Ransomware in the First Hour: A Plain-English Response Plan

It is 6:40 on a Tuesday morning. A nurse reports that the screen at the station shows a message demanding payment, and files will not open. Within minutes, other computers show the same thing. What happens in the next hour will affect how long you are down, how much data is at risk and how well you can show regulators you acted responsibly.

The best time to decide what to do is before it happens. This walkthrough gives administrators and directors of nursing a plan they can print and keep at the nurses' station.

Minute 0 to 10: Recognize and contain

Signs of ransomware include files that suddenly will not open, renamed files with odd extensions, a ransom note on screen, or many computers failing at once.

Do this immediately:

Tell IT or your managed provider right away. Use the phone, not email, since email may be affected.

Disconnect affected computers from the network. Unplug the network cable or turn off Wi-Fi. Do not shut the machines down unless instructed, because shutting down can erase useful evidence in memory.

Do not touch the ransom note or click anything in it.

Stop people from plugging in USB drives or moving files between machines.

If you can identify the first affected computer, note which one it was. That helps investigators trace the entry point.

Minute 10 to 30: Protect care

Resident safety comes first. Switch to your downtime procedures.

Move to paper charting and paper medication administration records, using the printed copies you should keep for this purpose.

Confirm that call lights, door controls and any life-safety systems are still working. Check whether any of these depend on the affected network.

Identify residents with time-sensitive needs, such as insulin or treatments that require current orders, and make sure the nurse in charge knows the plan.

Notify your medical director and department heads.

If you do not have a downtime kit with printed census, medication records and contact lists, make that your first improvement once this is over.

Minute 30 to 60: Assemble the team and preserve evidence

Call the right people

Your IT provider or security team

Your cyber insurance carrier, since many policies require prompt notice and may provide a response team

Legal counsel familiar with healthcare privacy

Your compliance or privacy officer

Many cyber insurance policies direct you to a specific incident response firm. Using someone else can affect coverage, so check the policy now, not during an emergency.

Preserve evidence

Do not wipe or reimage machines yet.

Keep logs from firewalls, email and servers.

Write down a timeline: who noticed what and when.

Check your backups

Have your IT team verify that backups are intact and disconnected from the infected network. Attackers often try to destroy backups first. Do not restore until the intruder is removed, or they may encrypt everything again.

What not to do

Do not pay in a hurry. Payment does not guarantee recovery and may raise legal issues. This decision belongs with counsel, your insurer and leadership, after experts have weighed in.

Do not communicate with the attacker without guidance from professionals.

Do not announce details publicly or on social media until you know the facts and have legal guidance.

Do not assume it is only one computer. Treat it as network-wide until proven otherwise.

Thinking about HIPAA

Ransomware that encrypts electronic protected health information is presumed to be a breach under HHS guidance, unless you can demonstrate a low probability that the information was compromised. That means a documented risk assessment is needed. If a breach of unsecured PHI is confirmed, the Breach Notification Rule requires notice to affected individuals without unreasonable delay and no later than 60 days after discovery, plus notice to HHS and, for larger breaches, the media. Your counsel and privacy officer should lead this analysis.

Before it happens: prepare these five things

A printed contact list with after-hours numbers for IT, your insurer, counsel and your EHR vendor

Downtime forms and a tested paper process

Offline or immutable backups, with restore tests

A one-page plan with named roles

Multi-factor authentication on email and remote access

Practice the plan once a year with a short tabletop exercise.

We can help

UnityCare IT works with long-term care and healthcare organizations to build incident plans, test backups and respond when something goes wrong. If you do not have a one-page ransomware plan yet, we can help you write one.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172