Picture this hypothetical: it is two in the morning at a 100-bed skilled nursing facility. The night nurse cannot open the electronic health record, and a message on a workstation screen says the files are encrypted and demands payment. Nobody from administration is on site. What happens in the next sixty minutes will decide whether this is a bad night or a long disaster.
This walkthrough covers the first hour of a ransomware incident. It is not a substitute for a written plan, but it shows what a good plan contains.
The first goal is to stop the spread. Ransomware often moves across the network from one computer to others, so speed matters.
Disconnect affected computers from the network by unplugging the network cable or turning off Wi-Fi. Do not shut down the computer if you can avoid it, since memory can hold evidence, though disconnecting is the priority.
Do not log in to other systems with administrator accounts from affected machines.
Do not delete the ransom note, and photograph the screen with a phone.
Tell the nurse on duty to switch to paper downtime procedures right away.
Staff should know in advance that disconnecting a computer is allowed and expected. Hesitation is the biggest enemy here.
A good plan has a short call list taped to the wall at the nurse station and stored where it can be reached without the network.
Your IT provider's emergency line
The administrator and the person responsible for HIPAA privacy and security
Your cyber insurance carrier's incident hotline, if you have a policy
Legal counsel familiar with healthcare breaches
Your EHR vendor
Cyber insurance policies often require early notice and may provide access to forensic and legal help. Calling late can jeopardize coverage, so check your policy now rather than at 2 a.m.
Your IT team or provider should begin working out how far it has spread.
Which computers and servers show encrypted files?
Is the EHR, the phone system or the door access system affected?
Are backups intact and isolated from the infected network?
Is there any sign that data was copied out before encryption?
The last question matters because many attackers now steal data first, which can turn the event into a reportable breach under HIPAA.
Keep a written log with times, names and actions. Preserve logs and affected machines rather than wiping them. Wiping systems too soon destroys the information needed to determine whether protected health information was accessed.
At the same time, focus on care continuity:
Verify that medication administration records exist in paper form for the next pass
Confirm contact methods for physicians and pharmacies that do not depend on the affected systems
Use personal phones or a separate channel if the facility phone system is down
Do not pay or negotiate on your own. Decisions about ransom involve legal, law enforcement and insurance considerations.
Do not restore from backups until you know the attacker has been removed, or they may simply encrypt everything again.
Do not discuss the incident on social media or with outsiders before leadership and counsel agree on messaging.
Recovery typically involves forensic review, rebuilding systems from clean backups and resetting every credential. The HIPAA Breach Notification Rule requires covered entities to assess whether protected health information was compromised and, if so, to notify affected individuals without unreasonable delay and no later than 60 days after discovery. Counsel should guide that assessment.
The best time to learn this is a calm afternoon. Print the call list, run a tabletop exercise with night shift, test your backups and confirm who can authorize disconnecting systems.
UnityCare IT can help your team build an incident response plan, run a tabletop exercise and make sure your backups would hold up when you need them.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172