First Signs of Ransomware in a Care Facility and What to Do Next

It usually starts quietly. A nurse cannot open a file, a screen shows a strange message, or the EHR runs slowly and then stops. Ransomware attacks on healthcare organizations can lock systems and demand payment, and they often start outside business hours. What you do in the first hour will not solve everything, but it can limit the damage and make recovery faster.

This walkthrough is meant to be printed and kept with your emergency binder. Adapt it to your organization and rehearse it before you need it.

Minutes 0 to 10: Recognize and contain

The goal is to stop the spread without destroying evidence.

Tell staff to stop using affected computers. Do not keep clicking or trying to open files.

Disconnect affected devices from the network by unplugging the network cable or turning off Wi-Fi

Do not shut down or restart unless your IT provider instructs you to, because memory can hold useful information

Do not delete ransom notes or files. Photograph the screen instead.

If you cannot tell which devices are affected, isolate the network segment or ask IT to do so

If you are the first person to notice, call your IT provider by phone right away rather than sending an email, since email may be unavailable or compromised.

Minutes 10 to 30: Activate your team

Your incident response plan should name who is in charge. Typical roles include:

Incident lead: Usually the administrator or a designated executive

Technical lead: Your IT provider or internal IT manager

Clinical lead: The director of nursing or equivalent, who manages care during downtime

Compliance or privacy officer: Handles HIPAA assessment and notifications

Communications contact: Speaks to staff, families and media

Start a written log. Record times, actions, names and decisions. This record is valuable for insurers, regulators and your own review later.

Switch to downtime procedures

Resident care continues, so every facility needs a downtime plan on paper. Make sure it is easy to find.

Printed medication administration records or a recent printout of current orders

Paper forms for charting, incident reports and admissions

Phone lists for physicians, pharmacies, families and key vendors

Manual processes for call lights and door access if those systems are affected

A way to communicate with staff if email and phones are down, such as a group call tree

The director of nursing should take charge of care continuity while IT works on technical response.

Minutes 30 to 60: Notify and preserve

Cyber insurance: Many policies require prompt notice and may provide a response hotline and approved vendors. Check your policy before hiring outside help, since using non-approved vendors can affect coverage.

Legal counsel: Consider involving an attorney experienced in healthcare privacy early, so that communications and investigation are handled appropriately.

Law enforcement: Federal agencies such as the FBI accept reports of ransomware, and CISA provides guidance and resources. Reporting is encouraged.

Your EHR and key vendors: Let them know so they can watch for suspicious connections from your accounts.

Preserve evidence: Keep logs, affected machines and backups untouched where possible.

Questions for the first hour

Your technical team should try to answer these:

Which systems and accounts are affected?

Are backups intact and isolated from the infected environment?

Is there evidence that data was copied out of the network?

How did the attacker get in, and is that entry point still open?

Which credentials should be reset?

Do not restore from backups until the intrusion path is understood, or you may reinfect the environment.

HIPAA considerations

HHS guidance states that when ePHI is encrypted by ransomware, a breach is presumed to have occurred unless a risk assessment shows a low probability that the information was compromised. Your compliance officer should begin that assessment promptly. The Breach Notification Rule sets deadlines, including notification to affected individuals without unreasonable delay and no later than 60 days after discovery, so start the clock and document your analysis.

Decisions about paying

Payment is a complex decision involving legal, financial and ethical factors, and law enforcement generally discourages it. Paying does not guarantee data recovery or that stolen data will not be released. Make that decision with counsel, your insurer and leadership, not in a panic.

Prepare before it happens

Write and rehearse the plan at least once a year

Keep printed contact lists and downtime forms

Maintain tested, isolated backups

Use multi-factor authentication and keep systems patched

Know your insurance requirements

UnityCare IT helps healthcare organizations build and practice incident response plans, and provides support during real events. If you have not run a tabletop exercise, we can help you set one up.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172