Skip to content
Cybersecurity

Ransomware Hit Your Practice. Here Is the First Hour, Step by Step.

August 21, 2026

It is 9:20 on a Wednesday. A medical assistant says the imaging workstation shows a full-screen note demanding payment. Then the front desk says the schedule will not open. Then your billing manager calls, seeing the same thing.

You are the practice administrator, not an engineer, and nobody expects you to be one. But the next sixty minutes are yours, and what you do in them shapes the next sixty days. Here is the hour, in order.

Minutes 0 to 5: recognize it and stop the spread

Signs that this is ransomware and not a routine glitch:

  • A ransom note on screen, as wallpaper, a desktop text file, or a browser page.
  • Files that will not open, or that have new, strange extensions.
  • Multiple machines failing at once, especially file shares and the EHR.
  • Antivirus or EDR alerts firing in a burst, or an alert that the security software was disabled.
  • Staff locked out of accounts they used an hour ago.

If you see two or more of these, treat it as ransomware. You lose nothing by being wrong.

Three things you do not do:

Do not pay. Not now, not from a link on the note. That is a decision for later, with counsel and your carrier.

Do not wipe. Do not reimage, restore, or "just reinstall Windows" on anything. You will destroy evidence and possibly the only clue to how they got in.

Do not reboot everything. Restarting does not clean a machine, and it can trigger a second stage of the attack or wipe volatile evidence.

What you do instead: isolate. Tell staff to unplug the network cable from every affected computer and turn off Wi-Fi on laptops. Leave the machines powered on unless your IT provider says otherwise; running memory can hold forensic evidence about how the attacker got in. If a machine is actively encrypting in front of you and you cannot reach IT, disconnecting the network is still the first move; powering it off is a judgment call to make with IT on the phone.

If you have a simple way to isolate the whole office, such as unplugging the internet router, do it. The EHR is already gone. Cutting the connection stops the attacker's access and any exfiltration still in progress.

Minutes 5 to 15: make two phone calls

Call one: your IT provider or MSP. Say the words "ransomware" and "active." A healthcare-focused MSP will already have an incident procedure and should be talking to you within minutes. Tell them what you have seen, which machines, and what you have already unplugged. Then do what they say.

Call two: your cyber insurance carrier's incident hotline. The number is on your policy declarations page. Call it now, not tomorrow. Nearly every cyber policy requires prompt notice, and many require that the carrier approve counsel, forensics, and any negotiation before you engage them. Calling late, or engaging your own vendors first, can jeopardize coverage. If you cannot find the number, call your broker.

The carrier will typically assign a breach coach, a privacy attorney, within hours. From that point most decisions route through counsel so the investigation is protected by privilege.

Start a paper log now: the time of each call and who you spoke with.

Minutes 15 to 30: preserve, then switch to downtime

Preserve evidence. Photograph the ransom note and the screen of any affected machine. Do not touch files. Do not delete emails, even suspicious ones. Ask staff to write down what they saw and when, on paper.

Do not touch backups. Do not log in to the backup console, do not start a restore, do not check "whether it worked." Ransomware groups routinely target backups first, and a well-meaning restore attempt can overwrite the last clean copy or alert an attacker still inside. Ask your IT provider to check backup status and report back.

Declare downtime. Open the EHR downtime plan and follow it: printed schedule, paper registration, paper encounter forms and superbills, paper orders, downtime log. Assign the roles the plan names. If there is no written plan, give staff one instruction: document every patient on paper and keep every sheet. Decide with your clinical lead which visits proceed on paper today and which get rescheduled.

Minutes 30 to 45: communicate carefully

Internally. Gather staff or send one text: systems are down due to a security incident, we are working with IT and the appropriate parties, we are on paper procedures, and all outside questions go to one person. Name that person. Say plainly: no speculation, no social media.

One spokesperson. You or the physician-owner. Nobody else speaks for the practice, including to vendors, patients, or the press if it comes to that.

Do not email from possibly compromised accounts. If the attacker had a foothold in Microsoft 365 or Google Workspace, they may be reading your mailbox right now. Use phone calls and personal cell texts until IT clears the email environment. Assume any account on any affected machine is compromised until told otherwise.

Patients. Front desk script only: we are experiencing a system outage, we are seeing patients on paper, there may be delays. Nothing about ransomware. Whether and when to say more is a legal question for the breach coach.

Minutes 45 to 60: get the picture and set the rhythm

By now IT should be able to tell you roughly what is affected: which servers and workstations, whether the EHR is encrypted, whether cloud services are reachable, whether backups appear intact. Write it in the log.

Set a cadence: IT updates you hourly, you update staff every two hours even if the news is "no change." Give staff an end-of-day plan: paper charts in a locked cabinet overnight, whether tomorrow's schedule is reduced, who to call if something new appears. Notify the physician-owner if you have not already, and notify your EHR vendor's support line so they can flag your account.

That is the first hour. You did not fix anything, and that was correct. You contained the damage, brought in the people whose job this is, protected the evidence and the coverage, and kept the practice running.

The first 24 hours after the first hour

The picture broadens quickly.

Forensics arrives. The carrier-approved forensics firm, working under counsel, images affected systems, looks for the entry point (a phishing email, an exposed remote desktop port, a stolen credential, an unpatched device), and looks for evidence of exfiltration. They tell IT what can be rebuilt and when.

Recovery planning. IT and forensics agree on the order: identity and domain controllers first, then servers, then workstations, restoring from backups only once those backups are verified clean. This is where a tested backup and disaster recovery setup pays for itself. Practices without offline or immutable backups face a very different week.

