Ransomware Response: The First Hour, Step by Step

It usually begins as a small oddity. A file will not open. A screen shows a note demanding payment. Several computers at the nurses' station slow to a crawl. In a care setting, the pressure is immediate because medication records, schedules and billing may all depend on those systems.

Having a plan before this happens changes the outcome. If you do not have one, the steps below are a reasonable starting point. They are general guidance, and your IT provider, insurer and counsel should shape the details.

Minutes 0 to 10: Recognize and Contain

Do not panic, and do not power off yet

Powering off can destroy information that investigators need, although in some cases isolating is better. Follow your IT provider's instruction if available.

Disconnect affected devices

Unplug network cables and turn off Wi-Fi on infected machines. The goal is to stop the spread to other computers and file servers. If you are unsure which are affected, it is better to isolate more than fewer.

Call the right person

Contact your IT provider or security contact immediately, using a phone that does not rely on your network. This is why after-hours numbers should be posted somewhere physical.

Minutes 10 to 30: Assess and Protect

Identify the scope

Which computers and servers are affected? Is the EHR available? Are backups intact? Do not assume backups are safe, since some ransomware seeks them out.

Preserve evidence

Take photos of ransom notes with a phone. Write down times, who noticed what, and any unusual activity beforehand. Avoid deleting files or running cleanup tools until advised.

Shut off remote access

Disable VPN and remote desktop access temporarily, and consider resetting passwords for administrator accounts from a clean device.

Switch to downtime procedures

This is where preparation pays off. Nursing staff should move to paper medication administration records and printed resident information. Your downtime kit should be accessible without any computer.

Minutes 30 to 60: Notify and Organize

Notify leadership and your insurer

If you have cyber insurance, the policy often requires prompt notice and may provide a breach coach and approved forensic vendors. Using vendors outside the policy can create coverage problems.

Involve legal counsel

Attorneys help manage privileged communications and notification decisions.

Consider law enforcement

The FBI and CISA encourage reporting ransomware incidents. Reporting does not obligate you to anything, and agencies sometimes have decryption tools or useful intelligence.

Appoint one coordinator

Choose one person to receive information and make decisions. Too many voices create confusion.

What to Avoid

Paying the ransom as a first reaction. It does not guarantee recovery, it may carry legal considerations, and it should be a decision made with counsel and professionals.

Restoring from backup before you know how attackers got in, since you may be restoring into the same hole.

Posting about the incident publicly before you know the facts.

Deleting logs or wiping machines before investigators capture them.

HIPAA Considerations

Under HIPAA, ransomware that encrypts electronic PHI is generally treated as a presumed breach unless you can demonstrate a low probability that the information was compromised, based on a risk assessment. HHS has published ransomware guidance explaining this. Timelines for notifying individuals and HHS are discussed separately, and legal counsel should guide those decisions.

After the First Hour

Recovery takes days, not hours. Keep a written timeline, keep staff and families informed with honest, measured messages, and plan a review afterward. Ask what allowed the intrusion, what slowed detection and which protections would have helped. Update your response plan with what you learned.

Prepare Before You Need It

Print your contact list, test restores of your backups, and practice a downtime drill at least annually. UnityCare IT helps care organizations build and rehearse incident response plans, and we can respond when something goes wrong. If you do not yet have a written plan, we can help you create one that fits your staffing and systems.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172