ChipSoft HiX Healthcare EHR Ransomware Attack — Dutch Hospital Infrastructure Disruption

ChipSoft HiX Healthcare EHR Ransomware Attack (TL-2026-0344), also tracked as ChipSoft HiX Ransomware Incident, is a critical-severity ransomware operation, first published 2026-04-09. It is attributed to Embargo (Russia) with high confidence, affects ChipSoft HiX Electronic Patient Record (On-Premise), maps to 18 MITRE ATT&CK techniques (T1003, T1005, T1018), and is covered by 9 detection rules and 15 indicators of compromise.

Key facts for TL-2026-0344

Threat ID
TL-2026-0344
Also known as
ChipSoft HiX Ransomware Incident, Dutch Healthcare EHR Attack April 2026
Severity
CRITICAL
Status
MONITORING
Category
RANSOMWARE
First published
2026-04-09
Last reviewed
2026-04-09
Attribution
Embargo
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
healthcare, hospitals, pharmaceuticals, general-practice, health-information-technology
Target regions
Netherlands, Europe
Detection rules
9
Indicators of compromise
15

Ransomware attack on ChipSoft, the vendor behind the HiX electronic patient record system used by 76% of Dutch hospitals, knocked critical healthcare infrastructure offline on April 7, 2026. Z-CERT issued emergency advisory to immediately disconnect VPN connections via the E-Zorg network due to lateral movement risk to 5,000+ healthcare locations. ChipSoft confirmed possible unauthorized access to patient data affecting millions of Dutch citizens.

How ChipSoft HiX Healthcare EHR Ransomware Attack works

On April 7, 2026, ChipSoft — the dominant electronic health record (EHR) vendor in the Netherlands — fell victim to a ransomware attack that disrupted healthcare IT infrastructure across the country. ChipSoft develops and operates the HiX (Healthcare Information eXchange) platform, which serves as the central patient data management system for approximately 76% of all Dutch hospitals, as well as many general practitioners and pharmacies.

The attack was first identified when ChipSoft's website (chipsoft.nl and chipsoft.com) went offline on April 7. Z-CERT, the Dutch healthcare sector's computer emergency response team, received notification of the ransomware attack the same day and immediately issued an emergency advisory instructing all healthcare institutions to disconnect their VPN connections to ChipSoft via the E-Zorg network.

The E-Zorg network is the largest independent healthcare network in the Netherlands, physically separated from the public internet, connecting over 5,000 healthcare locations including hospitals, general practitioners, and pharmacies. It is certified under ISO 27001, NEN 7510, and NTA7516 standards. Z-CERT's primary concern was the risk of lateral movement — ransomware potentially spreading from ChipSoft's compromised infrastructure into hospital networks through trusted VPN tunnels within this closed network.

A confidential memo to ChipSoft customers, obtained by Dutch broadcaster NOS, described a 'data incident' involving 'possible unauthorized access.' ChipSoft confirmed it could not rule out that patient records had been viewed or stolen. The attackers reportedly seized secure data and threatened publication or destruction unless a ransom was paid — a classic double extortion tactic.

At least 11 hospitals proactively took their patient portals and systems offline as a precautionary measure. Named affected institutions include Rijnstate Hospital (Arnhem), Antoni van Leeuwenhoek Hospital (Amsterdam), Erasmus MC, Ikazia Hospital, Medisch Spectrum Twente, Ziekenhuisgroep Twente, Franciscus Hospital (Rotterdam), St. Antonius Ziekenhuis, and Frisus MC (Heerenveen). Nine of these 11 hospitals use HiX more extensively for comprehensive record-keeping.

All ChipSoft deployment models were affected: HiX on-premise installations, HiX SaaS cloud deployments, the SaaS Patient Portal, and the GP (general practitioner) cloud tenant. However, some hospitals with locally stored data reported their systems remained functional, and the majority of hospitals continued to use their patient portals.

The incident has significant regulatory implications under GDPR (known as AVG in the Netherlands). ChipSoft operates as a data processor while hospitals serve as data controllers, creating complex liability and notification obligations. The Dutch Data Protection Authority (AP) and the National Cyber Security Centre (NCSC) were coordinated in the response alongside Z-CERT.

As of April 9, 2026, no ransomware group has publicly claimed responsibility for the attack. The initial attack vector has not been disclosed, though the Z-CERT advisory's focus on VPN disconnection suggests concern about compromise of network-level access or supply chain vectors. Forensic investigation remains ongoing.

This incident represents a critical healthcare supply chain attack due to ChipSoft's near-monopoly position in the Dutch hospital market. The concentration of 76% of Dutch hospitals on a single EHR vendor creates systemic risk — a single point of failure that, when exploited, can cascade across the entire national healthcare infrastructure.