Ransom decision. If backups are viable, the answer is usually no. If not, counsel and the carrier lead a structured process, often through a negotiator, with legal restrictions depending on who the attacker is. The practice does not make this decision alone.

Operations and regulators. Clinic continues on paper, billing holds claims, someone starts the back-entry list. Counsel decides whether and when to notify law enforcement and starts the HIPAA and Texas breach analysis.

The HIPAA and Texas notification question

This is a legal question. Do not answer it yourself, but understand the shape of it.

HHS OCR guidance treats ransomware that encrypts ePHI as a presumed breach. That presumption can be overcome only by a documented risk assessment showing a low probability that the PHI was compromised. The factors that matter most:

  • Encryption at rest. If the data was already encrypted by you, with keys the attacker did not get, the analysis looks different. Full-disk encryption on a machine that was running and logged in usually does not help.
  • Exfiltration evidence. Forensics looks for signs data was copied out. Modern ransomware groups almost always exfiltrate before encrypting, and many publish stolen files. Absence of evidence is not proof of absence, and counsel will weigh that.
  • Scope. Which systems held PHI, how many patients, and what data elements.

If notification is required, HIPAA sets an outside limit of 60 days from discovery for notifying individuals, with HHS notification and, above 500 affected individuals in a state, media notice. Texas has its own breach notification statute with a separate timeline and a threshold for reporting to the Texas Attorney General. Both clocks run at once, and counsel maps them to your facts. Your job is to make sure the log, the timeline, and the staff statements you preserved in hour one are complete and handed over.

Who does what: insurer, forensics, MSP, counsel

PartyOwnsDoes not own
Cyber insurerCoverage, vendor approval, claim payment, breach coach assignmentTechnical recovery
Breach counselLegal privilege, notification analysis, regulator and law enforcement contact, ransom decision oversightRebuilding systems
Forensics firmRoot cause, scope, exfiltration evidence, clearance to restoreDay-to-day IT
IT provider / MSPIsolation, backup verification, rebuild and restore, hardening, getting the practice back onlineLegal determinations, talking to regulators
Practice administratorThe log, staff communication, downtime operations, single point of contactEverything above

The administrator's job is to keep one log, one timeline, and one spokesperson so all of them work from the same facts.

The one-page checklist

Print this and put it in the downtime kit.

Recognize

  • Ransom note, encrypted files, multiple machines failing, security tool disabled
  • Treat as ransomware if two or more signs

Do not

  • Pay
  • Wipe or reimage
  • Reboot everything
  • Touch backups
  • Email from affected accounts

Isolate

  • Unplug network cables and disable Wi-Fi on affected machines
  • Leave powered on unless IT says otherwise
  • Consider disconnecting the office internet

Call

  • IT provider / MSP: ___________________
  • Cyber insurance hotline: ___________________
  • Broker (if hotline unknown): ___________________
  • Breach counsel (assigned by carrier): ___________________
  • Physician-owner / partners: ___________________
  • EHR vendor support: ___________________

Preserve

  • Photograph ransom notes and screens
  • Start a paper log: times, calls, names, actions
  • Staff write what they saw

Operate

  • Declare downtime, open the kit, assign roles
  • Reschedule what cannot be done on paper
  • Paper charts secured overnight

Communicate

  • One spokesperson
  • Staff: facts only, no speculation, no social media
  • Patients: outage script only
  • Phone and personal text, not email, until IT clears it

Cadence

  • IT updates hourly, staff every two hours
  • Hand the log to counsel

Not in the first hour, and not without counsel and your insurer. Payment does not guarantee decryption, may be restricted depending on who the attacker is, and is a decision the carrier and breach counsel will want to control. Your job in hour one is to isolate, notify, and preserve, not to negotiate.

Disconnect them from the network and Wi-Fi, but do not power them off unless your IT provider or forensics team tells you to. Memory on a running machine can hold evidence about how the attacker got in. Pulling the network cable stops the spread while keeping that evidence intact.

HHS OCR guidance treats ransomware that encrypts ePHI as a presumed breach unless a documented risk assessment shows a low probability of compromise. Whether it is reportable in your case depends on facts like exfiltration evidence and encryption status, and that determination belongs to counsel.

HIPAA sets an outside limit of 60 days from discovery for individual notice, with additional HHS and media notice depending on how many people are affected. Texas has its own breach notification statute with its own clock and attorney general reporting thresholds. Counsel will map both timelines to your facts.

Call your IT provider first, because isolation is a minutes-matter task. Call the cyber insurer's incident hotline immediately after, ideally within the same fifteen minutes. Most policies require prompt notice and want to assign counsel and forensics before you engage anyone else.

The first hour goes better when the isolation, backup verification, and rebuild are handled by an IT provider who already knows your network and has run this drill. Our managed cybersecurity and backup and disaster recovery services are built for that, with EDR that catches the burst before it spreads (see EDR versus antivirus for why that distinction matters), immutable backups that IT verifies for you, and a 15-minute response window that includes 9:20 on a Wednesday. If you want to understand the threat side, start with why ransomware targets medical practices and what cyber insurance requirements for healthcare now expect.

Ready for a straight answer about your IT? Call (972) 776-6366 or visit our contact page.

Get Started

Ready for a straight answer about your IT?

Schedule a 20-minute discovery call. We will tell you what is working, what is not, and what the gaps would cost.