It is 6:40 on a Tuesday morning. A nurse calls the front desk because the charting computer shows a message demanding payment, and files that opened yesterday will not open now. What happens in the next sixty minutes will influence how long your facility is disrupted and how much resident information is exposed.
Nobody wants to practice this on a real day. This walkthrough is meant to be read ahead of time, shared with your leadership team, and turned into a one-page card.
The first goal is to stop the spread, not to fix anything.
Disconnect affected computers from the network. Unplug the network cable or turn off Wi-Fi. Do not shut down or restart unless your IT provider tells you to, because memory can hold useful evidence.
Do not log in with administrator accounts on affected machines. Attackers often harvest those credentials.
Do not pay, reply to, or negotiate with the attacker yet. That decision belongs at the leadership level, with legal advice.
Take a photo of the ransom note with a phone rather than copying files from the computer.
Have these numbers printed and somewhere that does not depend on your network.
Your IT provider or helpdesk
The administrator and the director of nursing
Your cyber insurance carrier's incident hotline, if you have a policy, since many policies require prompt notice and may provide approved responders
Legal counsel familiar with healthcare privacy
The insurance call matters. Using vendors the carrier has not approved can sometimes affect coverage, so check before engaging outside responders.
Residents still need care while systems are down. This is where preparation pays off.
Activate your paper downtime forms for medication administration, vitals, and care notes.
Print or retrieve the most recent offline census, medication lists, allergy information and emergency contacts, if you keep downtime copies.
Brief charge nurses at each unit on what is working and what is not.
Assign someone to document the time of every decision and action. A written timeline is useful later for insurers, regulators and investigators.
Long-term care facilities already have emergency preparedness obligations under CMS requirements, and an IT outage fits naturally within an all-hazards approach to planning.
With your IT provider, begin answering:
Which systems and sites are affected?
Are backups intact and offline or separate from the network?
Is the attacker still in the environment?
Was data copied out? Many ransomware groups steal data before encrypting it, which turns an outage into a potential breach.
Do not restore from backup until you are confident the attacker has been removed. Restoring into a compromised network can lead to reinfection.
Under HIPAA, a ransomware attack that encrypts protected health information is generally treated as a presumed breach unless you can demonstrate a low probability that the information was compromised, based on a documented risk assessment. That means notification clocks may start. Under the Breach Notification Rule, individuals must be notified without unreasonable delay and no later than 60 days after discovery, and breaches affecting 500 or more people also require notice to HHS and the media. Your attorney should guide these decisions. You may also consider reporting to the FBI or CISA, which accept reports of ransomware incidents.
The facilities that recover fastest tend to have done a few things in advance:
Backups kept separate from the main network and tested for restore
Multi-factor authentication on email and remote access
A written incident response plan with names and phone numbers
Practiced downtime procedures on every unit
A current inventory of systems, so scoping goes faster
None of this is glamorous, but each item buys hours or days during a real event.
Take the steps above and fit them on a single page: who to call, what to disconnect, where the paper forms are, and who documents decisions. Laminate it and keep copies at the administrator's desk, nursing stations and off-site.
UnityCare IT helps care organizations write and rehearse incident response plans, including tabletop exercises with administrators and clinical leaders. If your plan lives only in someone's head, we can help get it onto paper.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172