Skip to content

Heywood Healthcare cyberattack

Summary

Heywood Healthcare logo

Heywood Healthcare said a cybersecurity incident detected Oct. 12, 2025, disrupted networks at Heywood Hospital in Gardner and Athol Hospital in Athol, including communications and clinical systems, and led to ambulance diversions. Most services returned to the network and electronic health records by Oct. 31. A later breach notice confirmed unauthorized access to files containing patient information; Sinobi’s separate 550 GB theft claim was not verified by Heywood.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

Data impacts

  • Unauthorized data access

    An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.

Operational impacts

Extortion indicators

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

Incident narrative

Analyst assessment

Heywood Healthcare said a cybersecurity incident caused the outage affecting Heywood Hospital in Gardner and Athol Hospital in Athol. DysruptionHub reported that both hospitals took affected systems offline and engaged outside cybersecurity experts. Network and phone interruptions began Oct. 12–13, 2025. The initial technical access method and whether encryption occurred were not established.

Operational significance

Both hospitals continued inpatient care but used Code Black ambulance diversions after communications and other systems failed. Local and clinical reporting documented disrupted phones and provider contact; emergency medical services reported limited imaging capacity. Heywood said Oct. 31 that most services, including outpatient lab, radiology, clinics and inpatient units, were back on its network and electronic health records, while a small number of departments remained unrestored. Its official directory lists medical-group locations in Gardner, Athol, Ashburnham and Winchendon. The latter two are mapped as organization locations; reviewed sources do not confirm an individual outage at either clinic.

Data and extortion

In a Dec. 10 Massachusetts-filed notice, Heywood said an unauthorized party accessed its network Oct. 12 and may have viewed or acquired files containing patients’ names, birth dates, procedure, medical record number, account number and diagnosis. A later New Hampshire filing describes a broader Oct. 8–12 access window, but the PDF could not be directly reviewed here; the dates warrant reconciliation. Separately, Comparitech reported that Sinobi claimed theft of 550 GB and demanded a ransom. Heywood did not verify Sinobi’s attribution or claimed volume. Official confirmation of unauthorized file access does not establish the group’s alleged amount or ransomware encryption.

Current status and gaps

Most operations were restored by Oct. 31, but no precise date for all departments was found. The incident is presumed resolved because no continuing service disruption was found after more than 30 days. The final scope of patient data, total affected people, relationship between the two breach notices, and attack method require further verification.

Threat actor and claim

Listed as: heywood.orgSource: ransomware.livePublished:

Claim details

Sinobi claimed 550 GB theft and sought a ransom. Heywood has not verified the group or amount.

Organizations involved

Impacted locations

Sources

Heywood Healthcare cybersecurity incident update

Heywood said the network outage was a cybersecurity incident, affected systems were taken offline, and outside experts were engaged.

Massachusetts hospitals take IT systems offline after cybersecurity incident

Heywood Healthcare moved IT systems offline after the Oct. 12 incident; hospitals and medical group used downtime communication alternatives.

Heywood Healthcare Oct. 31 service update

Local outlet reproduced the Heywood Oct. 31 statement that most clinical services had returned to network and EHR.

Heywood Healthcare service restoration update

Most services, including lab, radiology, clinics and inpatient units, had returned to network and EHR; a few departments were not fully restored.

Sinobi claim for heywood.org

Ransomware.live indexed a Sinobi leak-site claim naming heywood.org.

Heywood Healthcare December 2025 data breach notice

Heywood said unauthorized access Oct. 12 may have involved viewing or acquiring files containing names, birth dates, procedure, medical record, account and diagnosis information.

Heywood Healthcare September 2026 New Hampshire breach notice

A later NH-filed notice describes Oct. 8–12 network access and acquisition of files containing personal information.

Heywood Healthcare locations

Official directory lists hospitals in Gardner and Athol and medical-group facilities in Gardner, Athol, Ashburnham and Winchendon.

See something that needs correction?

Signed-in members can report an error, update, or missing source.