Ransomware in a Nursing Home: The First 60 Minutes

It is 6:40 on a Monday morning and the nurse station computer shows a message demanding payment. Printers are spitting out pages. The EHR will not load. Nobody on the shift has seen this before. What happens in the next hour will decide how long you are down, how much data is at risk and how clean your recovery will be.

This walkthrough is written for administrators, DONs and facility managers, not just IT staff. Print it, adapt it and tape it inside your incident binder.

Minutes 0 to 10: Contain and call

Do this first

Isolate affected devices. Unplug the network cable or turn off Wi-Fi on the machine. Do not shut the computer down unless your IT provider says so, since memory can hold useful evidence.

Call your IT provider or incident lead. Phone, not email. Email may be compromised.

Note the time. Write down when the first symptom was noticed and who saw it.

Do not do this

Do not keep working on other computers "just to get through the shift" until IT confirms they are safe.

Do not try to delete the ransom note or run random cleanup tools.

Do not contact the attackers.

Minutes 10 to 30: Switch to downtime procedures

Resident care continues regardless of IT status. Activate your downtime plan:

Pull paper MARs, TARs and care plan printouts from the downtime kit

Confirm that medication cart contents and last-known orders are accurate

Assign one person to document everything done on paper with times, so it can be entered later

Notify department heads: nursing, dietary, business office, maintenance

If you do not have a downtime kit, building one this quarter is one of the best resilience investments you can make.

Minutes 30 to 60: Scope, preserve and escalate

Scope the problem

Your IT team will work to answer:

Which devices and servers show signs of infection?

Are backups intact and offline or immutable?

Were accounts used that have wide access?

Is there evidence that data left the network?

Preserve evidence

Ask IT to keep logs, screenshots and the ransom note. Avoid reimaging machines until you have confirmed what is needed for investigation and insurance.

Start the right calls

Cyber insurance carrier: many policies require early notice and use of approved responders. Check your policy before hiring anyone.

Legal counsel: especially one familiar with HIPAA.

Leadership and compliance officer: to begin the HIPAA breach risk assessment.

Law enforcement: the FBI and CISA accept reports of ransomware incidents, and reporting is generally encouraged.

What about paying?

That is a leadership, legal and insurance decision, not a front-line one. Payment does not guarantee working decryption or that stolen data will be deleted. The best position is one where you never have to consider it, because you have tested backups.

HIPAA considerations

Under HHS guidance, ransomware that encrypts protected health information is generally treated as a presumed breach unless a documented risk assessment shows a low probability that the information was compromised. That assessment looks at the nature of the data, who accessed it, whether it was actually acquired or viewed, and how well the risk was mitigated. Document your reasoning. The Breach Notification Rule has deadlines, so start the clock when the incident is discovered.

Prepare before it happens

The organizations that recover best did the boring work ahead of time:

Backups that are offline or immutable and have been test-restored

A printed contact sheet with IT, insurance, legal and key vendor numbers

Downtime kits for each unit, refreshed regularly

Multi-factor authentication on email, VPN and remote access

A tabletop exercise at least once a year, even a 45-minute one

Where to start

If you are not sure your plan would hold up at 6:40 on a Monday morning, a short readiness review can show gaps in backups, access and communication. UnityCare IT helps healthcare and senior-living teams build and rehearse incident plans so that the first hour is calm rather than chaotic.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034