Backups That Survive Ransomware: The 3-2-1 Rule Explained

When ransomware hits a care facility, the first question is usually "Do we have backups?" The better question is "Do we have backups that the attackers could not touch and that we have actually tested?" Modern ransomware operators know that backups are your way out, so they often hunt for them first. A backup sitting on a server in the same network, using the same admin credentials, can be encrypted or deleted along with everything else.

The 3-2-1 rule

A long-standing guideline for resilient backups is the 3-2-1 rule:

Three copies of your data: the original plus two backups

Two different types of storage, such as a local appliance and cloud storage

One copy off-site, away from your building and your primary network

Many security professionals now extend it to 3-2-1-1-0: one copy that is offline or immutable, and zero errors when you test restores.

Why the extra "1" matters

An immutable backup cannot be changed or deleted for a set retention period, even by an administrator. An offline or air-gapped copy is physically or logically disconnected. Either way, an attacker who steals your administrator password still cannot erase that copy.

Ask your IT provider directly: if an attacker had domain administrator credentials today, could they delete every backup we have? The answer should be no.

What to back up

Think beyond the EMR database.

Servers hosting clinical, billing and scheduling applications

File shares used by administration, dietary, activities, maintenance and the business office

Email and collaboration data, which cloud providers often do not back up in the way people assume

Configuration for firewalls, switches and wireless controllers

Phone system, door access and camera system settings

Cloud application data where the vendor does not guarantee recovery

If your EMR is hosted by the vendor, ask what recovery commitments exist, how often backups are taken and how you can export your own copy of records.

Define recovery goals

Two numbers shape your backup design:

Recovery point objective (RPO): how much recent data you can afford to lose. A nightly backup means you could lose up to a day of work.

Recovery time objective (RTO): how long you can operate without the system before care is affected.

Administrators and clinical leaders should help set these, because IT cannot decide alone what is acceptable. A facility might decide, for instance, that its EMR needs to be back within hours while the activities shared drive can wait days. Your downtime procedures should cover the gap.

Test restores, not just backups

A backup job that reports "success" can still produce an unusable copy. Schedule routine restore tests:

Restore a few random files monthly and confirm they open

Restore a full server to an isolated environment at least annually

Time the process and compare it to your RTO

Document results and fix anything that failed

A facility that has never restored a full system is guessing about its recovery time.

Protect the backup system itself

Use separate credentials for backup management, with multi-factor authentication

Do not join backup servers to the same domain if you can avoid it

Encrypt backups in transit and at rest, which supports HIPAA safeguards for ePHI

Monitor backup jobs and alert on failures or unusual deletions

Keep retention long enough to recover from problems discovered late, since attackers sometimes sit in networks for days or weeks

HIPAA connection

The Security Rule requires a contingency plan, including a data backup plan, a disaster recovery plan and an emergency mode operation plan. Testing and revising these plans is an addressable specification. Documenting your backups, tests and results demonstrates that you take these requirements seriously. CMS emergency preparedness requirements for long-term care facilities also expect plans for continuing operations and protecting records.

Questions to ask your IT provider

Where are our backups stored and who can delete them?

Is at least one copy immutable or offline?

When was our last full restore test, and what did it show?

How long would it take to restore our EMR connectivity and file shares?

Are cloud email and file storage included?

UnityCare IT designs and monitors backup and recovery systems for healthcare organizations and can run a restore test with your team so you know exactly what to expect. If you are unsure whether your backups would survive an attack, we can help you find out before you need them.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172