For years, the standard advice about ransomware was simple: keep good backups and you can restore without paying. That advice is still valuable, but it is no longer complete. Many ransomware groups now steal data before they encrypt anything, then threaten to publish it if the victim does not pay. This is commonly called double extortion.
For healthcare organizations, the shift changes the nature of an incident. Restoring from backup solves the availability problem. It does nothing about the fact that information has already left your network.
A typical attack proceeds through stages:
Entry. The attackers gain access, often through stolen credentials, a phishing email or an unpatched internet-facing system.
Exploration. They move through the network, learn where data lives and obtain higher privileges.
Theft. They copy files, often to servers they control. This can take days or weeks and may be quiet.
Destruction of defenses. They disable security tools and try to delete or encrypt backups.
Encryption. They lock systems, usually timed for a weekend or holiday.
Extortion. They demand payment for a decryption tool and, separately, for a promise not to leak or sell the stolen data.
Some groups now skip encryption and focus on theft and extortion alone.
Encryption denies you access to your data. Theft exposes it. A restore brings your systems back, but the criminals still hold copies of what they took. The pressure to pay then centers on privacy rather than operations.
Records may include names, dates of birth, Social Security numbers, diagnoses, insurance information and financial details. Leaked information creates risks of identity theft and fraud and can be deeply distressing for residents and families.
If you restore without finding and closing how they got in, they may return. A rushed rebuild without investigation risks reinfection.
Even if an organization pays, there is no reliable way to verify that stolen data will be destroyed.
Under the HIPAA Breach Notification Rule, an impermissible acquisition, access, use or disclosure of unsecured protected health information is presumed to be a breach unless a documented risk assessment shows a low probability that the information was compromised. With data theft, that probability is typically not low.
Practical implications:
Investigate what was taken. Forensic analysis of logs and network traffic helps determine which systems and records were accessed or copied.
Notification clocks apply. Notice to affected individuals is required without unreasonable delay and within 60 days of discovery, and breaches affecting 500 or more people also require notice to HHS and, in certain cases, the media. Smaller breaches are reported to HHS annually.
State laws may differ. Some states have shorter deadlines or additional requirements.
Encryption of data at rest may provide a safe harbor in some circumstances, but only if the stolen data was truly unreadable to the attacker. If attackers obtained access through authorized accounts, encrypted data may still have been viewable.
Counsel should lead. Engage legal counsel early so investigation and communication decisions are made with privilege and care.
This is general information, not legal advice.
Enforce multi-factor authentication, especially for email and remote access
Patch internet-facing systems promptly
Train staff to recognize phishing
Limit administrative privileges
Segment the network so one compromised machine cannot reach everything
Restrict who can access sensitive file shares
Monitor for unusual large data transfers
Limit unnecessary storage of old data, because data you no longer keep cannot be stolen
Use endpoint detection and response with someone watching alerts
Retain logs long enough to investigate
Alert on new administrator accounts and disabled security tools
Keep at least one copy offline or immutable, isolate backup credentials from the main directory, and test restores regularly.
Maintain an incident response plan with contact details stored offline
Know your insurer's notice requirements and approved vendors
Draft notification templates in advance
Practice with a tabletop exercise
UnityCare IT helps healthcare organizations build layered defenses and response plans that assume both outcomes, locked systems and stolen data. Good backups remain essential. They are just one part of a larger answer.
Microsoft 365, cloud storage and tested backups with access controls built in.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172