Skip to content

UMMC Ransomware Attack and Statewide Clinic Closures

Summary

University of Mississippi Medical Center logo

A ransomware attack struck the University of Mississippi Medical Center on Feb. 19, 2026, disabling Epic records, phone and email systems and closing 35 clinics across 23 Mississippi municipalities. Clinics and phone service returned March 2 after nine days, while Medusa later claimed the attack and demanded $800,000 to prevent publication of allegedly stolen data.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

Data impacts

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

  • Data publication or leak

    Stolen, exposed, or otherwise compromised data was publicly released, posted, distributed, or offered for download.

  • Data encryption

    Data was rendered inaccessible through unauthorized encryption, including ransomware-related encryption.

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Complete service outage

    A primary service, system, platform, or operational capability became entirely unavailable.

  • Email disruption

    Email sending, receiving, access, or related messaging functions were unavailable or materially impaired.

  • Phone service disruption

    Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.

  • Website unavailable

    A public-facing website was unavailable, disabled, or inaccessible.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Healthcare operations disrupted

    Clinical, diagnostic, pharmacy, patient-care, medical-record, or other healthcare operations were materially affected.

  • Facility closure

    One or more offices, schools, clinics, stores, plants, branches, or other facilities closed because of the incident.

  • Event or activity cancellation

    Scheduled events, meetings, hearings, classes, procedures, programs, or other activities were canceled.

  • Manual workaround required

    Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.

  • Staff sent home or placed on leave

    Employees were sent home, placed on administrative leave, furloughed, or otherwise removed from normal duties because of the incident.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

Extortion indicators

  • Ransom demand

    The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.

  • Encryption-based extortion

    The extortion activity involved unauthorized encryption of systems or data, with restoration or decryption conditioned on payment.

  • Data-theft extortion

    The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.

  • Public leak threat

    The actor explicitly threatened to publish or publicly release victim data or incident details.

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

  • Data sample published

    The actor published or shared a sample of allegedly stolen victim data to substantiate the extortion claim.

  • Countdown or payment deadline

    The actor imposed a deadline or public countdown before increasing the demand, publishing data, deleting keys, or taking another threatened action.

  • Direct victim contact

    The actor directly contacted the victim through a ransom note, email, chat portal, telephone call, messaging platform, or other communication channel.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that the University of Mississippi Medical Center experienced a ransomware attack beginning Feb. 19, 2026. UMMC called the event a cybersecurity attack in its first public statement and later confirmed that intruders demanded financial compensation to decrypt affected systems. Our initial Feb. 19 reporting documented widespread system outages, statewide clinic closures and canceled outpatient care.

Medusa claimed responsibility March 12, demanded $800,000 and posted images it described as samples of stolen UMMC documents. UMMC has not confirmed Medusa’s role or that data was stolen, so the actor relationship remains a medium-confidence claim rather than confirmed attribution.

Detection and containment

UMMC later said its monitoring detected irregular activity in the early hours of Feb. 19 as users began reporting problems. The organization shut down affected systems to contain the threat. UMMC said the incident was not caused by a single user error or someone clicking a malicious email, but it has not disclosed the initial-access mechanism.

Operational significance

The attack cut off access to Epic electronic health records and disrupted phone, email, Wi-Fi, website and other internal systems. UMMC closed all 35 clinics statewide, canceled outpatient and ambulatory surgeries and procedures, canceled imaging appointments, sent some staff home and used paper-based downtime procedures. The Jackson Medical Mall dialysis clinic continued scheduled care. Hospitals and emergency departments remained open, including facilities in Jackson, Grenada, Canton and Lexington, but UMMC temporarily diverted some transfers before resuming higher-level-care transfers Feb. 20. Staff made special arrangements for time-sensitive treatments, and chemotherapy restarted Feb. 23.

The disruption also affected organizations that depended on UMMC systems. Mississippi county health departments used paper charts while their UMMC electronic-record dependency was unavailable, although those departments remained open. UMMC later said all mission areas were affected and patient care was hit hardest. February revenue finished about 20% below budget, and the outage briefly delayed the Medical Center’s budget process.

Geographic scope

UMMC said all of its locations were affected. Its July 2025 statewide-presence map and facility directory support incident locations in 23 municipalities: Batesville, Bay St. Louis, Biloxi, Canton, Ecru, Flowood, Grenada, Gulfport, Hattiesburg, Iuka, Jackson, Lexington, Louisville, Madison, McComb, Meridian, Oxford, Ridgeland, Tupelo, Vaiden, Vicksburg, West and Winona. Multiple hospitals or clinics in the same municipality are represented by one deduplicated geographic record.

Extortion and data impact

UMMC said the attackers communicated directly and demanded payment in exchange for decrypting affected systems, independently confirming ransomware without relying on the later Medusa claim. Medusa’s listing added an alleged data-theft component, sample publication, a public leak threat and a deadline. Those actions establish extortion indicators but do not prove Medusa caused the intrusion or that its descriptions of the data were accurate.

As of UMMC’s April 27 public response, forensic work was still examining what data may have been accessed or exfiltrated. UMMC had not confirmed patient-data theft, Medusa attribution or whether any payment was made.

Confidence and uncertainty

Confidence is high that ransomware caused the disruption because UMMC described a payment demand for decryption and documented the resulting system outages. Confidence is also high in the organizationwide operational scope. Medusa attribution and alleged data theft remain medium-confidence claims because UMMC has not corroborated them.

Recovery and current status

UMMC said it was largely back to normal by Feb. 28. Clinics resumed normal operations and phone service returned March 2, with staff beginning to reschedule canceled appointments. Most systems used in regular operations were back online by March 13. The service-delivery disruption is resolved; the continuing forensic investigation does not make the incident operationally active.

