Livingston HealthCare

Livingston HealthCare disclosed a potential cybersecurity incident on February 13, 2026, after phone and network services were disrupted and some systems were taken offline. Phones returned February 16, but staff still could not use the patient portal February 18; the final recovery date and possible patient-data compromise remain unresolved.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
The incident is cyber-related, but available evidence does not establish whether or how data was affected.
A service, system, platform, or operational capability remained available only in part or with significant limitations.
Internal or external network connectivity was unavailable or materially impaired.
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
Clinical, diagnostic, pharmacy, patient-care, medical-record, or other healthcare operations were materially affected.
A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.
Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.
We reported that Livingston HealthCare experienced a cybersecurity incident affecting phone and network services in February 2026. The hospital’s qualified cyber wording and containment actions confirm cyber involvement without establishing ransomware or a specific mechanism.
Phone and network services were disrupted, and Livingston HealthCare took some systems offline for containment. Emergency, urgent and other patient care continued; phone service returned Feb. 16 while some network services remained limited. Continued patient care establishes clinical continuity, not normal network operations.
Livingston HealthCare’s Feb. 18 update said the patient portal remained unavailable to staff because of ongoing network disruptions. Patients were told not to send portal messages because providers might not receive or answer them promptly and were directed to call instead.
The health system’s official directory lists its main hospital and UrgentCare in Livingston and Shields Valley Clinic in Wilsall, both in Park County. The public incident notices did not identify site-by-site conditions, so Wilsall is included as a medium-confidence impacted location rather than a confirmed facility-specific outage.
Confidence is high that the disruption was cyber-related because Livingston HealthCare described a potential cybersecurity incident and corresponding containment actions. HIPAA Journal reported that the organization could not yet determine the extent of possible patient-data compromise. That wording does not establish confirmed unauthorized access, and ransomware, data theft and threat-actor attribution remain unresolved. No stable public actor claim was located.
The hospital used cyber-specific language and documented phone, network and patient-portal effects, supporting organization-confirmed cyber and disruption transparency.
The incident is presumed resolved. Feb. 18 is the latest date on which Livingston HealthCare documented continuing operational limitations, and no later source established continuing material disruption or a final all-clear.
The public record does not establish entry method, malware, confirmed data access, exfiltration, notification population, recovery cost, threat actor, site-by-site impact or a final restoration date.

Livingston HealthCare operates Shields Valley Clinic in Wilsall. The organization described network disruption without publishing site-by-site conditions.
We reported phone and network disruption, containment measures, continued patient care, phone restoration and network services that remained limited Feb. 16.
Livingston HealthCare’s Feb. 18 update said its patient portal remained unavailable to staff because of ongoing network disruptions. It told patients not to send portal messages and to call providers instead while restoration continued.
HIPAA Journal reported that Livingston HealthCare said it could not yet determine the extent of possible patient-data compromise and warned patients about fraudulent compensation solicitations. It did not report confirmed unauthorized access or misuse.
Livingston HealthCare’s official directory lists the main hospital and UrgentCare in Livingston and Shields Valley Clinic at 309 Elliot St. N. in Wilsall.
Signed-in members can report an error, update, or missing source.