A 2025 JAMA Network Open study found that ransomware accounted for 69% of affected patient records in the 2024 healthcare breaches included in its dataset. The authors noted that 2024 reporting was incomplete because the study period ended on October 31 (Source).
This healthcare ransomware incident response checklist focuses on the actions healthcare organizations should take during the first day—before rushing into restoration.
Quick Answer – What to Do Just After Healthcare Ransomware Attack
In the first 24 hours after a healthcare ransomware attack, isolate affected systems, activate the incident response team, preserve evidence, protect unaffected backups, assess whether PHI may be involved, maintain critical patient-care workflows, and confirm containment before beginning recovery. Do not automatically restore the newest backup without first evaluating whether the recovery point is safe and usable.
Healthcare Ransomware Response Checklist for the First 24 Hours
| Action | Typical Internal Owner | Target Timing | Evidence of Completion |
|---|---|---|---|
| Confirm and declare the incident | IT / Incident Lead | Immediate | Incident officially logged |
| Isolate affected systems | IT / Security | Immediate | Compromised devices segmented or disconnected |
| Activate the response team | Incident Lead | First hour | Key stakeholders notified |
| Preserve logs and evidence | IT / Security | First hour | Logs, alerts, and ransom notes retained |
| Protect unaffected backups | Backup / IT Team | First hour | Recovery copies protected from the affected environment |
| Identify affected systems and accounts | IT / Security | Hours 1–4 | Initial scope documented |
| Check for possible data exfiltration | IT / Security / Forensics | Hours 1–4 | Initial evidence reviewed |
| Activate healthcare downtime procedures | Clinical / Operations Lead | Hours 1–4 | Critical workflows moved to approved alternatives |
| Assess potential PHI impact | Privacy / Compliance | Hours 4–12 | Initial PHI assessment documented |
| Notify appropriate response partners | Leadership / Legal | Hours 4–12 | Notifications recorded |
| Define recovery priorities | Incident + Clinical Leads | Hours 12–24 | Critical systems ranked |
| Confirm recovery readiness | Security / Recovery Team | Before restoration | Recovery criteria documented |
First Hour: Contain the Ransomware Attack, Preserve Evidence, and Protect Backups
The first hour should focus on limiting further spread, establishing clear ownership, and preserving the systems and information required for investigation and recovery.

Isolate Ransomware-Affected Systems & Access Paths
Disconnect affected endpoints, servers, and network segments from connectivity where appropriate. Review remote-access pathways and privileged accounts that may also have been compromised.
Containment may also require disabling or resetting compromised administrative credentials, restricting remote access, or strengthening authentication where attacker access has been identified.
The objective is to limit ransomware propagation without unnecessarily disrupting unaffected systems. HHS guidance recommends containing the impact and propagation of ransomware as part of the incident-response process.
Activate the Healthcare Incident Response Team
Assign clear ownership for the response. Depending on the organization, this may include:
- an incident lead;
- IT or security personnel;
- privacy or compliance staff;
- executive leadership;
- an external MSP, security provider, or incident-response specialist.
A designated lead helps keep technical containment, clinical operations, documentation, and stakeholder communication coordinated.
Document the Incident Timeline and Preserve Evidence
Record what is known as the incident develops, including:
- when the incident was discovered;
- which systems first showed signs of compromise;
- ransom notes or suspicious messages;
- relevant security alerts and logs;
- unusual account or network activity;
- actions already taken by staff.
Preserving this information supports technical investigation, compliance review, cyber-insurance requirements, and later recovery decisions.
Protect Unaffected Backups and Recovery Infrastructure
Restrict unnecessary access to backup repositories and separate unaffected recovery copies from the compromised production environment where appropriate.
Review whether compromised credentials, remote-access pathways, or active connections could still reach backup infrastructure.
A successful backup job only confirms that data was copied. It does not prove that the recovery point is intact, free from compromise, or suitable for production restoration after ransomware. Preserve available recovery options now; backup verification and recovery comes later in the recovery process.
Establish Secure Alternative Communications
If email or collaboration systems may be compromised, use approved alternative channels such as phone or another secure out-of-band communication method.
