London hospital recovers from Conficker outbreak
Whipps Cross worm-whipped
Regcast training : Hyper-V 3.0, VM high availability and disaster recovery
An east London hospital has confirmed its computer systems were infected by the Conficker worm earlier this month.
Whipps Cross University Hospital NHS Trust stressed that the outbreak affected only administrative systems, causing minor inconvenience, and did not affect patient care. Systems have since been restored to normal.
Around one in 20 computers were affected by the outbreak, the Leytonstone-located NHS hospital explained in a statement.
Whipps Cross University Hospital NHS Trust can confirm that on August 5 the conficker worm virus entered our IT system on site.As a result about five per cent of the Trust's PCs (30 machines) were affected and were out of action for a number of days.
The virus, which was quickly isolated, did not affect the delivery of patient care and all systems are now operating normally.
The incident is a reminder that the Conficker mega-worm, whose 1 April "activation date" was much hyped by the mainstream press, remains active. Although the botnet the worm established has not been used to launch either denial of service attacks or spam runs it remains a huge threat, with hundreds of thousands of machines infected by the worm.
Local paper The Epping Forest Guardian first reported the infection last Friday. More details emerged over the weekend, including the revelation that the outbreak was down to Conficker.
Virus infections at NHS hospitals are rare but hardly unprecedented. Last November PCs at the three hospitals that form the Barts and the London NHS Trust were forced offline following infection by the MyTob worm. The malware outbreak forced the hospitals to briefly reroute ambulances and disrupted hospital administration while the infection was being contained. A subsequent report criticised the Trust's IT security.
Other incidents include the infection of PCs at a Sheffield hospital with the Conficker worm in January 2009, soon after the first appearance of the worm. More than 800 computers at the Sheffield Teaching Hospitals Trust were infected by Conficker. ®
COMMENTS
In defense of slow patching...
...not every MS patch is golden -- everyone who works with Windows will recall some Bad Patch Of Doom that mares things up. Also, many patches require restarts and a lotta healthcare stuff is 24/7. Yes, the game needs to be sharpened up. But throwing open the servers to automatic updates would be at least as risky, and involve plenty of docs saying "excuse me, where is my spleen scanning system?" when it bounces.
OMG
OMG
I wish I could but I can't be bothered...
Must admit to supporting MSP decisions though (long live freedom)
And *How* long has the Conficker fix patch been out? :)
Seems to me the IT staff isn't keeping up with their patches...
I mean, come on! The patch was released almost a year ago! I can understand 2-3 months delay (maybe) but 12?
I suggest an alternate headline:
"Hospital IT staff incompetent: systems unpatched for 12 months infected"

IT infrastructure monitoring strategies
Agentless Backup is Not a Myth
Top 10 SIEM implementer’s checklist
Steps to Take Before Choosing a Business Continuity Partner
Requirements Checklist for Choosing a Cloud Backup and Recovery Service Provider