It usually begins as a small oddity. A file will not open. A screen shows a note demanding payment. Several computers at the nurses' station slow to a crawl. In a care setting, the pressure is immediate because medication records, schedules and billing may all depend on those systems.
Having a plan before this happens changes the outcome. If you do not have one, the steps below are a reasonable starting point. They are general guidance, and your IT provider, insurer and counsel should shape the details.
Powering off can destroy information that investigators need, although in some cases isolating is better. Follow your IT provider's instruction if available.
Unplug network cables and turn off Wi-Fi on infected machines. The goal is to stop the spread to other computers and file servers. If you are unsure which are affected, it is better to isolate more than fewer.
Contact your IT provider or security contact immediately, using a phone that does not rely on your network. This is why after-hours numbers should be posted somewhere physical.
Which computers and servers are affected? Is the EHR available? Are backups intact? Do not assume backups are safe, since some ransomware seeks them out.
Take photos of ransom notes with a phone. Write down times, who noticed what, and any unusual activity beforehand. Avoid deleting files or running cleanup tools until advised.
Disable VPN and remote desktop access temporarily, and consider resetting passwords for administrator accounts from a clean device.
This is where preparation pays off. Nursing staff should move to paper medication administration records and printed resident information. Your downtime kit should be accessible without any computer.
If you have cyber insurance, the policy often requires prompt notice and may provide a breach coach and approved forensic vendors. Using vendors outside the policy can create coverage problems.
Attorneys help manage privileged communications and notification decisions.
The FBI and CISA encourage reporting ransomware incidents. Reporting does not obligate you to anything, and agencies sometimes have decryption tools or useful intelligence.
Choose one person to receive information and make decisions. Too many voices create confusion.
Paying the ransom as a first reaction. It does not guarantee recovery, it may carry legal considerations, and it should be a decision made with counsel and professionals.
Restoring from backup before you know how attackers got in, since you may be restoring into the same hole.
Posting about the incident publicly before you know the facts.
Deleting logs or wiping machines before investigators capture them.
Under HIPAA, ransomware that encrypts electronic PHI is generally treated as a presumed breach unless you can demonstrate a low probability that the information was compromised, based on a risk assessment. HHS has published ransomware guidance explaining this. Timelines for notifying individuals and HHS are discussed separately, and legal counsel should guide those decisions.
Recovery takes days, not hours. Keep a written timeline, keep staff and families informed with honest, measured messages, and plan a review afterward. Ask what allowed the intrusion, what slowed detection and which protections would have helped. Update your response plan with what you learned.
Print your contact list, test restores of your backups, and practice a downtime drill at least annually. UnityCare IT helps care organizations build and rehearse incident response plans, and we can respond when something goes wrong. If you do not yet have a written plan, we can help you create one that fits your staffing and systems.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172