It might start with a nurse who cannot open files, a ransom note on a screen, a strange login alert, or a call from a bank about a payment you did not authorize. In those first minutes, adrenaline runs high and instincts can cause damage. Someone shuts down a server and destroys evidence. Someone else emails a screenshot of the problem to the whole staff. Having a plan in advance, even a one-page version, makes a measurable difference in how the next days unfold.
This walkthrough covers the first hour. It is written for administrators, but it is most useful when you review it with your IT partner before an incident happens.
Write down when the issue was discovered, by whom, and what they saw. Notes taken in the moment are far more reliable than memory later.
If a device appears infected, disconnect it from the network by unplugging the Ethernet cable or turning off Wi-Fi. Do not shut it down or reboot it unless your IT team instructs you to. Powering off can erase evidence held in memory and complicate investigation.
Resist the urge to clean up. Leave ransom notes, suspicious emails and logs in place.
Do not contact an attacker or make any payment decisions in the first hour. Those decisions involve legal counsel, insurers and law enforcement.
Call the people who need to know, using phone numbers that do not depend on potentially compromised systems.
Your IT provider or security contact
The administrator and compliance or privacy officer
Your cyber insurance carrier, since many policies require prompt notice and may provide a breach coach or approved vendors
Legal counsel, if you have one
Keep a printed contact sheet in a binder or on a phone. If email is down, it is hard to find numbers stored only there.
Your IT team will start asking questions. Help by gathering facts, not guessing.
Which systems, locations or accounts appear affected?
Are residents' records involved?
Is the EMR still accessible?
Were any unusual logins, emails or file changes noticed before the incident?
Has anyone clicked a suspicious link or approved an unexpected login prompt?
If an email account may be compromised, change its password from a clean device and review mailbox rules for forwarding that an attacker may have added. Disable accounts if instructed.
Resident care continues whatever the state of your computers. Activate paper-based downtime procedures if systems are unavailable.
Use printed medication administration records and resident face sheets, if you keep recent copies
Confirm that care staff know how to document by hand and enter data later
Keep clear, calm communication with department heads
Make sure phones and nurse call systems are working, since some depend on the network
A downtime kit that is refreshed regularly is one of the most valuable things a facility can prepare.
Ask your IT provider to preserve logs and take images of affected systems when appropriate
Limit who discusses the incident, and keep communications factual
Avoid speculation in email or text, which may become part of the record
Decide who is the single voice for staff, residents and families
Some obligations start counting from discovery of a breach. Under the HIPAA Breach Notification Rule, covered entities must notify affected individuals without unreasonable delay and no later than 60 days after discovery of a breach of unsecured protected health information. Larger breaches involve notice to HHS and the media. State laws, contracts with payers and insurance policies may have shorter timelines. Your counsel and compliance officer should evaluate which apply. A documented risk assessment of the incident is part of determining whether notification is required.
A workable incident response plan does not need to be long. It should list roles, phone numbers, decision authority, system priorities and downtime steps. Practice it with a tabletop exercise, in which the team talks through a scenario such as a ransomware note appearing on a Sunday night. Even a one-hour session reveals gaps, such as who has the insurer's number.
UnityCare IT helps healthcare organizations prepare incident response plans, run tabletop exercises and respond when something goes wrong. If you do not yet have a one-page plan posted at the administrator desk, we can help you draft one.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034