It is 6:15 a.m. and the night nurse reports that the EHR will not open and a message on the screen demands payment. Whatever happens in the next hour will do a lot to decide whether this is a bad day or a bad month. Most people have never lived through it, which is exactly why a written plan matters.
This walkthrough describes what a calm, effective first hour looks like for a long-term care or clinic environment. It is not a substitute for your own incident response plan, but it can help you write one.
A ransom note on screens or in folders
Files that cannot be opened and have strange new extensions
Systems that suddenly stop working across several computers
Alerts from security software about mass file changes
Disconnect affected devices from the network by unplugging the network cable or turning off Wi-Fi. Do not shut them down if you can avoid it, because memory may hold evidence useful to investigators.
Do not try to pay, negotiate or reply to the attacker.
Do not delete files or run cleanup tools.
Write down the time, what was seen, who saw it and which devices are affected.
If you are unsure whether to disconnect a system that supports care, such as nurse call or medication dispensing, ask your IT provider quickly, but do not wait long. Spread is usually faster than people expect.
Have a one-page contact list on paper, because your email and phones may be down:
Your IT provider or security team, with an after-hours number
Your administrator and the person designated as Security Officer
Your cyber insurance carrier's incident hotline, if you have a policy. Many policies require notice early and may have approved response firms, and using others can affect coverage.
Your EHR vendor
Legal counsel
Notify law enforcement as appropriate. The FBI and CISA both accept reports of ransomware incidents, and your insurer or counsel can guide you.
Care continues regardless of IT. Your emergency operations and downtime procedures matter now.
Switch to paper downtime forms for medication administration records, orders and assessments. Keep printed or offline copies of current medication lists and resident census in a known location.
Ensure staff know that a system outage is not a reason to delay medications or treatments.
Use phones, radios or in-person communication if systems for nurse call or messaging are affected.
Brief shift supervisors so everyone gives consistent information to staff and families.
CMS emergency preparedness requirements for long-term care facilities expect plans that cover loss of normal operations, and a cyber event is a good test of them.
Keep affected systems powered and isolated. Do not wipe or reimage anything yet.
Preserve logs, screenshots and ransom notes. Photographs of screens work well.
Identify which systems are unaffected and confirm that backups are intact and disconnected from the network.
Change passwords for administrator and email accounts, using a clean device, because attackers often steal credentials before encrypting files.
Assign roles: one person leads the incident, one handles communications, one keeps a timeline, and one coordinates with clinical leadership.
Under HIPAA, ransomware that encrypts protected health information is generally presumed to be a breach unless you can show a low probability that the information was compromised, based on a documented risk assessment. HHS has published guidance on this. You will need to document:
What data was on affected systems
Whether the attacker accessed or copied it
Whether it was encrypted in a way that rendered it unreadable
What evidence supports your conclusion
Breach notification deadlines can run as short as sixty days from discovery, so start your timeline from the moment you learned of the incident.
Waiting for confirmation before calling your insurer or IT provider
Rebooting everything to see if it fixes the problem
Restoring from backup before you know how the attacker got in, which can lead to reinfection
Sending sensitive messages on a compromised email system
Making public statements before facts are known
The best time to learn who calls whom is during a drill. Run a short tabletop exercise at least once a year using a scenario like this one. Keep the contact list and downtime forms updated and stored where you can reach them without the network.
UnityCare IT helps healthcare organizations write incident response plans, assemble contact sheets, and respond when something goes wrong. If you do not have a written plan, we can help you build one that fits your facility.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034