Building Backups That Actually Survive a Ransomware Attack

Most care organizations have backups of some kind. The uncomfortable truth is that many of those backups are sitting on the same network, with the same credentials, as the systems they are meant to protect. When ransomware arrives, it often looks for backup files first and encrypts or deletes them before announcing itself.

A backup is only useful if it is clean, recent and restorable. This post walks through the design choices that make the difference, in terms an administrator or director of nursing can follow.

Start with the 3-2-1 idea

The long-standing rule of thumb is three copies of your data, on two different types of storage, with one copy kept offsite. For a skilled nursing or assisted living operator, that might look like:

The live data on your servers or in your cloud applications.

A local backup appliance or network storage device for fast restores.

A second copy in a separate cloud location that your everyday staff accounts cannot reach.

The key phrase is cannot reach. If a stolen administrator password can delete every copy, you effectively have one copy.

Make at least one copy immutable or offline

Immutable storage means that once a backup is written, it cannot be changed or deleted for a set retention period, even by an administrator. Many modern backup services offer this as a setting. An offline copy, such as a disconnected drive rotated weekly, achieves a similar goal with more manual effort.

Ask your vendor directly: if someone gets our domain administrator password tomorrow, can they erase our backups? The answer should be no.

Know what you are backing up

A common gap is the list of what is included. Walk through these questions with your IT provider:

Are file shares, databases and line-of-business servers all covered?

Are cloud applications such as email and document storage backed up separately? Software-as-a-service vendors protect their platform, but that does not always cover accidental deletion or an account takeover on your side.

Are the configuration files for firewalls, switches and Wi-Fi included? Rebuilding a network from memory is slow.

Is anything stored only on a laptop or a nurse station desktop?

Your EMR vendor may host and back up clinical records. Confirm in writing what they protect and what recovery time they commit to, then decide what you must cover yourself.

Decide your recovery targets

Two numbers drive every backup decision:

Recovery point objective: how much recent data you can afford to lose. If backups run nightly, you could lose a day of work.

Recovery time objective: how long you can operate without the system before care or billing suffers.

A facility might decide that the medication administration system needs to be back within hours, while an archive of old scanned documents can wait days. Writing these down turns a vague hope into a plan and helps justify the budget.

Test restores, not just backup jobs

A green checkmark on a backup report only means files were copied. It does not prove they can be restored. Schedule restore tests:

Monthly: restore a handful of random files and confirm they open.

Quarterly: restore a full server or database to a test location and verify the application works.

Annually: walk through a full disaster scenario with leadership, including how staff would document care on paper in the meantime.

Keep a short record of each test. This documentation also supports your HIPAA contingency planning requirements, which include data backup, disaster recovery and emergency mode operation plans.

Protect the backup system itself

Treat your backup console like a crown jewel:

Use unique, strong credentials, separate from everyday administrator accounts.

Require multi-factor authentication on the backup portal.

Limit who can change retention settings or delete jobs.

Alert on failed jobs and on any deletion activity.

Encrypt backups in transit and at rest, since they contain protected health information.

Plan for the day it happens

Even good backups take time to restore. Keep a printed copy of your recovery steps, vendor phone numbers and the order in which systems should come back. If your network is down, a document stored only on that network is not much help.

How UnityCare IT can help

UnityCare IT designs and monitors backup and recovery for long-term care and healthcare organizations across Oklahoma, Texas and Arkansas. If you are not sure your backups would survive an attack, we are glad to review your current setup and run a restore test with you.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172