The 3-2-1 Backup Rule for Healthcare, Adapted for Ransomware

Backup advice has been repeated for decades: keep three copies of your data, on two different types of media, with one copy stored off-site. This 3-2-1 rule remains a solid starting point. But ransomware changed the threat. Attackers now deliberately look for backup systems, and a backup that sits on the same network with the same credentials can be encrypted or deleted along with everything else.

Here is how to apply 3-2-1 in a healthcare setting, and the extra steps that make it hold up against modern attacks.

What 3-2-1 means

Three copies of your data: the live production copy plus two backups

Two different media or storage types, such as a local disk appliance and cloud storage

One copy off-site, so a fire, flood, tornado or theft at the building does not destroy everything

For Oklahoma, Texas and Arkansas facilities, weather events make the off-site copy especially relevant.

The ransomware upgrade: 3-2-1-1-0

Many security practitioners extend the rule:

One copy that is offline, air-gapped or immutable, meaning it cannot be altered or deleted for a set period, even by an administrator

Zero errors, meaning backups are verified and restores are tested

Immutability is the key protection. Many cloud backup services and some on-premises appliances offer immutable storage with a retention lock.

What to back up

Do not assume everything is covered. List and confirm:

EHR or EMR data, whether hosted by a vendor or on your servers. If it is vendor-hosted, ask how they back up and how quickly they can restore, and get it in writing

File servers and shared drives

Email and cloud document storage. Cloud providers generally protect their platform, not your accidental deletions or ransomware, so a separate backup is worth considering

Databases for billing, scheduling and payroll

Configuration files for firewalls, switches and wireless controllers

Laptops used by staff who store files locally, if your policy allows that

Phone system and call recordings, if applicable

Decide your recovery targets

Two terms help set expectations:

Recovery point objective (RPO): how much data you can afford to lose, such as the last four hours of charting

Recovery time objective (RTO): how long you can be down before the impact becomes unacceptable

Ask clinical and business leaders to help set them, since IT alone cannot judge the operational impact. A system that holds medication administration records likely needs tighter targets than an archive of old policy documents.

Protect the backups themselves

Use separate credentials for backup systems, not the same administrator accounts used for daily work

Require multi-factor authentication for backup consoles

Restrict network access to the backup system

Encrypt backups, and store the keys safely and separately

Monitor for failed jobs and for unexpected deletions

Test restores regularly

A backup you have never restored is a hope, not a plan. Build a schedule:

Monthly: restore a few sample files and confirm they open

Quarterly: restore a full server or application to an isolated test environment

Annually: run a full recovery exercise that includes the clinical downtime procedures, and record how long each step took

Document the results, including problems. This documentation supports the HIPAA contingency planning requirements, which include data backup, disaster recovery and emergency mode operation plans.

Common mistakes

Backing up to a network drive that is permanently mounted and reachable from every computer

Relying on a single USB drive taken home by one person

Never checking whether backup jobs actually completed

Forgetting that recovery depends on having working hardware and internet capacity to restore

Keeping the only copy of the backup instructions on the server that failed

Where to begin

Start with a one-page inventory: what you back up, where copies live, who can delete them, and when you last tested a restore. UnityCare IT designs and manages backup and recovery for healthcare organizations, including immutable and off-site options. If you are unsure whether your backups could survive a ransomware event, we can help you find out.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034