It usually begins with something small. A nurse cannot open a shared file. A screen shows a message demanding payment. A server is slow, and then the whole network stops responding. In a care setting, the pressure is immediate, because residents still need medications, meals and attention.
This walkthrough describes a sensible first hour. It is not a substitute for your written incident response plan, but it highlights the decisions that matter most. If you do not have a plan yet, use this as a starting point.
Anyone who sees ransom notes, files with strange extensions, or many systems failing at once should report immediately by phone, not email. Email may be unavailable or monitored by the attacker.
Keep the call simple:
Who is calling and from where
What was seen, and on which devices
When it started
Whether anyone clicked a link or opened an attachment just before
The person receiving the report should notify the administrator, the designated incident lead and your IT provider right away.
The goal is to stop spread. Typical containment steps include:
Disconnect affected computers from the network by unplugging the network cable or turning off Wi-Fi
Do not shut down or restart machines unless instructed, because volatile evidence may be lost
Disconnect shared drives and servers that appear affected
Isolate backup systems so they cannot be reached from infected machines
Disable compromised accounts if you know which ones are affected
Your IT provider may isolate segments remotely. Follow their direction and avoid doing too much on your own.
Continuity of care comes first. Activate downtime procedures:
Switch to paper medication administration records and charting forms
Pull printed census, allergy and medication lists if available
Use phones or radios for communication if the network phone system is down
Verify that nurse call and life-safety systems are working independently
Assign a staff member to document everything done on paper so it can be entered later
If the electronic health record is hosted by a vendor, contact them to confirm whether their systems are affected and whether it is safe to log in from unaffected devices.
Start an incident log immediately. Record:
Times of each observation and action
Names of people involved
Screenshots or phone photos of ransom notes and error messages
Which systems were affected and which were taken offline
Do not delete ransom notes or wipe systems. Evidence matters for insurance, law enforcement and investigation of what data may have been accessed.
In the first hour, you generally need to contact:
Your IT provider or security team, to lead technical response
Your cyber insurance carrier, since many policies require prompt notice and may provide approved response vendors; check your policy for the hotline
Legal counsel or compliance officer, to assess breach notification obligations under HIPAA
Leadership and your board or ownership, as appropriate
Law enforcement, such as the FBI field office or local authorities, which your counsel or insurer can help coordinate
CISA also offers resources and a reporting channel for ransomware incidents.
Do not pay or negotiate on your own. Decisions involving payment involve legal, insurance and regulatory considerations.
Do not restore from backups until the infection is contained and the source is understood, or you may reinfect systems.
Do not communicate publicly or with residents' families before leadership and counsel agree on messaging.
Do not assume the incident is limited to what you can see.
Under HIPAA, ransomware that encrypts electronic protected health information is generally treated as a presumptive breach unless a risk assessment demonstrates a low probability that the information was compromised. That determination should be made carefully, with documentation, and typically with counsel. The Breach Notification Rule sets deadlines that start when the incident is discovered.
Keep a printed incident contact list, including after-hours numbers
Store your insurance policy number and carrier hotline offline
Practice downtime procedures at least annually
Test restores from backups
Run a tabletop exercise so leaders know their roles
UnityCare IT helps healthcare organizations build incident response plans, run tabletop exercises and respond when something goes wrong. If you do not yet have a written plan with phone numbers on paper, we would be glad to help you create one.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034