This helps keep incident coordination separate from systems that may be monitored or controlled by the attacker.
Hours 1–4: Assess the Ransomware Scope and Maintain Patient Operations
Once immediate containment is underway, the next priority is understanding how far the incident extends while maintaining essential healthcare services.
Identify Affected Systems, Accounts, and ePHI
Build an initial picture of the affected environment. Review:
- endpoints and servers;
- EHR and practice-management systems;
- imaging and laboratory platforms;
- email and identity systems;
- privileged or administrator accounts;
- shared drives and databases containing PHI or ePHI.
The objective is not to complete a full forensic investigation in the first few hours. It is to understand which systems, accounts, and data require the most urgent attention.
For healthcare organizations, that often means understanding dependencies across EHRs, imaging, scheduling, billing, and other systems covered by a broader healthcare data backup and recovery strategy.
Determine Whether the Ransomware Attack is Still Active
Check whether:
- encryption is continuing;
- additional systems are showing signs of compromise;
- unauthorized sessions remain active;
- suspicious privileged-account activity continues;
- lateral movement may still be occurring.
If the attack remains active, containment should continue before restoration begins. Reconnecting systems too early can extend the incident.
Check for Data Exfiltration and Unauthorized Access
Do not assume ransomware only encrypted files.
HHS notes that ransomware may also destroy or exfiltrate data, and evidence of attempted exfiltration can be relevant when assessing whether PHI has been compromised. [Source]
Review available evidence for indicators such as:
- unusual outbound data transfers;
- large archive or compression activity;
- unexpected access to PHI repositories;
- suspicious cloud-storage activity;
- attacker staging or copying files;
- unusual authentication or network logs.
Encryption and data theft are separate questions. If the organization cannot reliably determine whether information left the environment, qualified forensic assistance may be necessary.
Activate Healthcare Downtime Procedures for Critical Workflows
If clinical systems are unavailable, move to approved downtime procedures so patient care can continue as safely as possible.
Depending on the organization, this may include:
- manual patient documentation;
- alternative scheduling processes;
- approved communication channels;
- temporary procedures for accessing essential clinical information.
The objective is to maintain essential operations without reconnecting compromised systems simply to regain access.
Prioritize Critical Patient-Care Systems
Not every unavailable system carries the same clinical or operational impact.
Identify systems that most directly affect patient safety and care delivery, such as:
- EHR access;
- diagnostic imaging;
- laboratory interfaces;
- medication information;
- clinical communications;
- scheduling.
The priority order should reflect the organization’s actual clinical dependencies rather than a universal recovery sequence.

Hours 4–12: Coordinate the Response and Assess Potential HIPAA Impact
Once the immediate scope is clearer, the response should expand beyond IT. A ransomware incident can create privacy, legal, insurance, clinical, and operational obligations that need to be handled in parallel.
Notify Legal, Privacy, Insurance, and Incident Response Partners
Bring in the appropriate stakeholders based on the facts of the incident.
These may include:
- executive leadership;
- IT and security personnel;
- the Privacy Officer;
- legal counsel;
- the cyber-insurance provider;
- an external incident-response or forensic partner;
- law enforcement where appropriate.
Not every ransomware incident follows the same notification path. Decisions should follow the organization’s incident-response plan, contracts, insurance requirements, and applicable legal obligations.
Assess Potential PHI and ePHI Impact
A ransomware incident involving ePHI requires careful review under HIPAA.
HHS states that ransomware is a security incident and explains that when ransomware encrypts ePHI, a breach is presumed unless the covered entity or business associate can demonstrate a low probability that the PHI was compromised based on the required risk assessment.
Begin documenting:
- which systems and ePHI were involved;
- what PHI may have been affected;
- evidence of unauthorized access or acquisition;
- evidence of data exfiltration;
- which records or individuals may be involved;
- what is known about the attacker’s activity.
Healthcare organizations should separately ensure that backup safeguards, documentation, and recovery evidence support their broader HIPAA-aligned backup strategy.
