The First 60 Minutes After You Suspect a Cyberattack

It usually starts with something small. A nurse cannot open the electronic record. Files on the shared drive have strange extensions. A note appears on a screen demanding payment. In the first hour after you suspect a cyberattack, the decisions you make shape how long the disruption lasts and how much damage it causes. This walkthrough is meant for administrators and directors of nursing, not just technical staff, so that the right steps happen even if the IT person is not in the building.

Before anything else: have a plan on paper

Most of what follows only works if the basics were prepared in advance. Keep a printed incident contact sheet at the front desk and in the administrator's office, because in an outage you may not be able to reach email or a shared drive. It should list your IT provider, your cyber insurance claim line, your attorney, your leadership team and your EMR vendor support contact.

Minutes 0 to 10: Recognize and report

Stop and report. Whoever notices the problem should call the IT provider or the designated incident contact right away, by phone, not email.

Write down the time and what was observed: messages on screen, affected computers, what the person was doing.

Do not delete anything and do not try to fix it by rebooting everything. Evidence in memory and logs can disappear.

Take a photo of any ransom message with a phone, making sure no resident information is visible.

Minutes 10 to 25: Contain the damage

Containment means stopping the problem from spreading while preserving evidence.

Disconnect affected computers from the network. Unplug the network cable or turn off Wi-Fi. Do not power them off unless your IT provider says so, because shutting down can erase useful evidence.

Do not log in with administrator accounts on suspected machines, because attackers can capture those credentials.

Isolate servers and backups if your IT provider advises it. Make sure backup storage is disconnected from the affected network.

Change passwords from a clean device, starting with administrator and email accounts, once IT confirms which systems are safe.

The instinct to restart everything is strong. Resist it until you have guidance.

Minutes 25 to 40: Keep residents safe

Resident care continues whether the computers work or not.

Move to your downtime procedures. That means paper medication administration records, printed census and care plan summaries, and manual call and communication methods if the nurse call system is affected.

Assign someone, often the DON or a designee, to run care continuity while the administrator and IT handle the incident.

Check that life-safety systems such as fire alarm, door access and nurse call are working, and confirm with the vendors if they connect to the affected network.

An emergency preparedness plan that CMS requires of long-term care facilities should already address loss of critical systems. Now is the time to use it.

Minutes 40 to 60: Notify and document

Call your cyber insurance carrier. Many policies require prompt notice and may provide a breach coach, forensic investigators and negotiators. Do not hire outside responders without checking the policy first.

Notify your attorney, who can advise on privilege and legal duties.

Contact your EMR vendor so they can check their side and advise on restoring access.

Start an incident log. Record who did what and when, including decisions and phone calls.

Limit internal communication to need-to-know, using phones or personal text messages if email may be compromised, and avoid discussing details on systems the attacker may be watching.

What to avoid

Paying a ransom or negotiating without legal and insurer involvement.

Wiping and rebuilding machines before evidence is preserved.

Telling the media or families before you know the facts and have legal guidance.

Assuming it is over because the screen looks normal.

After the first hour

The next steps include determining scope, identifying whether PHI was accessed or acquired, restoring from clean backups, and assessing HIPAA breach notification duties. Under the HIPAA Breach Notification Rule, an impermissible use or disclosure of PHI is presumed to be a breach unless a risk assessment shows a low probability that the information was compromised, and notices to affected individuals are due without unreasonable delay and no later than 60 days after discovery. Your attorney will guide those decisions.

Practice before you need it

A short tabletop exercise, where leadership talks through a scenario like this one for an hour, exposes gaps in phone numbers, authority and downtime supplies. UnityCare IT helps healthcare organizations build incident response plans and run these exercises, and we can assist with the technical response if an incident occurs.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034