The First Hour After Ransomware Hits a Care Facility

It usually begins with something small. A nurse cannot open a shared file. A screen shows a message demanding payment. A server is slow, and then the whole network stops responding. In a care setting, the pressure is immediate, because residents still need medications, meals and attention.

This walkthrough describes a sensible first hour. It is not a substitute for your written incident response plan, but it highlights the decisions that matter most. If you do not have a plan yet, use this as a starting point.

Minutes 0 to 10: Recognize and Report

Anyone who sees ransom notes, files with strange extensions, or many systems failing at once should report immediately by phone, not email. Email may be unavailable or monitored by the attacker.

Keep the call simple:

Who is calling and from where

What was seen, and on which devices

When it started

Whether anyone clicked a link or opened an attachment just before

The person receiving the report should notify the administrator, the designated incident lead and your IT provider right away.

Minutes 10 to 20: Contain

The goal is to stop spread. Typical containment steps include:

Disconnect affected computers from the network by unplugging the network cable or turning off Wi-Fi

Do not shut down or restart machines unless instructed, because volatile evidence may be lost

Disconnect shared drives and servers that appear affected

Isolate backup systems so they cannot be reached from infected machines

Disable compromised accounts if you know which ones are affected

Your IT provider may isolate segments remotely. Follow their direction and avoid doing too much on your own.

Minutes 20 to 35: Protect Resident Care

Continuity of care comes first. Activate downtime procedures:

Switch to paper medication administration records and charting forms

Pull printed census, allergy and medication lists if available

Use phones or radios for communication if the network phone system is down

Verify that nurse call and life-safety systems are working independently

Assign a staff member to document everything done on paper so it can be entered later

If the electronic health record is hosted by a vendor, contact them to confirm whether their systems are affected and whether it is safe to log in from unaffected devices.

Minutes 35 to 50: Preserve and Document

Start an incident log immediately. Record:

Times of each observation and action

Names of people involved

Screenshots or phone photos of ransom notes and error messages

Which systems were affected and which were taken offline

Do not delete ransom notes or wipe systems. Evidence matters for insurance, law enforcement and investigation of what data may have been accessed.

Minutes 50 to 60: Notify the Right People

In the first hour, you generally need to contact:

Your IT provider or security team, to lead technical response

Your cyber insurance carrier, since many policies require prompt notice and may provide approved response vendors; check your policy for the hotline

Legal counsel or compliance officer, to assess breach notification obligations under HIPAA

Leadership and your board or ownership, as appropriate

Law enforcement, such as the FBI field office or local authorities, which your counsel or insurer can help coordinate

CISA also offers resources and a reporting channel for ransomware incidents.

What Not to Do

Do not pay or negotiate on your own. Decisions involving payment involve legal, insurance and regulatory considerations.

Do not restore from backups until the infection is contained and the source is understood, or you may reinfect systems.

Do not communicate publicly or with residents' families before leadership and counsel agree on messaging.

Do not assume the incident is limited to what you can see.

HIPAA Considerations

Under HIPAA, ransomware that encrypts electronic protected health information is generally treated as a presumptive breach unless a risk assessment demonstrates a low probability that the information was compromised. That determination should be made carefully, with documentation, and typically with counsel. The Breach Notification Rule sets deadlines that start when the incident is discovered.

Prepare Before It Happens

Keep a printed incident contact list, including after-hours numbers

Store your insurance policy number and carrier hotline offline

Practice downtime procedures at least annually

Test restores from backups

Run a tabletop exercise so leaders know their roles

How UnityCare IT Can Help

UnityCare IT helps healthcare organizations build incident response plans, run tabletop exercises and respond when something goes wrong. If you do not yet have a written plan with phone numbers on paper, we would be glad to help you create one.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034