Restoring Operations After an Attack: What to Rebuild First

When an attack takes systems offline, the temptation is to bring everything back as fast as possible. But recovery done in the wrong order can reintroduce the attacker, waste hours or leave critical services waiting behind less important ones. In a senior-living or skilled nursing setting, the priority is clear: keep residents safe and cared for. A pre-planned order of recovery, written before anything goes wrong, takes the guesswork out of a very stressful time.

This post outlines a practical way to prioritize what to restore after an attack, and the checks to make along the way.

First, make sure the attacker is out

Restoring systems before the intrusion has been contained is a common and costly mistake. Before rebuilding anything, confirm with your incident response team, cyber insurance resources or forensic specialists that:

The way the attacker got in has been identified and closed.

Compromised accounts have had their passwords reset, and multi-factor authentication is enforced.

Any attacker access, such as remote tools or new accounts, has been removed.

Backups have been checked for signs of tampering or infection.

Preserve evidence before wiping systems, since investigators, insurers and regulators may need it.

Think in tiers

Group your systems by how quickly they must return. A simple three-tier model works for most organizations.

Tier one: life and safety

These are the systems that directly support resident care and safety, and they come first. Examples include:

Access to resident medication, allergy and care information, whether electronic or through downtime paper procedures.

Nurse call and emergency communications.

Door access and safety systems that affect residents' security and emergency exits.

Phones, so staff, families and emergency services can communicate.

Power-dependent equipment and environmental controls.

Many of these should have downtime procedures that work without computers. Make sure staff know where paper forms and printed contact lists are kept.

Tier two: core operations

Next come the systems that run the organization day to day:

Identity and sign-in services, which most other systems depend on.

Core network services, including internet connectivity, DNS and Wi-Fi.

The electronic health record or a read-only copy of it.

Email and messaging.

Pharmacy and ordering connections.

Payroll and scheduling.

Identity and the network are the foundation, so they often need to be rebuilt first among the tier two systems, even though staff do not see them directly.

Tier three: business support

Finally, restore the systems that matter but can wait a short time: billing and accounts receivable, file shares, reporting tools, websites and marketing systems, and older or less critical applications.

Rebuild in a clean order

Within each tier, restore dependencies first. A database server must be up before the application that uses it, and a sign-in service must be available before users can connect. Map these dependencies in advance, ideally in a short diagram.

Restore from known-good backups where possible, scan restored systems before reconnecting them and bring them back in a segmented or monitored network. Change credentials and keys that the attacker may have seen. Where a system cannot be trusted, rebuild it from a clean image instead of cleaning it.

Verify before declaring success

After each system returns, test it. Confirm data is current and complete, integrations work and users can sign in. Ask clinical staff to verify what they depend on, not just IT. Keep monitoring closely for several days for signs of reinfection.

Communicate throughout

Recovery is as much about communication as technology. Provide regular updates to staff, residents' families, regulators and insurers as appropriate. Keep a log of decisions and timelines. Coordinate any breach notification obligations under HIPAA with your legal and compliance teams.

Plan now, not during the crisis

You can do most of this work in advance:

Write your tier list with input from clinical, administrative and IT leaders.

Record how long each system can be down before it affects care.

Keep offline copies of the plan, contact lists and key procedures.

Test restores from backup regularly, and time them.

Run a tabletop exercise on recovery order.

Plans that have never been tested almost always have surprises, so it is better to discover them in a drill.

How UnityCare IT can help

UnityCare IT helps healthcare and senior-living organizations map their systems, define recovery priorities, test their backups and support recovery when an incident occurs. If you do not have a written recovery order, we can help you create one.

Related service

An outsourced IT department with proactive maintenance and one number to call.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172