Ransomware at Your Facility: What to Do in the First Hour

It is 6:40 on a Tuesday morning. A nurse calls the front desk because the charting computer shows a message demanding payment, and files that opened yesterday will not open now. What happens in the next sixty minutes will influence how long your facility is disrupted and how much resident information is exposed.

Nobody wants to practice this on a real day. This walkthrough is meant to be read ahead of time, shared with your leadership team, and turned into a one-page card.

Minutes 0 to 10: Contain

The first goal is to stop the spread, not to fix anything.

Disconnect affected computers from the network. Unplug the network cable or turn off Wi-Fi. Do not shut down or restart unless your IT provider tells you to, because memory can hold useful evidence.

Do not log in with administrator accounts on affected machines. Attackers often harvest those credentials.

Do not pay, reply to, or negotiate with the attacker yet. That decision belongs at the leadership level, with legal advice.

Take a photo of the ransom note with a phone rather than copying files from the computer.

Minutes 10 to 20: Call the Right People

Have these numbers printed and somewhere that does not depend on your network.

Your IT provider or helpdesk

The administrator and the director of nursing

Your cyber insurance carrier's incident hotline, if you have a policy, since many policies require prompt notice and may provide approved responders

Legal counsel familiar with healthcare privacy

The insurance call matters. Using vendors the carrier has not approved can sometimes affect coverage, so check before engaging outside responders.

Minutes 20 to 40: Switch to Downtime Procedures

Residents still need care while systems are down. This is where preparation pays off.

Activate your paper downtime forms for medication administration, vitals, and care notes.

Print or retrieve the most recent offline census, medication lists, allergy information and emergency contacts, if you keep downtime copies.

Brief charge nurses at each unit on what is working and what is not.

Assign someone to document the time of every decision and action. A written timeline is useful later for insurers, regulators and investigators.

Long-term care facilities already have emergency preparedness obligations under CMS requirements, and an IT outage fits naturally within an all-hazards approach to planning.

Minutes 40 to 60: Scope the Problem

With your IT provider, begin answering:

Which systems and sites are affected?

Are backups intact and offline or separate from the network?

Is the attacker still in the environment?

Was data copied out? Many ransomware groups steal data before encrypting it, which turns an outage into a potential breach.

Do not restore from backup until you are confident the attacker has been removed. Restoring into a compromised network can lead to reinfection.

Later That Day: Think About Reporting

Under HIPAA, a ransomware attack that encrypts protected health information is generally treated as a presumed breach unless you can demonstrate a low probability that the information was compromised, based on a documented risk assessment. That means notification clocks may start. Under the Breach Notification Rule, individuals must be notified without unreasonable delay and no later than 60 days after discovery, and breaches affecting 500 or more people also require notice to HHS and the media. Your attorney should guide these decisions. You may also consider reporting to the FBI or CISA, which accept reports of ransomware incidents.

What Makes This Easier

The facilities that recover fastest tend to have done a few things in advance:

Backups kept separate from the main network and tested for restore

Multi-factor authentication on email and remote access

A written incident response plan with names and phone numbers

Practiced downtime procedures on every unit

A current inventory of systems, so scoping goes faster

None of this is glamorous, but each item buys hours or days during a real event.

Build Your One-Page Card

Take the steps above and fit them on a single page: who to call, what to disconnect, where the paper forms are, and who documents decisions. Laminate it and keep copies at the administrator's desk, nursing stations and off-site.

UnityCare IT helps care organizations write and rehearse incident response plans, including tabletop exercises with administrators and clinical leaders. If your plan lives only in someone's head, we can help get it onto paper.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172