It might begin with a nurse reporting that she cannot open files. Or an email from a vendor saying your account is sending spam. Or a ransom note on a server screen. However it starts, the first day of a suspected security incident is stressful, and decisions made in a hurry can make things worse. A written plan and a rehearsed team make a big difference.
This walkthrough outlines a practical sequence for administrators of small and mid-size care organizations. It is a general framework, not legal advice, and you should adapt it with your IT provider, legal counsel and insurer.
Take reports seriously. Staff should know to report odd behavior immediately, not wait until the end of a shift.
Notify the incident lead. Decide in advance who is in charge, often the administrator or compliance officer, with a backup.
Call your IT provider or security team using a phone number you already have.
Start a log. Record who reported what, when, and every action taken, with timestamps. This record becomes invaluable later.
The goal is to stop the problem from spreading without destroying evidence.
Disconnect affected computers from the network by unplugging the network cable or turning off Wi-Fi. Do not power them off unless instructed, since memory may hold useful evidence.
Disable compromised accounts and reset passwords from a clean device.
Isolate affected servers or network segments, as directed by your IT team.
Preserve backups. Make sure they are disconnected or protected so they are not encrypted too.
Do not wipe or reimage machines yet.
Avoid communicating about the incident over systems that may be compromised. Use phone calls or a separate channel if email is suspect.
Work with your IT team to determine what happened, which systems are affected and whether resident information may have been accessed.
Contact your cyber insurance carrier. Many policies require prompt notice and may provide a breach hotline, forensic firms and legal counsel. Following the policy process matters, because using unapproved vendors can affect coverage.
Engage legal counsel experienced in healthcare privacy.
Switch to downtime procedures for clinical care so residents are not affected. Make sure the nursing team has current medication records on paper.
Notify key leadership, such as the owner, board or corporate office.
Identify how the attacker got in, such as a phished credential or an exposed remote access service, so you can close the door.
Determine whether data was copied out. Ransomware groups often steal data before encrypting it.
Decide, with counsel and your insurer, how to handle any law enforcement contact. Many organizations report ransomware to the FBI or CISA.
Plan the recovery order based on your priorities.
Do not make decisions about paying a ransom in haste. It involves legal, ethical and practical considerations, and payment does not guarantee recovery.
Provide a short, calm update to staff on what is known, what is affected and what to do.
Prepare for questions from families, but avoid speculation. Coordinate wording with counsel.
Begin the HIPAA breach risk assessment. Under the Breach Notification Rule, an impermissible use or disclosure of protected health information is presumed to be a breach unless a risk assessment shows a low probability that the information was compromised. Notifications to individuals are required without unreasonable delay and no later than 60 days after discovery, and larger breaches have additional reporting duties to HHS and the media.
Preserve all logs, screenshots and notes.
Incident lead
Technical lead, internal or from your provider
Clinical continuity lead, often the DON
Communications lead
Legal and compliance contact
Scribe who keeps the timeline
Deleting files or wiping systems before evidence is preserved
Waiting to tell the insurer
Letting multiple people give conflicting messages
Forgetting the paper process for care
Declaring the incident over before the entry point is closed
The best time to build this plan is before an incident. UnityCare IT can help you write an incident response plan, run a tabletop exercise and provide support when something looks wrong.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172