AP lab maps its cyberattack recovery
August 2021—The downtime manual that the anatomic pathology laboratory at the University of Vermont Medical Center maintained in 2020 was never intended to be used for dealing with a cyberattack. In fact, it wasn’t actually a manual. It was a laboratory-wide policy essentially consisting of one instruction to be used in the event of a power failure or short-term IT disruption or other emergency: “Bring everything to a halt.” In anatomic pathology, “Our downtime protocol was: You stop in your tracks,” says dermatopathologist Anne M. Stowman, MD. “For the urgent/emergent specimens, you get out your paper logs, you do paper recording of the cases coming in, and you handwrite your cassettes, your descriptions, your slides.” That would be a bit slower and less efficient, but it would work for brief, temporary outages and disruptions. But the cyberattack that UVMMC experienced in October 2020, cutting off the labs’ access to the medical center’s information technology systems and disabling operations for more than three weeks, was an abrupt wake-up call.