Imagine arriving at a facility and learning that nobody can open the EHR, and a message on a screen demands payment. Or perhaps the signs are quieter: an administrator's email sending strange messages, or a vendor reporting that suspicious logins came from your network. In either case, the decisions in the first day shape the outcome.
This walkthrough outlines a sensible sequence. It is not a substitute for your own plan or for professional incident response help, but it can guide leadership when emotions are high.
Designate one incident lead, usually the administrator or the security officer, who coordinates communication and decisions. Everyone else follows that person's direction.
Disconnect suspected computers from the network by unplugging the network cable or turning off Wi-Fi. Do not power them off unless instructed, since memory may hold evidence, and do not delete anything. If your IT provider is available, they may guide a more targeted isolation, such as disabling accounts or blocking traffic at the firewall.
Phone your IT provider, and your cyber insurance carrier's hotline if you have a policy. Many policies require prompt notice and may provide breach counsel and forensic specialists. Have those numbers printed, since email might be down.
Document what you see, including screenshots or phone photos of messages, with times
Identify which systems are affected, and which are still working
Preserve logs from firewalls, email and servers, and do not allow routine overwrites if possible
Reset credentials for affected users and administrators, from a known clean device
Check that backups are intact and disconnected from the affected network before attempting any restore
Avoid communicating about the incident using systems that may be compromised, such as the affected email
Start a written timeline right away. Record who did what and when.
Resident safety comes first. Switch to your downtime procedures:
Use paper medication administration records and treatment sheets, printed from your downtime kit
Confirm that critical medications, allergies and diet orders are communicated to the staff on every unit
Make sure the nurse call system and emergency equipment work. If they are connected to the network, verify them manually
Notify pharmacy and other partners of the situation through alternate channels
Assign staff to record events on paper so information can be entered later
The CMS emergency preparedness requirements ask long-term care facilities to maintain plans for continuing operations, and a cyber event is a good test of those plans.
Counsel experienced in healthcare privacy can advise on obligations and privilege. Forensic investigators can determine how attackers entered and whether data was taken. Your insurer may help arrange both.
Consider reporting to the FBI, including through the Internet Crime Complaint Center, or to your local FBI field office. CISA also accepts incident reports and offers resources.
Under the HIPAA Breach Notification Rule, an impermissible use or disclosure is presumed to be a breach unless a risk assessment shows a low probability that the information was compromised. That assessment considers the nature of the information, who obtained it, whether it was actually acquired or viewed, and how much the risk has been mitigated.
Brief staff with clear, factual updates and instructions on what to say if families ask
Prepare a short holding statement for families and the public, approved by counsel
Notify your state survey agency or others as required in your jurisdiction, with legal guidance
Build a restoration plan, starting with the most critical systems, and only restore after confirming the threat has been removed
Plan for further credential resets and monitoring
If a breach is confirmed, remember the timelines: notification to affected individuals without unreasonable delay and no later than sixty days after discovery, with HHS notification as required, and possibly media notice for larger breaches.
Do not pay a ransom without legal, insurance and law enforcement consultation
Do not wipe machines before evidence is preserved
Do not communicate with the attackers without guidance
Do not assume the problem is over when systems come back
Practice with a tabletop exercise and print your plan. UnityCare IT helps healthcare organizations build and test response plans and can support you during an incident. If you do not have a plan today, we can help you create one.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034