It is 6:40 on a Tuesday morning. A nurse reports that the screen at the station shows a message demanding payment, and files will not open. Within minutes, other computers show the same thing. What happens in the next hour will affect how long you are down, how much data is at risk and how well you can show regulators you acted responsibly.
The best time to decide what to do is before it happens. This walkthrough gives administrators and directors of nursing a plan they can print and keep at the nurses' station.
Signs of ransomware include files that suddenly will not open, renamed files with odd extensions, a ransom note on screen, or many computers failing at once.
Do this immediately:
Tell IT or your managed provider right away. Use the phone, not email, since email may be affected.
Disconnect affected computers from the network. Unplug the network cable or turn off Wi-Fi. Do not shut the machines down unless instructed, because shutting down can erase useful evidence in memory.
Stop people from plugging in USB drives or moving files between machines.
If you can identify the first affected computer, note which one it was. That helps investigators trace the entry point.
Resident safety comes first. Switch to your downtime procedures.
Move to paper charting and paper medication administration records, using the printed copies you should keep for this purpose.
Confirm that call lights, door controls and any life-safety systems are still working. Check whether any of these depend on the affected network.
Identify residents with time-sensitive needs, such as insulin or treatments that require current orders, and make sure the nurse in charge knows the plan.
Notify your medical director and department heads.
If you do not have a downtime kit with printed census, medication records and contact lists, make that your first improvement once this is over.
Your IT provider or security team
Your cyber insurance carrier, since many policies require prompt notice and may provide a response team
Legal counsel familiar with healthcare privacy
Your compliance or privacy officer
Many cyber insurance policies direct you to a specific incident response firm. Using someone else can affect coverage, so check the policy now, not during an emergency.
Do not wipe or reimage machines yet.
Keep logs from firewalls, email and servers.
Write down a timeline: who noticed what and when.
Have your IT team verify that backups are intact and disconnected from the infected network. Attackers often try to destroy backups first. Do not restore until the intruder is removed, or they may encrypt everything again.
Do not pay in a hurry. Payment does not guarantee recovery and may raise legal issues. This decision belongs with counsel, your insurer and leadership, after experts have weighed in.
Do not communicate with the attacker without guidance from professionals.
Do not announce details publicly or on social media until you know the facts and have legal guidance.
Do not assume it is only one computer. Treat it as network-wide until proven otherwise.
Ransomware that encrypts electronic protected health information is presumed to be a breach under HHS guidance, unless you can demonstrate a low probability that the information was compromised. That means a documented risk assessment is needed. If a breach of unsecured PHI is confirmed, the Breach Notification Rule requires notice to affected individuals without unreasonable delay and no later than 60 days after discovery, plus notice to HHS and, for larger breaches, the media. Your counsel and privacy officer should lead this analysis.
A printed contact list with after-hours numbers for IT, your insurer, counsel and your EHR vendor
Downtime forms and a tested paper process
Offline or immutable backups, with restore tests
A one-page plan with named roles
Multi-factor authentication on email and remote access
Practice the plan once a year with a short tabletop exercise.
UnityCare IT works with long-term care and healthcare organizations to build incident plans, test backups and respond when something goes wrong. If you do not have a one-page ransomware plan yet, we can help you write one.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172