When ransomware hits a care facility, the first question is usually "Do we have backups?" The better question is "Do we have backups that the attackers could not touch and that we have actually tested?" Modern ransomware operators know that backups are your way out, so they often hunt for them first. A backup sitting on a server in the same network, using the same admin credentials, can be encrypted or deleted along with everything else.
A long-standing guideline for resilient backups is the 3-2-1 rule:
Three copies of your data: the original plus two backups
Two different types of storage, such as a local appliance and cloud storage
One copy off-site, away from your building and your primary network
Many security professionals now extend it to 3-2-1-1-0: one copy that is offline or immutable, and zero errors when you test restores.
An immutable backup cannot be changed or deleted for a set retention period, even by an administrator. An offline or air-gapped copy is physically or logically disconnected. Either way, an attacker who steals your administrator password still cannot erase that copy.
Ask your IT provider directly: if an attacker had domain administrator credentials today, could they delete every backup we have? The answer should be no.
Think beyond the EMR database.
Servers hosting clinical, billing and scheduling applications
File shares used by administration, dietary, activities, maintenance and the business office
Email and collaboration data, which cloud providers often do not back up in the way people assume
Configuration for firewalls, switches and wireless controllers
Phone system, door access and camera system settings
Cloud application data where the vendor does not guarantee recovery
If your EMR is hosted by the vendor, ask what recovery commitments exist, how often backups are taken and how you can export your own copy of records.
Two numbers shape your backup design:
Recovery point objective (RPO): how much recent data you can afford to lose. A nightly backup means you could lose up to a day of work.
Recovery time objective (RTO): how long you can operate without the system before care is affected.
Administrators and clinical leaders should help set these, because IT cannot decide alone what is acceptable. A facility might decide, for instance, that its EMR needs to be back within hours while the activities shared drive can wait days. Your downtime procedures should cover the gap.
A backup job that reports "success" can still produce an unusable copy. Schedule routine restore tests:
Restore a few random files monthly and confirm they open
Restore a full server to an isolated environment at least annually
Time the process and compare it to your RTO
Document results and fix anything that failed
A facility that has never restored a full system is guessing about its recovery time.
Use separate credentials for backup management, with multi-factor authentication
Do not join backup servers to the same domain if you can avoid it
Encrypt backups in transit and at rest, which supports HIPAA safeguards for ePHI
Monitor backup jobs and alert on failures or unusual deletions
Keep retention long enough to recover from problems discovered late, since attackers sometimes sit in networks for days or weeks
The Security Rule requires a contingency plan, including a data backup plan, a disaster recovery plan and an emergency mode operation plan. Testing and revising these plans is an addressable specification. Documenting your backups, tests and results demonstrates that you take these requirements seriously. CMS emergency preparedness requirements for long-term care facilities also expect plans for continuing operations and protecting records.
Where are our backups stored and who can delete them?
Is at least one copy immutable or offline?
When was our last full restore test, and what did it show?
How long would it take to restore our EMR connectivity and file shares?
Are cloud email and file storage included?
UnityCare IT designs and monitors backup and recovery systems for healthcare organizations and can run a restore test with your team so you know exactly what to expect. If you are unsure whether your backups would survive an attack, we can help you find out before you need them.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172