What to Do in the First Hour After a Suspected Breach

It might start with a nurse who cannot open files, a ransom note on a screen, a strange login alert, or a call from a bank about a payment you did not authorize. In those first minutes, adrenaline runs high and instincts can cause damage. Someone shuts down a server and destroys evidence. Someone else emails a screenshot of the problem to the whole staff. Having a plan in advance, even a one-page version, makes a measurable difference in how the next days unfold.

This walkthrough covers the first hour. It is written for administrators, but it is most useful when you review it with your IT partner before an incident happens.

Minutes 0 to 10: Recognize and contain

Stay calm and document the time

Write down when the issue was discovered, by whom, and what they saw. Notes taken in the moment are far more reliable than memory later.

Isolate affected devices

If a device appears infected, disconnect it from the network by unplugging the Ethernet cable or turning off Wi-Fi. Do not shut it down or reboot it unless your IT team instructs you to. Powering off can erase evidence held in memory and complicate investigation.

Do not delete anything

Resist the urge to clean up. Leave ransom notes, suspicious emails and logs in place.

Do not pay, negotiate or reply

Do not contact an attacker or make any payment decisions in the first hour. Those decisions involve legal counsel, insurers and law enforcement.

Minutes 10 to 20: Activate the response team

Call the people who need to know, using phone numbers that do not depend on potentially compromised systems.

Your IT provider or security contact

The administrator and compliance or privacy officer

Your cyber insurance carrier, since many policies require prompt notice and may provide a breach coach or approved vendors

Legal counsel, if you have one

Keep a printed contact sheet in a binder or on a phone. If email is down, it is hard to find numbers stored only there.

Minutes 20 to 35: Scope the problem

Your IT team will start asking questions. Help by gathering facts, not guessing.

Which systems, locations or accounts appear affected?

Are residents' records involved?

Is the EMR still accessible?

Were any unusual logins, emails or file changes noticed before the incident?

Has anyone clicked a suspicious link or approved an unexpected login prompt?

If an email account may be compromised, change its password from a clean device and review mailbox rules for forwarding that an attacker may have added. Disable accounts if instructed.

Minutes 35 to 50: Switch to downtime procedures

Resident care continues whatever the state of your computers. Activate paper-based downtime procedures if systems are unavailable.

Use printed medication administration records and resident face sheets, if you keep recent copies

Confirm that care staff know how to document by hand and enter data later

Keep clear, calm communication with department heads

Make sure phones and nurse call systems are working, since some depend on the network

A downtime kit that is refreshed regularly is one of the most valuable things a facility can prepare.

Minutes 50 to 60: Preserve evidence and communicate carefully

Ask your IT provider to preserve logs and take images of affected systems when appropriate

Limit who discusses the incident, and keep communications factual

Avoid speculation in email or text, which may become part of the record

Decide who is the single voice for staff, residents and families

After the first hour: legal and regulatory clocks

Some obligations start counting from discovery of a breach. Under the HIPAA Breach Notification Rule, covered entities must notify affected individuals without unreasonable delay and no later than 60 days after discovery of a breach of unsecured protected health information. Larger breaches involve notice to HHS and the media. State laws, contracts with payers and insurance policies may have shorter timelines. Your counsel and compliance officer should evaluate which apply. A documented risk assessment of the incident is part of determining whether notification is required.

Build the plan before you need it

A workable incident response plan does not need to be long. It should list roles, phone numbers, decision authority, system priorities and downtime steps. Practice it with a tabletop exercise, in which the team talks through a scenario such as a ransomware note appearing on a Sunday night. Even a one-hour session reveals gaps, such as who has the insurer's number.

Support when it counts

UnityCare IT helps healthcare organizations prepare incident response plans, run tabletop exercises and respond when something goes wrong. If you do not yet have a one-page plan posted at the administrator desk, we can help you draft one.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034