It usually starts small. A nurse reports that files will not open. A screen shows a strange message demanding payment. Several computers slow down at once. In a care setting, the pressure to act is intense, because residents depend on the systems that just went wrong. Having a plan in place before it happens lets you act deliberately instead of reacting in a panic.
This walkthrough describes what a facility should do in the first hour. It is general guidance, and your own incident response plan should be tailored to your environment.
The first task is to stop the spread without destroying evidence.
Disconnect affected computers from the network by unplugging the network cable or turning off Wi-Fi. Do not shut them down unless instructed, because memory may hold useful information.
If you cannot tell which machines are affected, ask your IT provider whether to isolate whole segments of the network.
Do not log in to affected machines with administrator accounts. That can expose powerful credentials.
Do not try to delete files, run random cleanup tools or restart servers.
If a single staff member discovers the problem, the instruction is simple: unplug the network cable, leave the screen as it is and call IT immediately.
Have a contact list ready on paper, since email and phones may be affected. It should include:
Your IT provider or security team, with a 24-hour number
The administrator and compliance officer
Your cyber insurance carrier, since many policies require prompt notice and may include approved response vendors
Legal counsel, if you have one
Your EHR vendor
Assign one person to coordinate communication and one to keep a written log of what happened and when. Time-stamped notes become important for insurance, investigators and your HIPAA analysis.
This is the part many generic checklists skip. Activate your downtime procedures right away:
Switch to paper medication administration records and care plans.
Make sure staff know where printed resident lists, allergy information and emergency contacts are kept.
Confirm that critical safety systems, such as nurse call, door controls and phones, are working, and use manual backups if not.
Brief department heads so everyone hears the same message.
CMS emergency preparedness requirements for long-term care facilities already expect you to plan for continued operations during disruptions, and a cyber incident belongs in those plans.
Your IT provider will start determining what is affected. You can help by:
Noting the ransom message or screenshot, taken with a phone camera if needed
Listing which systems and locations were affected and when staff first noticed
Preserving backups by making sure backup systems are disconnected from the affected network
Avoiding any contact with the attackers until professionals advise you
Do not decide whether to pay a ransom in the first hour. That decision involves legal, insurance and law enforcement considerations, and it should not be rushed.
Under the HIPAA Breach Notification Rule, a ransomware incident involving ePHI is presumed to be a breach unless a risk assessment shows a low probability that the data was compromised. Notification deadlines can run as soon as the breach is discovered, with notice to individuals required without unreasonable delay and no later than 60 days. Note the date and time of discovery in your log, and engage your privacy officer.
You may also report to law enforcement, such as your local FBI field office or CISA, which can offer assistance.
The first hour goes much better if you have prepared:
A written incident response plan, kept on paper and in a secure offsite location
Tested backups, including at least one copy that attackers cannot reach
Downtime forms printed and stored on every unit
A tabletop exercise at least once a year, walking through this scenario with leadership
UnityCare IT helps healthcare organizations write incident response plans, run tabletop exercises and respond when something goes wrong. If you would like to rehearse this scenario before you need it, we can help you set that up.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172