It usually starts with something small. A nurse cannot open a document. A shared drive is slow. Then a text file appears on a desktop explaining that your data has been encrypted and demanding payment. In a care facility, where patient safety depends on access to records, the pressure to act immediately is intense. The first hour matters, and a clear sequence helps you avoid the mistakes people make under stress.
This walkthrough is general guidance for administrators. Your own incident response plan, your cyber insurance policy and your IT partner should drive the details.
Note what you see, including the ransom note, the time and the affected computers. Take photos with a phone if screens are affected.
Disconnect infected computers from the network by unplugging the network cable and turning off Wi-Fi. Do not power them off unless instructed, because shutting down can destroy information that investigators need. If you cannot tell which computers are affected, disconnecting a whole network segment or switch may be justified.
Attackers may capture those credentials. Use a clean device for any administrative work.
Call in this order, using phone numbers kept somewhere that does not depend on your network, such as a printed sheet:
Your IT provider or security team.
Your cyber insurance carrier, which often has a breach hotline and may require you to use approved response firms before costs are covered.
Your administrator and compliance officer.
Legal counsel, if you have one.
Do not contact the attackers yet. Negotiation decisions involve legal and law enforcement considerations and should not be made in the first hour.
Activate paper charting, printed medication administration records and manual processes. If you keep a recent printout or read-only copy of medication lists and resident census, this is when it earns its keep. Clinical staff should know this is a patient safety situation, not an IT inconvenience.
Check whether backup systems are connected to the affected network. If they are not yet encrypted, disconnect them from the network so they cannot be reached. Backups are the most valuable thing you have right now.
Give staff a short, factual message by phone, text or in person: the systems are down, use downtime procedures, do not turn on or connect affected computers, do not discuss on social media.
Keep a written log of every action, with times and names.
Preserve logs from firewalls, email and servers. Ask your IT provider to capture copies.
Change passwords for key accounts from a known clean device, especially email and administrator accounts, once guided by your responders.
Consider whether law enforcement should be contacted. Many organizations report ransomware to the FBI or CISA, and your insurer or counsel can guide you.
Under HHS guidance, ransomware that encrypts electronic protected health information is generally presumed to be a breach unless you can demonstrate a low probability that the data was compromised. The Breach Notification Rule gives you up to 60 days from discovery to notify affected individuals, but you should move faster when you can, and some states and contracts set shorter deadlines. Document your risk assessment carefully.
Rebooting or wiping machines before evidence is saved.
Restoring from backup before the attacker is out of the network. They may simply encrypt again.
Paying without legal and insurance guidance.
Using the same compromised email system to coordinate the response.
Having no printed contact list.
The best first hour is one you have already rehearsed. Keep a printed incident contact sheet, a downtime kit and tested offline backups, and practice the plan once a year.
UnityCare IT helps healthcare organizations write response plans, test backups and run tabletop exercises, and can be reached when something goes wrong. If you do not yet have a written plan, that is a good first project.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172