Document the HIPAA Breach Risk Assessment Factors
Under HHS guidance, the formal risk assessment considers at least four factors:
- The nature and extent of the PHI involved, including identifiers and the likelihood of re-identification.
- The unauthorized person who used the PHI or received the disclosure.
- Whether the PHI was actually acquired or viewed.
- The extent to which the risk to the PHI has been mitigated.
These factors help determine whether the organization can demonstrate a low probability that PHI was compromised. The assessment should be documented and based on the evidence available from the incident investigation.
Document Incident Decisions, Findings, and Notifications
Maintain a clear record of:
- affected systems and data;
- actions taken;
- key decisions;
- notification times;
- stakeholder communications;
- confirmed facts;
- unresolved questions.
Good documentation supports the technical investigation, HIPAA review, cyber-insurance process, and any later regulatory or legal response.
Hours 12–24: Establish Ransomware Recovery Readiness
By this stage, the organization should be determining whether it has enough control over the incident to begin preparing for recovery.
Confirm Ransomware Containment Before Restoration
Before restoration begins, verify that:
- active ransomware spread has been stopped or sufficiently controlled;
- compromised accounts and access paths have been addressed;
- relevant evidence has been preserved;
- backup infrastructure remains protected;
- the organization has a clearer understanding of affected systems and data.
Recovery should not begin simply because systems are unavailable. Restoring into an environment that remains compromised can create additional disruption.
Define Critical System Recovery Priorities
Rank systems according to their impact on patient care and operations.
Typical priorities may include:
- EHR systems;
- imaging and diagnostic platforms;
- clinical communications;
- scheduling;
- billing and administrative systems.
The exact order should reflect patient-safety needs, technical dependencies, and operational requirements.
Identify Candidate Backup and Recovery Points
Review available backup history to identify potential recovery points without restoring them immediately.
Consider:
- when each recovery point was created;
- how it relates to the suspected compromise timeline;
- whether the recovery copy remained protected from the affected environment;
- whether the backup chain is complete and usable;
- whether an immutable or isolated copy is available;
- what integrity, threat, and restore validation is required before production use.
An isolated or immutable backup can reduce the likelihood that ransomware altered the recovery copy, but immutability alone does not prove that the data is safe to restore. A backup created after an attacker entered the environment could still contain compromised data.
A candidate recovery point should therefore represent a known-good state only after appropriate validation.
Understanding the difference between clean and infected restore points helps explain why backup age alone is not enough to determine whether a copy should return to production.
What Should a Healthcare Practice Do Without an Internal Cybersecurity Team?
Small medical and dental practices may not have a dedicated security team, but they still need clear ownership during a ransomware incident.
Assign Clear Internal Incident Ownership
At minimum, identify:
- a business or clinical decision-maker;
- the primary IT contact;
- a privacy or compliance contact;
- the external technical partner responsible for incident support.
One person should coordinate decisions and communications so technical, clinical, privacy, and recovery actions do not become fragmented.
Know When to Bring in External Incident Response or Recovery Help
Bring in qualified outside support when:
- ransomware is still spreading;
- privileged or administrator accounts may be compromised;
- backup systems may have been affected;
- the practice cannot establish the scope of the incident;
- critical clinical systems remain unavailable;
- internal staff cannot determine whether recovery can safely begin.
The type of help needed depends on the stage of the incident. Security or forensic specialists may be required for containment and investigation, while CDS recovery engineers can support backup evaluation, restore-point verification, and controlled restoration when the organization is ready to recover.
Unison Complete combines backup and disaster recovery with cybersecurity capabilities, vulnerability detection, security-controls validation, and verified recovery.
Common Mistakes During the First 24 Hours of a Ransomware Attack
Even a well-intentioned response can make recovery harder if decisions are rushed.
- Restoring or reconnecting systems too early: Bringing systems back before active spread and unauthorized access are sufficiently controlled can extend the incident or reintroduce compromise.
- Failing to preserve logs and evidence: Deleting alerts, logs, or incident data can make investigation and compliance review more difficult.
- Assuming a successful backup is safe to restore: Backup success does not automatically mean the data is recoverable. A completed job confirms that data was copied; it does not prove that a recovery point is intact or safe for production use.
