Ransomware is malicious software that locks or steals data and demands payment. Healthcare organizations of every size have been affected, and the disruption to care can be severe. Yet in conversations with owners and administrators, the same misconceptions come up. Believing them can leave a small facility less prepared than it needs to be. Here are seven worth correcting.
Reality: Criminals do not usually pick a target by size. Many attacks are automated, scanning the internet for exposed systems or sending phishing emails by the thousands. A small facility with weaker defenses can be an easier target than a large one, and the data it holds is just as sensitive. Small operators also have fewer resources to absorb downtime, which makes them attractive to criminals expecting payment.
Reality: Traditional antivirus is one layer, and it is not enough alone. Attackers use stolen credentials, remote access tools and legitimate software that antivirus does not flag as malicious. Modern endpoint detection and response tools that watch for suspicious behavior and can isolate a computer are better suited, particularly when someone is watching the alerts.
Reality: Backups are essential, but attackers know it. They look for backup systems and try to delete or encrypt them first. Backups that are connected to the network with the same credentials as everything else can be wiped. Keep at least one copy offline or immutable, protect backup administration with separate credentials and MFA, and test restores. Also note that restoration takes time, and modern attacks often steal data before encrypting it, so restoring from backup does not remove the privacy issue.
Reality: Phishing is a common entry point, but not the only one. Attackers also exploit unpatched software on internet-facing systems, use stolen or guessed remote access credentials, and abuse vendor connections. Exposed remote desktop services without MFA have been a repeated cause of incidents. Protection requires patching, MFA, limiting what is exposed to the internet and monitoring, in addition to training.
Reality: Payment is no guarantee. Decryption tools sometimes work poorly or slowly, data may already have been stolen, and paying can mark you as willing to pay again. Federal agencies generally discourage paying ransom. There may also be legal considerations, including sanctions rules, so decisions about payment should involve legal counsel and the insurer. The better strategy is to be able to restore without paying.
Reality: Under HIPAA, an impermissible use or disclosure of PHI is presumed to be a breach unless a documented risk assessment shows a low probability of compromise. Ransomware that encrypts ePHI is treated by HHS guidance as a presumptive breach unless you can demonstrate otherwise. That triggers notification duties even if no one ever sees a resident's record.
Reality: During an incident, leaders make decisions about care continuity, communication, insurance, legal and law enforcement contact, and spending. Staff outside IT must know where the downtime forms are and who to call. Preparation is a leadership responsibility, including budget for protections and time for training and exercises.
No single control is enough, but these layers work together:
Multi-factor authentication on email, remote access and administrator accounts.
Patching of operating systems, applications, firewalls and other network devices, prioritizing anything reachable from the internet.
Endpoint detection and response with monitoring.
Email filtering and regular staff training.
Segmentation so an infection on one computer cannot reach everything, and so medical devices and guest Wi-Fi are separated from clinical systems.
Least privilege, meaning staff and IT accounts have only the access they need.
Tested backups with an offline or immutable copy.
An incident response plan with printed contacts, downtime procedures and defined decision makers.
Cyber insurance that fits your risk, with clear understanding of its requirements.
CISA and the HHS 405(d) program publish free guidance, including practices aimed at small healthcare organizations, that can serve as a checklist.
If you are not sure which of these layers you have, ask your IT provider to show you evidence, not just assurance. UnityCare IT helps care facilities assess their ransomware readiness and build practical protections that fit small teams and tight budgets.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172