It usually starts quietly. A nurse cannot open a file, a screen shows a strange message, or the EHR runs slowly and then stops. Ransomware attacks on healthcare organizations can lock systems and demand payment, and they often start outside business hours. What you do in the first hour will not solve everything, but it can limit the damage and make recovery faster.
This walkthrough is meant to be printed and kept with your emergency binder. Adapt it to your organization and rehearse it before you need it.
The goal is to stop the spread without destroying evidence.
Tell staff to stop using affected computers. Do not keep clicking or trying to open files.
Disconnect affected devices from the network by unplugging the network cable or turning off Wi-Fi
Do not shut down or restart unless your IT provider instructs you to, because memory can hold useful information
Do not delete ransom notes or files. Photograph the screen instead.
If you cannot tell which devices are affected, isolate the network segment or ask IT to do so
If you are the first person to notice, call your IT provider by phone right away rather than sending an email, since email may be unavailable or compromised.
Your incident response plan should name who is in charge. Typical roles include:
Incident lead: Usually the administrator or a designated executive
Technical lead: Your IT provider or internal IT manager
Clinical lead: The director of nursing or equivalent, who manages care during downtime
Compliance or privacy officer: Handles HIPAA assessment and notifications
Communications contact: Speaks to staff, families and media
Start a written log. Record times, actions, names and decisions. This record is valuable for insurers, regulators and your own review later.
Resident care continues, so every facility needs a downtime plan on paper. Make sure it is easy to find.
Printed medication administration records or a recent printout of current orders
Paper forms for charting, incident reports and admissions
Phone lists for physicians, pharmacies, families and key vendors
Manual processes for call lights and door access if those systems are affected
A way to communicate with staff if email and phones are down, such as a group call tree
The director of nursing should take charge of care continuity while IT works on technical response.
Cyber insurance: Many policies require prompt notice and may provide a response hotline and approved vendors. Check your policy before hiring outside help, since using non-approved vendors can affect coverage.
Legal counsel: Consider involving an attorney experienced in healthcare privacy early, so that communications and investigation are handled appropriately.
Law enforcement: Federal agencies such as the FBI accept reports of ransomware, and CISA provides guidance and resources. Reporting is encouraged.
Your EHR and key vendors: Let them know so they can watch for suspicious connections from your accounts.
Preserve evidence: Keep logs, affected machines and backups untouched where possible.
Your technical team should try to answer these:
Which systems and accounts are affected?
Are backups intact and isolated from the infected environment?
Is there evidence that data was copied out of the network?
How did the attacker get in, and is that entry point still open?
Which credentials should be reset?
Do not restore from backups until the intrusion path is understood, or you may reinfect the environment.
HHS guidance states that when ePHI is encrypted by ransomware, a breach is presumed to have occurred unless a risk assessment shows a low probability that the information was compromised. Your compliance officer should begin that assessment promptly. The Breach Notification Rule sets deadlines, including notification to affected individuals without unreasonable delay and no later than 60 days after discovery, so start the clock and document your analysis.
Payment is a complex decision involving legal, financial and ethical factors, and law enforcement generally discourages it. Paying does not guarantee data recovery or that stolen data will not be released. Make that decision with counsel, your insurer and leadership, not in a panic.
Write and rehearse the plan at least once a year
Keep printed contact lists and downtime forms
Maintain tested, isolated backups
Use multi-factor authentication and keep systems patched
Know your insurance requirements
UnityCare IT helps healthcare organizations build and practice incident response plans, and provides support during real events. If you have not run a tabletop exercise, we can help you set one up.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172