Memorial Day weekend is a time for remembrance, family and, for many care facilities, a lighter administrative presence. Fewer managers are on site, the IT contact may be out of town and the office staff who normally notice something odd are home. Cybercriminals understand this. Government agencies, including CISA and the FBI, have repeatedly warned that ransomware actors favor holidays and weekends, when an intrusion is more likely to go unnoticed until it is well under way.
Care facilities cannot close for the weekend, so preparation matters. Here is a checklist for the days before any holiday.
Name the administrator on call and the backup.
Confirm your IT provider's after-hours number works, and that someone in the building knows how to reach them.
Post a printed contact sheet at the nurses station and in the administrator's office. It should work even if the network is down.
Confirm that the on-call person knows the incident reporting steps.
Disable accounts for people who left recently, including agency and contract staff.
Check that vendor remote access is off unless a scheduled maintenance window requires it.
Verify that administrator accounts are protected by multi-factor authentication.
Patch internet-facing systems, firewalls and VPN appliances before the holiday, not on the way out the door. Avoid risky changes on the last working day, because problems may not be noticed until the weekend.
Confirm the last backup completed successfully.
Review that backup alerts are going to someone who will actually see them over the weekend.
If possible, verify that an offline or immutable copy is current.
Holiday messages are a good disguise for phishing. Remind staff about fake shipping notices, e-cards, gift card requests and payment change requests. A short note from the administrator on Friday is enough.
Staff should know to report immediately if they see:
Unexpected multi-factor prompts they did not request.
Files that will not open or have unusual extensions.
A ransom message or unfamiliar pop-up.
Programs or computers that are unusually slow.
Messages from supposed executives asking for urgent payments or gift cards.
Make sure paper forms, printed medication lists and resident census reports are current and in each unit's downtime kit. Update them on Friday, not after an outage begins.
If your organization closes parts of the building, consider shutting down non-essential systems and computers that are not needed. Do not shut down servers or devices unless your IT team has approved it.
Follow your incident response plan:
Isolate affected computers from the network.
Call your IT provider and cyber insurance hotline.
Start downtime procedures.
Keep a written log of actions and times.
Notify leadership.
Do not wait until Tuesday to call for help. Every hour matters.
When staff return, do a quick review:
Check logs and alerts that accumulated over the weekend.
Look for failed backup jobs or unusual login attempts.
Ask staff whether anything seemed odd, and encourage reporting even if it turned out to be nothing.
Apply any updates postponed for the holiday.
Every long weekend, including July 4, Labor Day, Thanksgiving, Christmas and New Year's Day, deserves the same short checklist. Put it on the calendar as a recurring task and assign an owner.
Many of your staff are working the holiday, caring for residents while their families gather without them. A clear plan means they do not also have to handle an IT emergency alone.
UnityCare IT provides after-hours monitoring and support for healthcare facilities across Oklahoma, Texas and Arkansas. If you would like a pre-holiday readiness review, or want to confirm that your after-hours coverage works as you expect, we are glad to help.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172