Record Analog Response to 28-Day Cyberattack

Scott Cormier, Vice President, Emergency Preparedness
Virginia Hospital & Healthcare Association, REP 2501

On the morning of May 9, 2024, Scott Cormier (REP 2501), Ascension Health’s emergency management leader and Incident Commander, was entering a secure meeting with the FBI and the Department of Homeland Security when regional leaders began reporting IT issues at their hospitals. He told each of them to keep him posted, and then stepped into a Sensitive Compartmented Information Facility, leaving his phone behind, as required.

When Cormier walked out of the meeting, his phone was flooded with messages. One was from Ascension’s Chief Information Officer: “Scott, we’ve had a cyberattack, and we need you to stand up incident command.”

In that moment, it was clear this was not just a technical problem, but an enterprise-wide operational crisis.

“That confirmed we were thinking about the problem the same way,” Cormier said. “This wasn’t just a technical issue—it was an operational one that needed to be managed.”

The attack—widely attributed to the Russia-linked Black Basta ransomware group—forced one of the nation’s largest nonprofit healthcare systems to operate without critical digital systems for weeks. As Ascension’s emergency management leader, Cormier led the system-wide response.

Cormier was no stranger to cyber incidents. After responding to a Conficker computer virus outbreak at HCA Healthcare in 2010—caused by a vendor’s infected USB drive—he helped develop policies which require healthcare organizations to retain control over cybersecurity on leased systems, and place emergency management at the center of incident command.

By 2024, that approach enabled him to stand up incident command immediately, and coordinate across Ascension’s network, spanning 19 states.

The attack unfolded differently than expected. A single phishing email introduced ransomware, but Ascension’s systems were not immediately locked. Instead, once the incident became public, external partners began cutting access—cloud providers blocked domains, and software vendors disconnected services.

“You cannot work in an analog environment by yourself. You have to work with your partners.”

-Scott Cormier, REP 2501

“I was preparing for our computers being locked up,” Cormier said, “and instead, our access to software was cut off by our partners.”

With systems down, the organization shifted into an extended analog operating environment under Cormier’s leadership.

Cormier recalled that clinicians returned to hand charting, often recreating records that would have spanned hundreds of pages. Financial workflows stalled, forcing teams to work directly with insurers to maintain cash flow. Some pharmacies would not accept paper prescriptions—particularly for controlled substances—requiring coordination across partners to ensure patients received medications.

None of those complications had been part of the original cyber plan.

“You cannot work in an analog environment by yourself,” Cormier said. “You have to work with your partners.”

That lesson—coordination over isolation—was not new to Cormier, but the magnitude of the incident reinforced it.

After decades in the military, public safety, and emergency management, he came to understand that recovery depends as much on governance and relationships as it does on technology.

Following the attack, Cormier completed CHDS’s Radiological Emergency Preparedness (REP) Program, where that perspective was further sharpened.

“What really interested me about REP is that it wasn’t a rehash of the past,” he said. “It’s about where we are now, where we need to be, and how to get there.”

Though rooted in radiological preparedness, Cormier viewed REP as an all-hazards leadership environment—one that reinforced his belief that cyber incidents are enterprise-wide crises, and not isolated IT failures.

At CHDS, he said, instructors challenge experienced practitioners to think beyond established playbooks.

“The instructors push you to think about what comes next,” he said. “You can be very experienced in your field and still be challenged to look at problems differently and anticipate future threats.”

REP also expanded his network across government and the private sector, reinforcing what the cyberattack had made clear: recovery depends on collaboration across organizations and disciplines.

“You’re not only connected to the people in your classroom,” he said, “but to their connections as well.”

Scroll to Top