latest operational report. No later positive all-clear was found; more than 30 days have elapsed without a newer documented impact.

Confidence and uncertainty

Confidence is high that the outage was cyber-related and caused material outpatient disruption because Gritman directly described both. Ransomware and threat-actor involvement remain unresolved. A weekly advisory later labeled the event ransomware without identifying a claimant or primary evidence; that unsupported characterization is not treated as a stable claim or confirmed ransomware evidence. Data impact remains unknown because Gritman’s assurance was explicitly preliminary and no final forensic result was found.

Analytic gaps

The public record does not establish the initial access vector, targeted account or host, vulnerability, attacker infrastructure, malware, encryption, persistence, final forensic cause, confirmed data access, affected-person count, extortion communication, actor attribution or final restoration date for the four residual phone outages.

Organizations involved

Impacted locations

  • Kendrick, Idaho

    Kendrick Family Medicine. Becker's reported that its phone lines remained down April 6 after the clinic reopened following the cybersecurity disruption.

  • Lewiston, Idaho

    LCSC Warrior Health in Lewiston. Becker's reported that its phone lines remained down April 6 after the clinic reopened following the cybersecurity disruption.

  • Potlatch, Idaho

    Potlatch Family Medicine. Becker's reported that its phone lines remained down April 6 after the clinic reopened following the cybersecurity disruption.

  • Troy, Idaho

    Troy Family Medicine. Becker's reported that its phone lines remained down April 6 after the clinic reopened following the cybersecurity disruption.

Sources

Moscow, Idaho, clinics reopen after Gritman cyber incident

DysruptionHub reported that the incident disrupted outpatient care while the hospital and emergency department remained open. It found no identified attack type, named actor, public responsibility claim, or extortion demand.

Gritman Medical Center electronic systems outage notice

Gritman Medical Center reported an electronic-systems outage that closed several primary and specialty clinics while the hospital and emergency department remained open.

Gritman Medical Center cybersecurity incident update

Gritman said electronic systems were coming back online following a cybersecurity incident, QuickCARE had reopened, and preliminary findings showed no successful system access or compromise of patient or secure data.

Moscow clinics begin reopening after Gritman systems outage

KHQ reported that primary and specialty clinics went offline early April 1, most affected appointments were canceled or rescheduled, and staff and volunteers answered phones while systems were restored.

Idaho hospital resumes operations after cybersecurity disruption

Becker’s reported that all Gritman offices and clinics reopened on regular schedules April 6, while phone lines remained down at Kendrick, Potlatch, Troy, and LCSC Warrior Health locations.

Gritman Medical Center

Official profile information supporting the public description of Gritman Medical Center.

Geographic profiles for selected U.S. locations

Official geographic reference used with local and state material to verify place names, jurisdiction types and location context for kendrick, troy, potlatch, moscow, nez perce, latah, lewiston.

See something that needs correction?

Signed-in members can report an error, update, or missing source.