Your First 24 Hours After a Suspected Cyberattack

Imagine arriving at a facility and learning that nobody can open the EHR, and a message on a screen demands payment. Or perhaps the signs are quieter: an administrator's email sending strange messages, or a vendor reporting that suspicious logins came from your network. In either case, the decisions in the first day shape the outcome.

This walkthrough outlines a sensible sequence. It is not a substitute for your own plan or for professional incident response help, but it can guide leadership when emotions are high.

Hours 0 to 1: Stop the spread and call for help

Do not panic or improvise

Designate one incident lead, usually the administrator or the security officer, who coordinates communication and decisions. Everyone else follows that person's direction.

Isolate affected devices

Disconnect suspected computers from the network by unplugging the network cable or turning off Wi-Fi. Do not power them off unless instructed, since memory may hold evidence, and do not delete anything. If your IT provider is available, they may guide a more targeted isolation, such as disabling accounts or blocking traffic at the firewall.

Call your response team

Phone your IT provider, and your cyber insurance carrier's hotline if you have a policy. Many policies require prompt notice and may provide breach counsel and forensic specialists. Have those numbers printed, since email might be down.

Hours 1 to 4: Scope and preserve

Document what you see, including screenshots or phone photos of messages, with times

Identify which systems are affected, and which are still working

Preserve logs from firewalls, email and servers, and do not allow routine overwrites if possible

Reset credentials for affected users and administrators, from a known clean device

Check that backups are intact and disconnected from the affected network before attempting any restore

Avoid communicating about the incident using systems that may be compromised, such as the affected email

Start a written timeline right away. Record who did what and when.

Hours 4 to 8: Keep care going

Resident safety comes first. Switch to your downtime procedures:

Use paper medication administration records and treatment sheets, printed from your downtime kit

Confirm that critical medications, allergies and diet orders are communicated to the staff on every unit

Make sure the nurse call system and emergency equipment work. If they are connected to the network, verify them manually

Notify pharmacy and other partners of the situation through alternate channels

Assign staff to record events on paper so information can be entered later

The CMS emergency preparedness requirements ask long-term care facilities to maintain plans for continuing operations, and a cyber event is a good test of those plans.

Hours 8 to 16: Bring in experts and assess exposure

Legal and forensic support

Counsel experienced in healthcare privacy can advise on obligations and privilege. Forensic investigators can determine how attackers entered and whether data was taken. Your insurer may help arrange both.

Law enforcement

Consider reporting to the FBI, including through the Internet Crime Complaint Center, or to your local FBI field office. CISA also accepts incident reports and offers resources.

Evaluate whether protected health information was involved

Under the HIPAA Breach Notification Rule, an impermissible use or disclosure is presumed to be a breach unless a risk assessment shows a low probability that the information was compromised. That assessment considers the nature of the information, who obtained it, whether it was actually acquired or viewed, and how much the risk has been mitigated.

Hours 16 to 24: Communicate and plan recovery

Brief staff with clear, factual updates and instructions on what to say if families ask

Prepare a short holding statement for families and the public, approved by counsel

Notify your state survey agency or others as required in your jurisdiction, with legal guidance

Build a restoration plan, starting with the most critical systems, and only restore after confirming the threat has been removed

Plan for further credential resets and monitoring

If a breach is confirmed, remember the timelines: notification to affected individuals without unreasonable delay and no later than sixty days after discovery, with HHS notification as required, and possibly media notice for larger breaches.

What not to do

Do not pay a ransom without legal, insurance and law enforcement consultation

Do not wipe machines before evidence is preserved

Do not communicate with the attackers without guidance

Do not assume the problem is over when systems come back

Prepare before you need it

Practice with a tabletop exercise and print your plan. UnityCare IT helps healthcare organizations build and test response plans and can support you during an incident. If you do not have a plan today, we can help you create one.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034