Backups That Survive Ransomware: The 3-2-1 Rule for Care Facilities

When ransomware hits a care facility, the first question is always the same: do we have a backup? The second question, which people discover too late, is whether the backup still works and whether the attacker could reach it. Modern ransomware groups know that backups are the thing standing between you and a ransom payment, and they often try to delete or encrypt them first.

A solid backup strategy is not complicated, but it has a few specifics that matter. Here is how to think about it.

The 3-2-1 rule

The long-standing guideline is simple:

Keep at least three copies of your important data

Store them on at least two different types of media or systems

Keep at least one copy offsite

Many security teams now add two more points: keep one copy immutable or offline, and verify that it can be restored. That brings the rule to 3-2-1-1-0, where the last number stands for zero restore errors.

Why the offsite copy matters

A fire, a flood, a tornado or a burst pipe that damages your server closet will also damage a backup drive sitting next to it. Offsite copies, whether in a secure cloud service or a geographically separate location, protect against local disasters.

Why immutability matters

An immutable backup cannot be changed or deleted for a set retention period, even by an administrator. If an attacker steals an admin password, they still cannot wipe those copies. Many cloud backup services and some on-site appliances offer this feature. An offline copy, such as a drive that is disconnected after each backup, achieves a similar result, though it takes more manual discipline.

What to back up

Think beyond the EHR. A typical facility depends on several systems:

Your EHR or EMR data, including any locally hosted components or interfaces

File shares with policies, schedules, forms and resident documents

Email and calendars, if hosted in a cloud service (cloud providers keep their own copies, but those are not a substitute for a backup you control)

Accounting, payroll and billing systems

Server configurations, firewall settings and network device configurations

Phone system and door access system configurations

If you use a cloud EHR, ask the vendor what they back up, how often and what your recovery options are. Do not assume.

Set recovery goals, not just backup schedules

Two terms help you decide how much protection you need:

Recovery point objective (RPO): how much data can you afford to lose? If your last backup is from last night, you may lose a full day of documentation.

Recovery time objective (RTO): how long can you operate without the system? Most facilities can work on paper for a short period, but not for a week.

Ask your administrator and director of nursing how long paper downtime procedures can realistically last. That answer should drive your backup frequency and your recovery plan.

Test your restores

An untested backup is a hope, not a plan. Many organizations discover failed or incomplete backups only during an emergency. A simple testing routine:

Each month, restore a handful of random files from backup to a separate location and confirm they open.

Each quarter, restore a full server or application into a test environment and confirm it starts.

At least once a year, run a recovery exercise that includes people, not just technology: who makes the call, who contacts the EHR vendor, who informs families, and how long it really takes.

Keep a written record of each test. This also supports the HIPAA contingency planning requirements, which call for a data backup plan, a disaster recovery plan and an emergency mode operation plan.

Protect the backup system itself

Use separate credentials for backup administration and require MFA

Do not leave backup storage mapped as a drive on regular workstations

Alert on failed jobs and on unusual deletions

Encrypt backups, both in transit and at rest, so a lost drive or a cloud breach does not become a HIPAA incident

Limit who can change retention settings

Common mistakes

Relying on a single external drive attached to the server

Backing up only the server and forgetting about cloud applications

Never checking the backup status reports

Keeping the only offsite copy on a staff member's home computer

Assuming that backup equals disaster recovery. Backups are data. Recovery also requires hardware, networking, licenses and people who know the steps.

Next steps

If you cannot answer when your last successful restore test happened, that is your starting point. UnityCare IT designs and monitors backup and recovery for healthcare organizations, including immutable offsite copies and documented restore tests, and we can review your current setup and show you where the gaps are.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034