The first few days of a ransomware incident are loud. Phones ring, outside responders arrive, and everyone is focused on stopping the spread. Then comes the second week, which is quieter and in some ways harder. Adrenaline fades, systems are only partly back, and staff are tired. Leaders often expect things to be nearly normal by now. They usually are not, and knowing what to expect helps you plan staffing and communicate honestly.
This post describes what the days after containment typically look like. Every incident is different, so treat this as a guide to realistic expectations, not a schedule.
Systems rarely return all at once. Responders and IT staff generally restore in an order based on resident care and business needs: network and internet first, then identity systems, then clinical applications, then everything else. Each system must be rebuilt or restored, scanned for remaining threats and tested before users return.
Expect a mix of "working," "working slowly" and "not yet" for several days. Publish a simple status list so staff know what is available and what is not, and update it at set times.
Even with good backups, restoring takes time. Large data sets take hours or days to copy, and each restored system must be verified. If some backups were also encrypted or were not recent, you may be recovering older data and reconstructing the gap by hand. Ask your recovery team for realistic time estimates, and plan for them to change.
Responders will want to be confident the attacker is gone before reconnecting everything. That commonly involves:
Resetting passwords across the organization, including service and administrator accounts
Rebuilding or reimaging affected computers instead of trying to clean them
Closing the entry point, such as a compromised remote access account or an unpatched system
Monitoring closely for signs the attacker has returned
Staff will need new credentials and possibly new multi-factor authentication enrollment. Plan help desk capacity for that.
Many facilities spend week two still working partly on paper. Make sure the downtime procedures hold up over days, not hours:
Keep printed census, medication records and key contacts current.
Assign someone to collect paper documentation for later entry.
Define how the backlog will be entered once systems return, and who verifies it.
Track entries so nothing is missed or duplicated.
Clinical safety comes first. Check in with nurses and aides about what is working and what is creating risk.
People who worked long hours in week one are now tired. Rotate shifts if possible, provide meals and breaks and acknowledge the effort. Mistakes rise with exhaustion, and so does the risk of shortcuts that undo security progress.
While technical teams restore systems, other tracks proceed in parallel:
Your counsel and compliance officer assess whether protected health information was involved and what notifications apply under HIPAA and state law
Your insurer may require documentation and approvals for certain expenses
Forensic work continues to determine what was accessed
Regulators, partners and families may ask questions
Keep a log of decisions and costs. Route outside statements through the designated spokesperson and review them with counsel.
Silence breeds rumors. Give staff short, regular updates: what is restored, what is not, what to do in the meantime. For residents and families, be honest and calm, and avoid speculation about causes or data exposure until facts are confirmed.
Third-party connections, such as your electronic health record vendor, pharmacy and labs, may need to be re-established or verified. Contact each, confirm what they have seen and agree on when connections resume.
Do not delay basic fixes until a long project plan is approved. Prioritize multi-factor authentication, patching the known weakness, tested backups stored separately from the network and better monitoring. These steps reduce the chance of a repeat.
Once things stabilize, schedule a blameless review to document lessons and assign actions. Capture notes while memories are fresh, including what worked.
By the end of week two, many organizations are mostly operating but still cleaning up loose ends: backlog entry, remaining systems, lingering access problems. Complete recovery can take longer. Pace yourself and your team accordingly.
We help healthcare and senior-living organizations in Oklahoma, Texas and Arkansas prepare for this phase with tested backups and written downtime plans, and we assist with recovery coordination when an incident occurs.
Security monitoring, HIPAA safeguards, backups and staff training for healthcare and small businesses.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172