MITRE ATT&CK techniques used in TL-2026-0344

credential-access

T1003 OS Credential Dumping

collection

T1005 Data from Local System; T1039 Data from Network Shared Drive

discovery

T1018 Remote System Discovery; T1046 Network Service Discovery

lateral-movement

T1021 Remote Services; T1570 Lateral Tool Transfer

exfiltration

T1041 Exfiltration Over C2 Channel

execution

T1059 Command and Scripting Interpreter

defense-evasion

T1070 Indicator Removal; T1078 Valid Accounts

command-and-control

T1071 Application Layer Protocol

persistence

T1133 External Remote Services

initial-access

T1195 Supply Chain Compromise

impact

T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in ChipSoft HiX Healthcare EHR Ransomware Attack

  • ChipSoft — HiX Electronic Patient Record (On-Premise)
    Vulnerable versions: All versions
  • ChipSoft — HiX Electronic Patient Record (SaaS)
    Vulnerable versions: All versions
  • ChipSoft — SaaS Patient Portal
    Vulnerable versions: All versions
  • ChipSoft — GP Cloud Tenant
    Vulnerable versions: All versions
  • E-Zorg — E-Zorg Healthcare VPN Network
    Vulnerable versions: Connected endpoints

Remediation for ChipSoft HiX Healthcare EHR Ransomware Attack

Immediate actions

  • Disconnect all VPN connections to ChipSoft via E-Zorg network immediately per Z-CERT advisory
  • Monitor all network traffic for unusual outbound connections from healthcare systems
  • Audit authentication logs for unauthorized access to HiX systems
  • Enable two-factor authentication on all healthcare portals and VPN connections
  • Isolate any systems that have communicated with ChipSoft infrastructure since April 5, 2026
  • Report suspicious findings to Z-CERT through official channels

Workarounds

  • Maintain manual patient record procedures as fallback during portal outages
  • Use local on-premise data copies where available for continuity of care
  • Establish direct phone communication channels between departments during portal downtime
  • Verify patient identity through alternative means when digital portals are unavailable

Longer-term hardening

  • Implement network segmentation between EHR systems and general hospital networks
  • Deploy EDR solutions with behavioral ransomware detection on all endpoints accessing HiX
  • Establish offline backup procedures for critical patient data independent of ChipSoft SaaS
  • Develop incident response playbooks specific to healthcare supply chain compromise
  • Review and strengthen VPN access controls with zero-trust architecture principles
  • Conduct tabletop exercises for EHR vendor compromise scenarios
  • Evaluate vendor concentration risk and develop multi-vendor contingency plans

Weaknesses (CWE) in ChipSoft HiX Healthcare EHR Ransomware Attack

CWE-1357

Timeline of ChipSoft HiX Healthcare EHR Ransomware Attack

  • Confidential memo sent to ChipSoft customers advising VPN disconnection; later obtained by Dutch broadcaster NOS
  • At least 11 hospitals proactively take patient portals and HiX systems offline including Rijnstate, Antoni van Leeuwenhoek, Erasmus MC, Ikazia, Medisch Spectrum Twente, Franciscus, St. Antonius, Frisus MC
  • E-Zorg network VPN connections to ChipSoft severed across 5,000+ healthcare locations to prevent ransomware propagation
  • Z-CERT issues emergency advisory instructing all healthcare institutions to immediately disconnect VPN connections to ChipSoft via E-Zorg network due to lateral movement risk
  • Z-CERT receives notification from ChipSoft of ransomware attack and begins coordinating response with healthcare institutions
  • ChipSoft discovers ransomware attack on its infrastructure; website (chipsoft.nl, chipsoft.com) goes offline
  • Dutch Data Protection Authority (AP) and National Cyber Security Centre (NCSC) coordinated in incident response alongside Z-CERT
  • Multiple media outlets publish coverage: The Register, NL Times, DutchNews, SC World, DataBreaches.net, myip.foo, ioplus.nl
  • ChipSoft confirms to NOS a data incident involving possible unauthorized access and cannot rule out patient data was viewed or stolen
  • Forensic investigation continues; no ransomware group has claimed responsibility; ChipSoft website remains offline; restoration timeline uncertain
  • As of 2026-05-29, the ChipSoft incident is contained: the Embargo group claimed it, ChipSoft says the ~100GB of stolen data was destroyed, and HiX/portals are being restored in stages with Z-CERT. It is not resolved-recovery is ongoing, Embargo stays active, and a Dutch minister/experts doubt the unverifiable deletion claim, leaving residual leak risk.

Sources cited for ChipSoft HiX Healthcare EHR Ransomware Attack

Threats related to ChipSoft HiX Healthcare EHR Ransomware Attack

Detection coverage for TL-2026-0344

As of 2026-04-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0344 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats