The University of Health Sciences & Pharmacy (UHSP) in St. Louis was encrypted by LockBit and refused to pay a ransom demand that its own CIO/CISO describes as exceeding seven figures. The institution restored critical systems from a layered backup estate whose third tier was fully isolated in Backblaze B2 Cloud Storage. The account comes from UHSP CIO/CISO Zach Lewis in an interview published by Healthcare Innovation on August 16, 2026, alongside Backblaze senior product marketing manager Kari Wilson. Lewis dates the intrusion to April 2023 and says it began with a compromised personal device. His LinkedIn profile confirms his role at a private health sciences university and his authorship of Locked Up: Cybersecurity Threat Mitigation Lessons from a Real-World LockBit Ransomware Response (Wiley, 2026), the book that account is drawn from.
A sourcing note up front: the UHSP-specific record here rests on a single practitioner interview and the subject's own professional profile. The remaining sources in this brief cover separate incidents and sector-level statistics. They are used as context and are labelled as such, not folded into the UHSP narrative.
What Happened
Per Lewis, the attack began in April 2023. He received an early-morning call reporting that servers were down and unavailable, initially assumed to be a routine service failure. It was LockBit, at the time among the most prolific ransomware operations worldwide. Internal systems were compromised and encrypted, and a ransom demand in excess of seven figures followed.
UHSP did not pay. Lewis credits a layered backup strategy, including a fully isolated tertiary tier held offsite in Backblaze B2 Cloud Storage, with letting the IT team recover methodically rather than under ransom-driven time pressure. Healthcare Innovation's summary of the interview singles out Object Lock, regular restore testing and validation, and out-of-band communication during the response as the controls that made the difference.
The published interview does not state total downtime, the number of systems encrypted, the exact ransom figure, or whether UHSP appeared on a LockBit leak site. Treat those as open questions.
What Was Taken
No data theft has been asserted in the available UHSP sourcing. The account describes encryption and system unavailability, and a recovery measured in restored systems rather than in notified individuals. There is no breach-portal entry, regulator filing, or notification letter for UHSP among these sources, and no record count is claimed. Absence of a claim is not proof that nothing was exfiltrated: LockBit's standard operating model pairs encryption with theft and public pressure. But on this record, the only confirmed impact is encryption and disruption.
That distinction matters because three of the sources supplied with this brief describe a different incident entirely. Unlimited Technology Systems (UTS), a Cincinnati, Ohio revenue cycle management and practice management software provider, disclosed on July 20, 2026 that an unauthorized actor accessed files between October 5 and October 10, 2025, detected on October 19, 2025. The HHS Office for Civil Rights portal lists 3,803,750 individuals affected, a figure reported consistently by The Register, BleepingComputer, and HIPAA Journal. The Register calls it the largest healthcare breach reported to regulators so far this year; HIPAA Journal ranks it second, behind DentaQuest at 15 million records and ahead of Trizetto Provider Solutions at 3.4 million. Those two rankings conflict, and the sources do not reconcile them. Exposed data types per UTS include names, Social Security numbers, dates of birth, addresses, phone numbers, demographic data, government ID scans, insurance cards, intake forms, policy numbers, claims and benefits information, patient balances, medical record numbers, dates of service, and diagnoses. UTS says complete medical records, medical images, credit card numbers, and bank account details were not involved. No group has claimed the UTS attack. It is unconnected to UHSP.
Why It Matters
UHSP is the counterfactual the ransomware economy depends on not existing. Healthcare and higher education both operate under acute pressure to pay: patient safety, semester continuity, and thin IT staffing all push toward the fastest restoration path. A seven-figure demand answered with a tested restore is the outcome that removes the attacker's leverage entirely.
Comparitech's H1 2026 education roundup puts that in economic terms. It recorded 104 ransomware attacks on education in H1 2026, down 13 percent from 120 in H2 2025, but with K-12 attacks falling 26 percent while higher education rose more than eight percent. Only 36 of the 104 were confirmed by the targeted entity. Median ransom demand reached $420,620, up 53 percent from $275,000 in H2 2025. LockBit made nine attack claims against education in the period, behind The Gentlemen and Qilin at 15 each. Roughly 693,000 records were breached across the confirmed attacks.
