The First 60 Minutes of a Ransomware Attack: A Walkthrough

It usually starts with something small. A nurse cannot open a document. A shared drive is slow. Then a text file appears on a desktop explaining that your data has been encrypted and demanding payment. In a care facility, where patient safety depends on access to records, the pressure to act immediately is intense. The first hour matters, and a clear sequence helps you avoid the mistakes people make under stress.

This walkthrough is general guidance for administrators. Your own incident response plan, your cyber insurance policy and your IT partner should drive the details.

Minutes 0 to 10: Recognize and contain

Do not panic and do not delete anything

Note what you see, including the ransom note, the time and the affected computers. Take photos with a phone if screens are affected.

Isolate affected devices

Disconnect infected computers from the network by unplugging the network cable and turning off Wi-Fi. Do not power them off unless instructed, because shutting down can destroy information that investigators need. If you cannot tell which computers are affected, disconnecting a whole network segment or switch may be justified.

Do not log in with administrator accounts on infected machines

Attackers may capture those credentials. Use a clean device for any administrative work.

Minutes 10 to 20: Call the right people

Call in this order, using phone numbers kept somewhere that does not depend on your network, such as a printed sheet:

Your IT provider or security team.

Your cyber insurance carrier, which often has a breach hotline and may require you to use approved response firms before costs are covered.

Your administrator and compliance officer.

Legal counsel, if you have one.

Do not contact the attackers yet. Negotiation decisions involve legal and law enforcement considerations and should not be made in the first hour.

Minutes 20 to 40: Protect patient care

Switch to downtime procedures

Activate paper charting, printed medication administration records and manual processes. If you keep a recent printout or read-only copy of medication lists and resident census, this is when it earns its keep. Clinical staff should know this is a patient safety situation, not an IT inconvenience.

Protect backups

Check whether backup systems are connected to the affected network. If they are not yet encrypted, disconnect them from the network so they cannot be reached. Backups are the most valuable thing you have right now.

Communicate carefully

Give staff a short, factual message by phone, text or in person: the systems are down, use downtime procedures, do not turn on or connect affected computers, do not discuss on social media.

Minutes 40 to 60: Preserve evidence and start the paperwork

Keep a written log of every action, with times and names.

Preserve logs from firewalls, email and servers. Ask your IT provider to capture copies.

Change passwords for key accounts from a known clean device, especially email and administrator accounts, once guided by your responders.

Consider whether law enforcement should be contacted. Many organizations report ransomware to the FBI or CISA, and your insurer or counsel can guide you.

HIPAA considerations

Under HHS guidance, ransomware that encrypts electronic protected health information is generally presumed to be a breach unless you can demonstrate a low probability that the data was compromised. The Breach Notification Rule gives you up to 60 days from discovery to notify affected individuals, but you should move faster when you can, and some states and contracts set shorter deadlines. Document your risk assessment carefully.

Mistakes to avoid

Rebooting or wiping machines before evidence is saved.

Restoring from backup before the attacker is out of the network. They may simply encrypt again.

Paying without legal and insurance guidance.

Using the same compromised email system to coordinate the response.

Having no printed contact list.

Prepare before it happens

The best first hour is one you have already rehearsed. Keep a printed incident contact sheet, a downtime kit and tested offline backups, and practice the plan once a year.

UnityCare IT helps healthcare organizations write response plans, test backups and run tabletop exercises, and can be reached when something goes wrong. If you do not yet have a written plan, that is a good first project.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172