A Practical Guide to Backups That Survive Ransomware

Most administrators know they need backups. Far fewer can say, with confidence, whether those backups would still be usable after a ransomware attack. Modern ransomware does not just encrypt the files on your server. It actively hunts for backup drives, backup software and cloud sync folders, and tries to destroy or encrypt them first. A backup that sits on the same network, with the same credentials, is often just one more target.

For a skilled nursing or assisted living facility, the stakes are concrete: medication administration records, care plans, resident contact information and billing data all have to be available when you need them. This guide walks through how to build backups that hold up under pressure.

Start With What You Are Protecting

Before choosing any product, list the systems that would stop operations if they disappeared for a day, a week or a month. For most care organizations that list includes:

Your EHR or EMR, whether hosted or on-premises

File shares with policies, admissions paperwork and HR records

Email and calendar data

Accounting and payroll systems

Phone system configuration and eFax archives

Network device configurations, such as firewall and switch settings

If a vendor hosts your EHR, ask in writing how they back it up and how quickly they can restore. Do not assume that a cloud application is automatically backed up in a way that meets your needs.

Follow the 3-2-1 Rule, Then Add One More Layer

The classic guideline is three copies of your data, on two different types of media, with one copy stored off-site. It remains a sound starting point. Today it helps to add two refinements:

Immutable or offline copy. At least one copy should be impossible to change or delete for a set period, even by an administrator account. Many backup services call this immutability or object lock. An offline copy, such as a rotated drive that is disconnected from the network, achieves a similar goal.

Separate credentials. The account that manages backups should not be the same account staff use to log in each morning, and it should not be a domain administrator account that an attacker could steal.

Decide How Much Loss You Can Tolerate

Two terms matter here, and both can be explained without jargon:

Recovery point objective (RPO): how much recent data you can afford to lose. If backups run nightly, you could lose up to a day of work.

Recovery time objective (RTO): how long you can be without the system before it hurts resident care or finances.

Ask your leadership team and your clinical staff to set these numbers, not just IT. A DON may tell you that losing even a few hours of charting is unacceptable, which changes how often you back up and which system you protect first.

Protect the Backups Themselves

Treat backup infrastructure as a high-value target and secure it accordingly:

Require multi-factor authentication on the backup console and cloud storage account.

Encrypt backup data both in transit and at rest, which also supports HIPAA safeguards for electronic protected health information.

Restrict who can delete backups or change retention settings, and alert on any such change.

Keep backup servers off the general staff network where possible.

Keep software and firmware on backup devices patched.

Test Restores, Not Just Backup Jobs

A green checkmark in the backup dashboard only means the job finished. It does not prove that you can restore a working system. Build testing into your calendar:

Monthly: restore a few random files and confirm they open correctly.

Quarterly: restore a full server or application to a test environment and time how long it takes.

Annually: walk through a full disaster scenario with leadership, including who makes decisions and who calls vendors.

Write down the results, including failures. HIPAA's contingency plan requirements call for data backup, disaster recovery and emergency mode operation plans, and documented testing helps show that you take them seriously.

Common Mistakes to Avoid

Backing up only to a USB drive plugged into the server permanently

Relying on file sync tools, which will happily replicate encrypted files

Never checking whether new systems were added to the backup scope

Keeping the only recovery instructions on a server that would be down during an incident

Forgetting that staff laptops and tablets may hold local copies of important files

Getting Help

Backing up a care facility well takes planning, monitoring and regular restore testing, and many small organizations do not have anyone with the time to do it. UnityCare IT can review your current backups, identify gaps against your recovery goals and manage the ongoing testing so you know your data would be there when it counts.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172