The cost of the alternative path is visible elsewhere. The Houston Chronicle reports that the University of St. Thomas, hit by ransomware at the start of the fall 2025 semester with servers down for over a week, received preliminary approval in late May 2026 to settle a class action offering affected students, staff and alumni three years of credit monitoring plus $100 to $4,500 each. The settlement is not an admission of liability and the university denies the allegations. Comparitech also notes Mount Royal University in Canada, attacked June 17, still disrupted more than a month later, with CMD Organization claiming 10 TB stolen.
LockBit itself remains operational. Undercode News reports that on August 16, 2026, ThreatMon attributed a new victim listing to LockBit 5, the German-headquartered engineering firm TECOSIM, alongside a Qilin listing for Spoonful of Comfort. That is an unverified leak-site claim from a single OTHER-tier source and the outlet itself cautions that a listing proves neither successful breach nor data theft. It is included only as evidence that the brand is still posting victims three years after the UHSP intrusion, through law enforcement disruption and rebrands.
The Attack Technique
Lewis attributes the initial foothold to a compromised personal device, which Healthcare Innovation frames as an argument for securing end-user endpoints rather than treating personally owned hardware as out of scope. The published excerpt does not detail how that device was compromised, how access was escalated, or how long the attackers dwelled before deploying the encryptor.
Two response-side details are worth extracting as tradecraft. First, out-of-band communication was necessary during the incident, which implies the attackers had reach into or over normal corporate messaging. Second, the tertiary backup tier survived because it was fully isolated and Object Lock immutability was in place. LockBit affiliates routinely hunt and delete backups before encrypting; a tier the attacker's credentials could reach would have failed here.
For contrast, UTS has publicly named neither an actor nor an initial access vector, saying only that it detected unauthorized activity in its commercial data center, engaged a forensic firm, and notified law enforcement.
What Organizations Should Do
- Build a third backup tier the production domain cannot touch. Isolated and offsite is the property that mattered at UHSP, not the vendor. If the credentials that run your servers can delete a backup, that backup does not count in your recovery plan.
- Turn on immutability and verify it. Object Lock or equivalent write-once retention should be enabled and its retention window should exceed your realistic detection-to-recovery timeline. Confirm the setting is actually applied per bucket, not assumed.
- Test restores on a schedule and time them. Lewis's recurring point is that backups only counted because they had been tested and validated. An untested backup is an untested hypothesis. Record restore duration per system so leadership can weigh recovery time against a ransom demand with real numbers.
- Extend endpoint controls to personally owned devices. The UHSP foothold was a personal device. Either enroll and monitor them or deny them access to systems that matter, and enforce phishing-resistant MFA on every remote entry point.
- Stand up out-of-band comms before you need them. Pre-provision an independent messaging and conferencing channel, distribute the contact tree on paper or to personal accounts, and rehearse it. Deciding this mid-incident is how responders end up coordinating over infrastructure the attacker is reading.
- Scope your business associates. Six of the top ten healthcare breaches reported this year hit business associates, per HIPAA Journal, as did half of the largest healthcare breaches on record. UTS alone touches 3.8 million people through 4,500 clinics. Inventory which vendors hold your data, and do not wait on the delayed HIPAA Security Rule update, now expected from OCR by July 2027, to impose contractual security requirements yourself.
Sources: LockBit Took Down UHSP’s Systems. Its Backups Brought Them Back HC... | Intrusion at US healthcare software provider puts 3.8M people's dat... | Unlimited Technology Systems breach impacts 3.8 million people | Patient Data Exposed in Cybersecurity Incident at Ohio Revenue Cycl... | LockBit 5 and Qilin Allegedly Add New Victims as Ransomware Pressur... | Education Ransomware Roundup: H1 2026 stats on attacks, ransoms, an... | Zach Lewis | St. Thomas to settle data breach lawsuit. Here's how to file a claim