In the first hours of a cyber incident, the instinct is to fix things: wipe the infected computer, rebuild the server, reset every password. Those steps are often necessary. They can also destroy evidence that your organization may need later, if a family files a claim, an insurer asks questions, a regulator opens a review or you want to pursue the attacker. A legal hold is the formal way to balance recovery with preservation.
This post explains in plain language what a legal hold is and how it applies to logs, email and devices. It is general information, not legal advice. Your attorney should decide when a hold is required and what it covers.
A legal hold, sometimes called a litigation hold, is a written instruction to preserve information that may be relevant to a reasonably anticipated claim, investigation or dispute. It suspends normal deletion practices, such as automatic email cleanup or the recycling of backup media, for the covered information. Legal counsel usually issues the notice, identifies who must follow it and tells them what to keep.
The duty to preserve can arise before any lawsuit is filed. A significant breach involving resident information, a ransomware event that disrupts care or a notice from a regulator may all trigger it. When in doubt, ask counsel early.
Investigators need logs and device images to understand how the attacker got in.
Insurers may request evidence to process a claim.
Regulators, such as HHS in a HIPAA matter, may ask what happened and how you responded.
If a claim is filed, destroyed records can create serious penalties and damage your credibility, even if the loss was accidental.
Your own review depends on records that still exist.
Many logs are overwritten automatically, sometimes within days. Act quickly to export or extend retention for:
Firewall, router and VPN logs.
Email and Microsoft 365 or Google audit and sign-in logs.
Server, domain controller and endpoint security logs.
EHR access and audit logs.
Door-access, camera and phone system logs where relevant.
Backup system logs.
Store exported logs in a protected location with limited access, and record who exported what and when.
Suspend automatic deletion for the mailboxes of people involved, such as IT staff, administrators, compliance leaders and affected employees. Include shared mailboxes, chat and text conversations about the incident. Remind staff not to delete messages, even if they seem unimportant.
Do not wipe, reimage or discard affected computers, servers or phones until counsel and your response team say it is safe.
Where possible, have a forensic specialist capture an image before cleanup.
Label devices, record who handled them and keep them secure. A written chain of custody shows that evidence was not altered.
Keep affected cloud accounts and their data, instead of deleting them.
Your incident timeline and notes.
Communications with vendors, insurers, law enforcement and agencies.
Policies, risk analyses and training records in effect at the time.
Residents still need care, so systems must come back. Good planning allows both:
Ask counsel and your forensic provider before major cleanup.
Take images or snapshots first, and then restore from clean backups.
Document each recovery action, including what was deleted or rebuilt and why.
Rebuild on new equipment where possible, and keep the old devices intact.
Do not delay care or safety measures for preservation. Document the decision and its reasons.
Backups that would normally be overwritten may hold evidence. Pause rotation for relevant backups, and keep copies from before and after the incident. Review automatic deletion settings in email, file storage and messaging platforms, and extend them for covered systems.
Counsel should send a clear written notice to the people and departments involved, explain what to keep, and say whom to contact with questions. Track acknowledgments. Remind people periodically, and add new employees or systems as the matter evolves.
A hold continues until counsel releases it in writing. Do not resume routine deletion on your own. When the matter closes, return to your normal retention schedule and record the release.
Include legal hold steps in your incident response plan.
Know the retention period of your key logs, and lengthen them where the cost is reasonable.
Identify a forensic provider and an attorney with cyber experience before you need them.
Practice the process in a tabletop exercise.
UnityCare IT helps healthcare and senior-living organizations in Oklahoma, Texas and Arkansas set sensible log retention, preserve evidence during incidents and coordinate with counsel and forensic specialists. If your plan does not mention legal holds yet, we can help you add them.
An outsourced IT department with proactive maintenance and one number to call.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172