Mississippi auditor presses UMMC over its ransomware response

Mississippi's state auditor wants answers from the university system about how it handled ransomware intrusions at a medical center and a higher-ed agency.

MedRisk Staff
By
2 Min Read

Mississippi’s state auditor has formally asked the university system for answers about how two agencies handled ransomware intrusions, including one that shut down the University of Mississippi Medical Center’s network earlier this year.

State Auditor Shad White sent a letter on September 21 to the commissioner of the Institutions of Higher Learning seeking the nature and scope of both incidents, whether extortion demands arrived, whether any payment was made, and copies of remediation plans. “Taxpayers deserve to know what happens to their money,” White wrote.

A UMMC spokesperson said the medical center did not pay a ransom. Officials told Mississippi Today in April that a forensic analysis was underway with FBI support to establish what data was accessed or exfiltrated.

The Medusa ransomware group claimed credit in March, nearly a month after the attack halted UMMC’s network, and demanded payment to keep stolen data offline. UMMC has declined to confirm Medusa as the attacker, though its leadership has said the perpetrator is well known to the FBI.

The exchange matters beyond Mississippi. Hospitals routinely absorb weeks of disruption from ransomware while disclosure timelines stretch for months, and public pressure from auditors and legislators is becoming a reliable source of detail alongside breach portals. Health systems still waiting on forensic findings should expect questions about ransom decisions, not just technical controls.

Share This Article