Ransomware Response: The First 60 Minutes, Step by Step

Nobody wants to read a ransomware response plan for the first time while the screens are locked. The first hour after discovery matters. Decisions made in panic, such as turning everything off, wiping machines or paying quickly, can destroy evidence, spread the damage or violate reporting obligations. A short written plan makes the difference.

This walkthrough is a general guide for administrators and IT contacts at care facilities. Your own plan should be tailored with your IT provider, legal counsel and insurer.

Minutes 0 to 10: Recognize and Contain

Signs of ransomware

Files that will not open or have strange new extensions

A ransom note on screens or in folders

Systems suddenly slow, or shared drives unavailable

Staff locked out of accounts

First actions

Alert the incident lead: your administrator, IT contact or managed provider. Use a phone, not email, in case email is compromised.

Disconnect affected devices from the network: unplug the network cable or turn off Wi-Fi. Do not power them off if you can avoid it, since memory may hold useful evidence.

Do not delete anything, and do not run random cleanup tools.

Do not log in to additional systems from affected computers.

Minutes 10 to 30: Assess and Protect Care

Switch to downtime procedures

Resident care comes first. Activate paper downtime forms for medication administration, assessments and orders. Print the most recent downtime reports if available. Make sure staff know who is in charge of each unit.

Scope the problem

IT should find out:

Which systems and locations are affected

Whether the EHR, email and phones are impacted

Whether backups appear intact and isolated

Whether the attacker may still have access

Protect credentials

Prepare to reset passwords for administrator, email and remote access accounts, using a clean device. Disable remote access until you know it is safe.

Minutes 30 to 60: Notify and Preserve

Call the right people

Your managed IT provider or incident response firm

Your cyber insurance carrier, since many policies require prompt notice and specify approved vendors

Legal counsel experienced with healthcare breaches

Leadership, ownership or board contacts

Your EHR vendor, if connection is affected

Law enforcement can also be contacted. The FBI and CISA accept reports of ransomware incidents, and many organizations report even if they do not need immediate help.

Preserve evidence

Take photos of ransom notes, save log files, and write down times and who did what. Keep a running timeline.

Communicate carefully

Provide staff with brief, factual instructions and a single point of contact. Avoid speculation in group chats or email. Hold off on telling families or the press until facts are known and counsel has advised.

Questions That Come Up Quickly

Should we pay?

That is a business and legal decision that should involve counsel, your insurer and law enforcement. Payment does not guarantee data recovery and can raise legal issues. Strong, tested backups reduce the pressure to consider it.

Is it a HIPAA breach?

HHS guidance treats ransomware that encrypts protected health information as a presumed breach unless you can demonstrate a low probability that the information was compromised, using the four-factor risk assessment. Breach notification timing is generally no later than 60 days from discovery, though some situations require faster action. Your counsel should guide this assessment.

Can we restore from backup right away?

Not until you are confident the attacker is out. Restoring into a compromised environment can lead to a second infection.

What to Prepare Before It Happens

A printed contact list with after-hours numbers

Downtime forms and procedures for each unit

Tested, isolated backups

Your insurer's reporting instructions

An agreed decision-maker and backup decision-maker

A tabletop exercise at least annually

How UnityCare IT Can Help

UnityCare IT helps healthcare organizations prepare incident response plans, test backups and run tabletop exercises, and we support clients during active incidents. If you do not have a written plan, a short working session can give you a solid start.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172