Ransomware is software that locks your files and demands payment to release them. In a care facility the stakes go beyond inconvenience. If staff cannot reach medication records, care plans or resident contact information, care continues but under stress. Most organizations never rehearse what to do when the screens change, so the first hour is often chaotic.
This walkthrough describes a calm, practical sequence. Your own plan should be written down and shared before you need it.
Ransomware does not always announce itself with a ransom note. Early signs can include:
Files that will not open or have strange new extensions
A message on screen demanding payment
Servers or shared drives suddenly unreachable
Many computers acting slowly at once
Security software alerts or disabled protection
If more than one of these appears, treat it as an incident until proven otherwise.
The goal is to stop the spread.
Disconnect affected computers from the network. Unplug the network cable or turn off Wi-Fi. Do not shut the computer down unless your IT provider tells you to, because memory may hold useful evidence.
Tell people to stop working on affected systems. Use a phone call or runner if email is unreliable.
Call your IT provider or incident contact immediately, using a number saved outside your computer systems.
If you cannot tell which machines are affected, IT staff may recommend isolating the whole network segment or disconnecting the internet connection.
Notify the administrator and your incident lead.
Switch to downtime procedures for resident care, such as paper medication records and printed contact lists, if your systems are affected.
Preserve a record of what staff saw, with times, screenshots or photos of ransom notes.
Identify what is affected: EHR, file shares, email, phones, building systems.
If your electronic records are hosted by a vendor in the cloud, check whether they are still reachable from an unaffected device. That matters for care continuity.
A good response involves several parties:
Your IT provider to investigate and contain
Your cyber insurance carrier, if you have a policy. Many require prompt notice and may provide approved response firms. Check your policy before hiring anyone yourself.
Legal counsel, especially one familiar with HIPAA
Law enforcement. The FBI and CISA accept reports of ransomware incidents and can offer guidance.
Keep a written log of every action and time. It helps later with insurance, regulators and lessons learned.
Do not restart or wipe machines before they are examined.
Do not log into systems with administrator accounts from infected computers.
Do not contact the attackers or decide to pay without insurer, legal and law enforcement involvement. Payment does not guarantee recovery and may carry legal considerations.
Do not discuss the incident publicly or on unsecured email.
Under the HIPAA Breach Notification Rule, ransomware that encrypts protected health information is generally treated as a potential breach unless a documented risk assessment shows a low probability that the information was compromised. HHS guidance on ransomware explains this. Notification deadlines can begin when the incident is discovered, so involve your privacy officer and counsel early.
Your ability to recover without paying rests on backups that are recent, separate from your main network and tested. Backups stored on the same network can be encrypted too. We discuss this further in our article on the 3-2-1 backup rule. Recovery also requires cleaning or rebuilding systems so the attacker cannot return, which is why investigation matters before restoring.
The best response is one you have practiced. Before an incident:
Keep a printed contact list for IT, insurer, counsel and key vendors.
Write downtime procedures for medication administration, admissions and communication.
Know where your backups are and who can restore them.
Run a short tabletop exercise once a year with leadership.
If you do not have a written incident response plan, a one-page version is a strong first step. UnityCare IT helps healthcare organizations build response plans, test backups and run tabletop exercises. If you would like help preparing, we are glad to start with a short conversation.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172