Incident Response: The First 24 Hours After a Suspected Breach

It might begin with a nurse reporting that she cannot open files. Or an email from a vendor saying your account is sending spam. Or a ransom note on a server screen. However it starts, the first day of a suspected security incident is stressful, and decisions made in a hurry can make things worse. A written plan and a rehearsed team make a big difference.

This walkthrough outlines a practical sequence for administrators of small and mid-size care organizations. It is a general framework, not legal advice, and you should adapt it with your IT provider, legal counsel and insurer.

Hour 0 to 1: Recognize and Escalate

Take reports seriously. Staff should know to report odd behavior immediately, not wait until the end of a shift.

Notify the incident lead. Decide in advance who is in charge, often the administrator or compliance officer, with a backup.

Call your IT provider or security team using a phone number you already have.

Start a log. Record who reported what, when, and every action taken, with timestamps. This record becomes invaluable later.

Hour 1 to 4: Contain the Damage

The goal is to stop the problem from spreading without destroying evidence.

Disconnect affected computers from the network by unplugging the network cable or turning off Wi-Fi. Do not power them off unless instructed, since memory may hold useful evidence.

Disable compromised accounts and reset passwords from a clean device.

Isolate affected servers or network segments, as directed by your IT team.

Preserve backups. Make sure they are disconnected or protected so they are not encrypted too.

Do not wipe or reimage machines yet.

Avoid communicating about the incident over systems that may be compromised. Use phone calls or a separate channel if email is suspect.

Hour 4 to 8: Assess and Activate Support

Work with your IT team to determine what happened, which systems are affected and whether resident information may have been accessed.

Contact your cyber insurance carrier. Many policies require prompt notice and may provide a breach hotline, forensic firms and legal counsel. Following the policy process matters, because using unapproved vendors can affect coverage.

Engage legal counsel experienced in healthcare privacy.

Switch to downtime procedures for clinical care so residents are not affected. Make sure the nursing team has current medication records on paper.

Notify key leadership, such as the owner, board or corporate office.

Hour 8 to 16: Investigate and Plan

Identify how the attacker got in, such as a phished credential or an exposed remote access service, so you can close the door.

Determine whether data was copied out. Ransomware groups often steal data before encrypting it.

Decide, with counsel and your insurer, how to handle any law enforcement contact. Many organizations report ransomware to the FBI or CISA.

Plan the recovery order based on your priorities.

Do not make decisions about paying a ransom in haste. It involves legal, ethical and practical considerations, and payment does not guarantee recovery.

Hour 16 to 24: Communicate and Document

Provide a short, calm update to staff on what is known, what is affected and what to do.

Prepare for questions from families, but avoid speculation. Coordinate wording with counsel.

Begin the HIPAA breach risk assessment. Under the Breach Notification Rule, an impermissible use or disclosure of protected health information is presumed to be a breach unless a risk assessment shows a low probability that the information was compromised. Notifications to individuals are required without unreasonable delay and no later than 60 days after discovery, and larger breaches have additional reporting duties to HHS and the media.

Preserve all logs, screenshots and notes.

Roles to Assign Before You Need Them

Incident lead

Technical lead, internal or from your provider

Clinical continuity lead, often the DON

Communications lead

Legal and compliance contact

Scribe who keeps the timeline

Mistakes to Avoid

Deleting files or wiping systems before evidence is preserved

Waiting to tell the insurer

Letting multiple people give conflicting messages

Forgetting the paper process for care

Declaring the incident over before the entry point is closed

Prepare Now

The best time to build this plan is before an incident. UnityCare IT can help you write an incident response plan, run a tabletop exercise and provide support when something looks wrong.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172