Some Dutch hospitals denied patients access to their medical records over the weekend because of security issues with the online gateway Citrix.
The national cybersecurity centre NCSC advised hospitals to disconnect their Citrix applications from the internet after discovering a “critical vulnerability” that could allow hackers to operate the system remotely.
The US Cybersecurity and Infrastructure Security Agency issued an alert on Sunday, saying it had “received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally”.
The Amphia Ziekenhuis in Breda, the Elisabeth-TweeSteden Ziekenhuis in Tilburg and the Frisius medical centre in Leeuwarden were among the Dutch hospitals that reported problems at the weekend.
Doctors were still able to look at patients’ records, but the patients themselves could not during online consultations.
The Frisius MC said on Sunday it had blocked access as a precautionary measure in response to the alerts by the NCSC and Z-Cert, the agency specialising in digital security in healthcare, but its systems were now back online.
The interior ministry said some of its civil servants had been unable to work remotely at the weekend after its Citrix applications were switched off.
It is not the first time Dutch institutions have experienced security issues with Citrix and its access program, NetScaler. Last year the public prosecution service (OM) restricted access for two months after hackers exploited a gap in its security systems.