Analytic gaps

The public record does not establish initial access, the precise ransomware variant, the full set of encrypted systems, the amount or categories of data allegedly stolen, whether a payment was made, Medusa’s actual role or the final notification population.

Threat actor and claim

Listed as: University of Mississippi Medical CenterSource: otherPublished:

Claim details

Medusa claimed UMMC, demanded $800,000 and posted sample images; UMMC did not confirm attribution or the alleged theft.

Organizations involved

Impacted locations

  • Batesville, Mississippi

    UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Batesville. UMMC said all locations were affected and all statewide clinics closed.

  • Bay St. Louis, Mississippi

    UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Bay St. Louis. UMMC said all locations were affected and all statewide clinics closed.

  • Biloxi, Mississippi

    UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Biloxi. UMMC said all locations were affected and all statewide clinics closed.

  • Canton, Mississippi

    UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Canton. UMMC said all locations were affected and all statewide clinics closed.

  • Ecru, Mississippi

    UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Ecru. UMMC said all locations were affected and all statewide clinics closed.

  • Flowood, Mississippi

    UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Flowood. UMMC said all locations were affected and all statewide clinics closed.

  • Grenada, Mississippi

    UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Grenada. UMMC said all locations were affected and all statewide clinics closed.

  • Gulfport, Mississippi

    UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Gulfport. UMMC said all locations were affected and all statewide clinics closed.

  • Hattiesburg, Mississippi

    UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Hattiesburg. UMMC said all locations were affected and all statewide clinics closed.

  • Iuka, Mississippi

    UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Iuka. UMMC said all locations were affected and all statewide clinics closed.

  • Lexington, Mississippi

    UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Lexington. UMMC said all locations were affected and all statewide clinics closed.

  • Louisville, Mississippi

    UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Louisville. UMMC said all locations were affected and all statewide clinics closed.

  • Madison, Mississippi

    UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Madison. UMMC said all locations were affected and all statewide clinics closed.

  • McComb, Mississippi

    UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in McComb. UMMC said all locations were affected and all statewide clinics closed.

  • Meridian, Mississippi

    UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Meridian. UMMC said all locations were affected and all statewide clinics closed.

  • Oxford, Mississippi

    UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Oxford. UMMC said all locations were affected and all statewide clinics closed.

  • Ridgeland, Mississippi

    UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Ridgeland. UMMC said all locations were affected and all statewide clinics closed.

  • Tupelo, Mississippi

    UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Tupelo. UMMC said all locations were affected and all statewide clinics closed.

  • Vaiden, Mississippi

    UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Vaiden. UMMC said all locations were affected and all statewide clinics closed.

  • Vicksburg, Mississippi

    UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Vicksburg. UMMC said all locations were affected and all statewide clinics closed.

  • West, Mississippi

    UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in West. UMMC said all locations were affected and all statewide clinics closed.

  • Winona, Mississippi

    UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Winona. UMMC said all locations were affected and all statewide clinics closed.

Sources

Mississippi medical center closes clinics amid cyberattack

We reported Feb. 19 that UMMC said a cybersecurity attack disabled Epic and other IT systems, closed all clinic locations statewide and canceled outpatient procedures, ambulatory care and imaging appointments.

UMMC Presence Across the State Maps

UMMC’s July 2025 statewide-presence map identifies preincident hospitals or clinics in Batesville, Bay St. Louis, Biloxi, Canton, Ecru, Flowood, Grenada, Gulfport, Hattiesburg, Iuka, Jackson, Lexington, Louisville, Madison, McComb, Meridian, Oxford, Ridgeland, Tupelo, Vaiden, Vicksburg, West and Winona.

UMMC confirms cyberattack, closing clinics and canceling surgeries

WLBT reported that UMMC shut down IT systems, lost access to electronic medical records, closed all 35 clinics and said attackers had communicated with the institution.

Cyberattack causes UMMC to close clinics, cancel appointments for second day

Mississippi Today reported that LouAnn Woodward said all UMMC locations were affected. All clinics closed, most elective care was canceled, hospitals used paper procedures, and county health departments that relied on UMMC records also shifted to paper charts while remaining open.

UMMC responds to cyberattack and works to restore operations

UMMC said phone and email remained unavailable or unreliable, federal teams and outside vendors were assisting, hospitals and emergency departments continued operating and transfers resumed.

UMMC confirms cyberattack financially motivated as restoration efforts continue

UMMC leadership said threat actors sought financial compensation in exchange for decrypting the medical center’s electronic platform and other affected systems and had left demands.

UMMC officials say normal operations will resume Monday after cyberattack

Mississippi Today reported that statewide clinics would resume normal operations and scheduled appointments March 2 after being closed for more than a week.

This has pulled us together: UMMC prioritizes care, learning during cyberattack

UMMC said clinics resumed normal operations March 2 after a nine-day cyberattack. All mission areas were affected, patient care was hit hardest, staff used paper workflows, chemotherapy restarted Feb. 23, and hospitals and emergency departments stayed open.

Spring Update

UMMC said monitoring detected irregular activity early Feb. 19 as users reported problems, prompting containment shutdowns. It said the attack was not caused by one user clicking a malicious email, operations were largely normal by Feb. 28, and data-access analysis continued.

Months after UMMC cyberattack, questions persist about patient data and systems improvements

Mississippi Today reported that UMMC was still determining what data was accessed or exfiltrated, had not confirmed Medusa or a ransom payment, and finished February about 20% below its revenue budget after the nine-day disruption.

UMMC Locations Search

UMMC’s public directory identifies its hospitals and clinics by address. Cross-checked against UMMC’s July 2025 presence map, it supports 23 incident-era facility municipalities while allowing multiple facilities in one municipality to be deduplicated.

See something that needs correction?

Signed-in members can report an error, update, or missing source.