- Ignoring possible data theft: Ransomware may involve exfiltration as well as encryption.
- Treating ransomware only as an IT problem: Healthcare incidents can affect patient care, privacy, compliance, communications, and business operations simultaneously.
- Using potentially compromised communication systems: Move incident coordination to approved alternative channels if email or collaboration platforms may be affected.
- Making undocumented decisions: Record key actions, findings, and decisions throughout the incident.
When is It Safe to Move From Ransomware Incident Response to Recovery?
A healthcare organization should move toward recovery only after it has enough control over the incident to reduce the risk of restoring into a still-compromised environment.
Key readiness signals include:
- ransomware spread has been contained;
- compromised accounts and access paths have been addressed;
- the affected environment is sufficiently scoped;
- relevant evidence has been preserved;
- backup infrastructure is protected;
- critical systems have been prioritized;
- candidate recovery sources are ready for validation.
Incident response focuses on containing the attack, understanding what happened, preserving evidence, and protecting remaining systems.
Recovery focuses on validating recovery points, restoring systems and data, and returning critical services to production safely.
The transition matters because ransomware recovery should not begin by automatically restoring the newest backup. Recovery history should first be reviewed to identify candidate restore points, followed by integrity, backup-chain, threat, and restore-readiness checks.
Conclusion: Contain First, Recover Second
The first 24 hours after a healthcare ransomware attack should focus on regaining control—not rushing into restoration.
Contain the threat, preserve evidence, protect patient-care operations, determine whether PHI may be involved, secure available recovery copies, and establish the scope of the incident before bringing systems back online.
Once the environment is sufficiently controlled, candidate recovery points should be evaluated for integrity, continuity, and suitability before critical systems return to production.
A successful backup job alone does not prove that a recovery point is ready to use.
Request a Data Risk & Recovery Assessment
Request a Data Risk & Recovery Assessment to determine whether your backup environment, recovery process, and critical systems are prepared to support a clean, controlled recovery after ransomware.
Healthcare Ransomware Incident Response FAQs
What Should a Healthcare Organization Do First After Detecting Ransomware?
Isolate affected systems, activate the incident response plan, preserve evidence, and protect unaffected backup infrastructure. The immediate objective is to limit further spread before restoration begins.
Should Ransomware-Infected Computers Be Disconnected From the Network?
Affected systems should generally be isolated from network connectivity as part of containment. The method should follow the organization’s incident-response procedures while avoiding unnecessary destruction of forensic evidence.
Does a Ransomware Attack Automatically Require HIPAA Breach Notification?
Not automatically. HHS treats ransomware affecting ePHI as a breach unless the organization can demonstrate through the required risk assessment that there is a low probability the PHI was compromised. The determination depends on the facts and documented evidence.
Can Ransomware Steal Patient Data Without Encrypting It?
Yes. Ransomware operators may exfiltrate data before, during, or even without encrypting it. Healthcare organizations should assess both data availability and evidence of unauthorized access or transfer when determining PHI impact.
How Should Healthcare Organizations Protect Backups During Ransomware?
Protect available recovery copies from the affected production environment, restrict unnecessary access to backup systems, and determine whether compromised credentials can still reach them. Treat each recovery point as a candidate until integrity and restore readiness are verified.
What Evidence Should Be Preserved After a Ransomware Attack?
Preserve relevant logs, alerts, ransom notes, screenshots, timestamps, affected-system details, suspicious account activity, and records of actions taken. This evidence supports investigation, HIPAA review, insurance, and recovery decisions.
Should a Healthcare Organization Pay a Ransomware Demand?
CISA and other federal law-enforcement partners do not recommend paying ransom because payment does not guarantee data recovery or prevent further compromise or disclosure. Decisions should involve legal counsel, insurers, incident responders, and appropriate authorities.
References Used
- HHS: Ransomware and HIPAA Fact Sheet
- JAMA Network Open: Ransomware Attacks on US Health Care Organizations, 2016–2024
- HHS ASPR TRACIE: Healthcare System Cybersecurity Incident Response Checklist




