It rarely begins with a dramatic message. More often, a nurse says the computer is acting strange, files will not open, or an email went out that no one wrote. What happens in the first hour after that report often decides whether an incident is a nuisance or a crisis.
This walkthrough is meant for administrators and department leaders. It is not a substitute for a formal incident response plan, but it can help you act calmly while you pull that plan out.
The first goal is to contain the problem without destroying information.
Disconnect, do not power off. If a computer shows signs of ransomware, unplug its network cable or turn off its Wi-Fi. Shutting it down can erase information in memory that investigators need.
Do not delete anything. Leave suspicious files, emails and messages in place.
Write down what you see. Note the time, the user, the symptoms and any message on the screen. A photo of the screen with a phone is helpful.
Tell staff to stop using the affected system and to avoid logging into other accounts from it.
Call your IT provider or security partner immediately, by phone rather than email, since email may be compromised. Then notify:
The administrator or executive director.
Your privacy and security officers.
The director of nursing, so clinical continuity plans can begin.
Your cyber insurance carrier, if you have a policy. Many policies require prompt notice and may provide an approved incident response team. Using unapproved vendors without notice can create coverage problems.
Keep a single written timeline. Assign one person to record decisions and times.
Your IT team will begin to determine what happened. Questions they will ask include:
Which accounts and devices were affected?
Was any account used from an unusual location or time?
Did the attacker create new accounts or forwarding rules in email?
Are backups intact and isolated?
Expect them to reset passwords for affected accounts, revoke active sessions and block malicious addresses. Resist the urge to rush them into restoring service before the cause is understood, or the attacker may still be inside.
Resident care continues regardless of IT status. Activate downtime procedures:
Paper medication administration records and care plans.
Printed census and emergency contact lists.
Manual processes for admissions, discharges and orders.
Clear communication to staff on each shift about what is working and what is not.
Having these printed and stored somewhere accessible beforehand makes this step far less stressful.
Do not pay a ransom or communicate with attackers without guidance from counsel, law enforcement and your insurer.
Do not post details on social media or talk with the press before facts are known.
Do not wipe and rebuild machines before evidence has been captured.
Do not assume the problem is isolated to one computer.
HIPAA's Breach Notification Rule requires a risk assessment when protected health information may have been exposed, and notification to affected individuals, HHS and sometimes the media when a breach is confirmed. Notice must generally be given without unreasonable delay and no later than 60 days after discovery. Counsel and your compliance team should lead this process, and your IT partner should help determine what was accessed. You may also have obligations under state law and your contracts.
The best time to make these decisions is before an incident. Keep a one-page contact sheet with phone numbers for IT, your insurer, counsel and leadership. Review it twice a year, and hold a short tabletop exercise where leaders talk through a scenario.
UnityCare IT supports healthcare and senior living organizations with incident response planning, tabletop exercises and hands-on help when something goes wrong. If you do not yet have a written plan, we can help you build a practical one.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172