Ransomware Response: What to Do in the First Hour

Ransomware is software that locks your files and demands payment to release them. In a care facility the stakes go beyond inconvenience. If staff cannot reach medication records, care plans or resident contact information, care continues but under stress. Most organizations never rehearse what to do when the screens change, so the first hour is often chaotic.

This walkthrough describes a calm, practical sequence. Your own plan should be written down and shared before you need it.

Signs You May Be Under Attack

Ransomware does not always announce itself with a ransom note. Early signs can include:

Files that will not open or have strange new extensions

A message on screen demanding payment

Servers or shared drives suddenly unreachable

Many computers acting slowly at once

Security software alerts or disabled protection

If more than one of these appears, treat it as an incident until proven otherwise.

Minutes 0 to 15: Contain

The goal is to stop the spread.

Disconnect affected computers from the network. Unplug the network cable or turn off Wi-Fi. Do not shut the computer down unless your IT provider tells you to, because memory may hold useful evidence.

Do not delete anything and do not try to clean files yourself.

Tell people to stop working on affected systems. Use a phone call or runner if email is unreliable.

Call your IT provider or incident contact immediately, using a number saved outside your computer systems.

If you cannot tell which machines are affected, IT staff may recommend isolating the whole network segment or disconnecting the internet connection.

Minutes 15 to 30: Activate Your Plan

Notify the administrator and your incident lead.

Switch to downtime procedures for resident care, such as paper medication records and printed contact lists, if your systems are affected.

Preserve a record of what staff saw, with times, screenshots or photos of ransom notes.

Identify what is affected: EHR, file shares, email, phones, building systems.

If your electronic records are hosted by a vendor in the cloud, check whether they are still reachable from an unaffected device. That matters for care continuity.

Minutes 30 to 60: Bring In Help

A good response involves several parties:

Your IT provider to investigate and contain

Your cyber insurance carrier, if you have a policy. Many require prompt notice and may provide approved response firms. Check your policy before hiring anyone yourself.

Legal counsel, especially one familiar with HIPAA

Law enforcement. The FBI and CISA accept reports of ransomware incidents and can offer guidance.

Keep a written log of every action and time. It helps later with insurance, regulators and lessons learned.

What Not To Do

Do not restart or wipe machines before they are examined.

Do not log into systems with administrator accounts from infected computers.

Do not contact the attackers or decide to pay without insurer, legal and law enforcement involvement. Payment does not guarantee recovery and may carry legal considerations.

Do not discuss the incident publicly or on unsecured email.

HIPAA Considerations

Under the HIPAA Breach Notification Rule, ransomware that encrypts protected health information is generally treated as a potential breach unless a documented risk assessment shows a low probability that the information was compromised. HHS guidance on ransomware explains this. Notification deadlines can begin when the incident is discovered, so involve your privacy officer and counsel early.

Recovery Depends on Backups

Your ability to recover without paying rests on backups that are recent, separate from your main network and tested. Backups stored on the same network can be encrypted too. We discuss this further in our article on the 3-2-1 backup rule. Recovery also requires cleaning or rebuilding systems so the attacker cannot return, which is why investigation matters before restoring.

Prepare Before You Need It

The best response is one you have practiced. Before an incident:

Keep a printed contact list for IT, insurer, counsel and key vendors.

Write downtime procedures for medication administration, admissions and communication.

Know where your backups are and who can restore them.

Run a short tabletop exercise once a year with leadership.

Next Steps

If you do not have a written incident response plan, a one-page version is a strong first step. UnityCare IT helps healthcare organizations build response plans, test backups and run tabletop exercises. If you would like help preparing, we are glad to start with a short conversation.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172