ChipSoft HiX Healthcare EHR Ransomware Attack — Dutch Hospital Infrastructure Disruption — Threadlinqs Intelligence
As of 2026-07-02, ChipSoft HiX Healthcare EHR Ransomware Attack — Dutch Hospital Infrastructure Disruption is a critical-severity ransomware threat attributed to Embargo (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 15 indicators of compromise.
Threat ID: TL-2026-0344 · Severity: CRITICAL · Status: MONITORING · Category: RANSOMWARE
Attribution: Embargo · Russia · FINANCIAL
Ransomware attack on ChipSoft, the vendor behind the HiX electronic patient record system used by 76% of Dutch hospitals, knocked critical healthcare infrastructure offline on April 7, 2026. Z-CERT
On April 7, 2026, ChipSoft — the dominant electronic health record (EHR) vendor in the Netherlands — fell victim to a ransomware attack that disrupted healthcare IT infrastructure across the country. ChipSoft develops and operates the HiX (Healthcare Information eXchange) platform, which serves as the central patient data management system for approximately 76% of all Dutch hospitals, as well as many general practitioners and pharmacies.
The attack was first identified when ChipSoft's website (chipsoft.nl and chipsoft.com) went offline on April 7. Z-CERT, the Dutch healthcare sector's computer emergency response team, received notification of the ransomware attack the same day and immediately issued an emergency advisory instructing all healthcare institutions to disconnect their VPN connections to ChipSoft via the E-Zorg network.
The E-Zorg network is the largest independent healthcare network in the Netherlands, physically separated from the public internet, connecting over 5,000 healthcare locations including hospitals, general practitioners, and pharmacies. It is certified under ISO 27001, NEN 7510, and NTA7516 standards. Z-CERT's primary concern was the risk of lateral movement — ransomware potentially spreading from ChipSoft's compromised infrastructure into hospital networks through trusted VPN tunnels within this closed network.
A confidential memo to ChipSoft customers, obtained by Dutch broadcaster NOS, described a 'data incident' involving 'possible unauthorized access.' ChipSoft confirmed it could not rule out that patient records had been viewed or stolen. The attackers reportedly seized secure data and threatened publication or destruction unless a ransom was paid — a classic double extortion tactic.
At least 11 hospitals proactively took their patient portals and systems offline as a precautionary measure. Named affected institutions include Rijnstate Hospital (Arnhem), Antoni van Leeuwenhoek Hospital (Amsterdam), Erasmus MC, Ikazia Hospital, Medisch Spectrum Twente, Ziekenhuisgroep Twente, Franciscus Hospital (Rotterdam), St. Antonius Ziekenhuis, and Frisus MC (Heerenveen). Nine of these 11 hospitals use HiX more extensively for comprehensive record-keeping.
All ChipSoft deployment models were affected: HiX on-premise installations, HiX SaaS cloud deployments, the SaaS Patient Portal, and the GP (general practitioner) cloud tenant. However, some hospitals with locally stored data reported their systems remained functional, and the majority of hospitals continued to use their patient portals.
The incident has significant regulatory implications under GDPR (known as AVG in the Netherlands). ChipSoft operates as a data processor while hospitals serve as data controllers, creating complex liability and notification obligations. The Dutch Data Protection Authority (AP) and the National Cyber Security Centre (NCSC) were coordinated in the response alongside Z-CERT.
As of April 9, 2026, no ransomware group has publicly claimed responsibility for the attack. The initial attack vector has not been disclosed, though the Z-CERT advisory's focus on VPN disconnection suggests concern about compromise of network-level access or supply chain vectors. Forensic investigation remains ongoing.
This incident represents a critical healthcare supply chain attack due to ChipSoft's near-monopoly position in the Dutch hospital market. The concentration of 76% of Dutch hospitals on a single EHR vendor creates systemic risk — a single point of failure that, when exploited, can cascade across the entire national healthcare infrastructure.
Target sectors: healthcare, hospitals, pharmaceuticals, general-practice, health-information-technology
Target regions: Netherlands, Europe
Detections & IOCs
As of 2026-07-20, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 15 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, CRITICAL, threat intelligence, cybersecurity, T1133, T1078, T1195, T1059, T1078, T1078, T1562, T1070, T1003, T1018