Guide

Ransomware: contain, report, notify — the first 72 hours

Summary

The day ransomware hits, work three phases fast: contain, assess, notify. Immediately isolate infected devices and preserve evidence, do not wipe anything, and start your incident log. Then run a documented risk assessment — a ransomware encryption of protected health information is presumed a reportable breach unless you can show a low probability of compromise. If it is reportable, the notification clock starts: patients within 60 days, then HHS, and media if 500 or more are affected.

By Gale Editorial · Updated 2026-07-27. Every figure cited to a dated source. How we write.

The day ransomware hits: three phases in the first 72 hours

Move in three phases and do not skip forward: contain the spread, assess whether protected health information was compromised, then notify whoever the law requires. Speed matters because a ransomware encryption of ePHI is presumed to be a reportable breach unless a documented risk assessment shows a low probability of compromise 1 — so the clock is already running the moment you see the ransom note. Do the first hour right and the rest becomes a process, not a panic.

This page walks the sequence a solo can actually run alone at first: what to touch and what to leave, how to decide whether it is reportable, who gets notified and by when, and what to fix so it does not happen again. Read it once now, while nothing is on fire, so the order is familiar when it is.

Hour zero: contain, preserve evidence, don't pay yet

Your first job is to stop the spread without destroying what investigators will need. Disconnect affected devices from the network and from each other — pull the network cable, turn off Wi-Fi — but do not power them down or wipe them, because that can erase the forensic trail that later proves what was and was not accessed. Start a written incident log now, timestamping every action; that log becomes the backbone of your risk assessment.

In the first hour: - Isolate every affected device; assume anything networked is exposed until proven otherwise - Preserve the ransom note, screenshots, and system logs — do not delete them - Call your IT or managed-security contact and, if you carry it, your cyber-insurance hotline before making changes - Do not decide whether to pay under pressure; that is a legal and business question for counsel and your insurer, not a reflex - Consider notifying law enforcement, which federal guidance encourages and which does not, on its own, satisfy your HIPAA duties

Is this a reportable breach? The risk assessment that decides

Under HIPAA, a ransomware attack that encrypts ePHI is presumed to be a breach — and the law treats it as reportable unless a documented, good-faith risk assessment demonstrates a low probability that the information was compromised 1. That assessment is not a gut call; it weighs the nature of the data, who could have accessed it, whether it was actually viewed or exfiltrated, and the extent to which the risk has been mitigated. Write it down as you go.

Get help with this step. For a solo, the honest move is to bring in a security professional or breach coach to run and document the assessment, because its conclusion determines whether the notification duties below apply at all. This is the situation where competent outside help is genuinely warranted — the same judgment that the lost laptop or the small-practice breach calls for, at larger scale.

The notification clock: who you tell, and by when

If the assessment does not clear you, breach-notification duties begin, and they run on fixed deadlines. Affected individuals get written notice without unreasonable delay and no later than 60 days from discovery. HHS is notified too: for a breach affecting fewer than 500 people you may report it in the annual submission, while a breach of 500 or more is reported to HHS — and to prominent media in the affected area — within that same 60-day window 2.

Who to notifyThresholdDeadline
Affected individualsAny reportable breachWithout unreasonable delay, no later than 60 days from discovery
HHS (OCR)Fewer than 500 affectedIn the annual breach report after year-end
HHS (OCR)500 or more affectedWithin 60 days of discovery
Prominent local media500 or more in a state or jurisdictionWithin 60 days of discovery

State breach-notification laws may add their own recipients and shorter clocks; those run in parallel with the federal rule, so the earliest applicable deadline is the one that controls.

If the attack hit a vendor, not your own laptop

Many solo practices are breached through a vendor — the EHR, the backup service, the outsourced IT provider. Those vendors are business associates: they create, receive, maintain, or transmit PHI on your behalf, and your business-associate agreement should define what they do when they are hit, including notifying you promptly 3. Their breach can still be your reporting obligation to your patients, so the agreement and their incident timeline matter as much as your own logs.

When a vendor calls with bad news, the questions are concrete: what data was involved, how many of your patients, when they discovered it, and when they will give you the details you need to notify. The day their clock started can determine when yours does, so pin down dates in writing and fold their findings into your own risk assessment rather than waiting for a tidy final report.

Getting back to work: restore, verify, keep serving patients

Recovery runs on the continuity plan you ideally wrote before today. The federal small-business continuity framework is built for exactly this: known-good backups you can restore, a documented recovery sequence, and emergency communications so patients and referrers know how to reach you while systems are down 4. Restore from a clean backup rather than a possibly re-infected one, verify data integrity before trusting it, and keep the practice reachable by an alternate channel throughout.

Patients' rights survive the outage. Even mid-recovery, a client's right to a copy of their record persists, so log any request you cannot immediately fulfill and complete it once systems are back rather than letting it lapse 5. This is also where the contingency plan proves its worth — reopening after the disaster is orderly when the backups, the call list, and the recovery steps were written down in advance, and chaotic when they were not.

Prevent the next one: what the Security Rule expected all along

Most of what limits a ransomware disaster is decided before the attack. The Security Rule expects a current risk analysis, reasonable safeguards, and — critically for ransomware — reliable, tested, offline backups, so that encrypted files are an inconvenience rather than an extinction event 1. A solo practice's safeguards scale to its size, but the expectation that you have analyzed your risks and can recover your data does not disappear because you work alone.

Before the next incident: - Keep at least one backup offline or otherwise isolated, and test a restore on a schedule - Encrypt devices and drives, so a stolen or lost device — the lost laptop problem — is not automatically a breach - Patch the systems that touch PHI and require multifactor sign-in - Train on the two mistakes that start most small-practice incidents: the phishing click and the misdirected fax - Keep the incident plan, the notification steps, and your vendors' contacts in the same place as the coverage plan for the solo emergency

Common questions

Usually yes. Paying the ransom does not erase the presumption that a breach occurred; the reporting question turns on your documented risk assessment, not on whether you recovered the data. If that assessment cannot show a low probability that PHI was compromised, the notification duties apply regardless of payment. Document the incident and the assessment either way.

Written notice to affected individuals goes out without unreasonable delay and no later than 60 days from the day you discover the breach. If 500 or more people are affected, HHS and prominent local media are notified within that same window; smaller breaches are reported to HHS in the annual submission. State laws may impose shorter deadlines that run in parallel.

That is a business, legal, and insurance decision, not a clinical reflex, and it is best not made alone under pressure in the first hour. Payment may not restore data, can carry its own legal exposure, and does not end your HIPAA obligations. Loop in counsel and your cyber-insurer before deciding, and preserve every artifact of the attack while you do.

Your vendors are business associates, and your agreement with them should require prompt notice and cooperation when they are breached. Their incident can still be your obligation to notify patients, so the timeline they give you feeds directly into your 60-day clock. Confirm what they will do, and by when, before an incident rather than during one.

Your IT or managed-security contact and, if you carry it, your cyber-insurance hotline, before you change anything on the affected machines. If you have neither, a reputable incident-response firm is worth the cost, because the risk assessment that decides your reporting duties needs to be defensible. Line up both contacts now so the number is not a scramble later.

Run your practice on Gale

The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.

Start or manage a practice →

References

  1. 1.HHS Office for Civil Rights (2016). FACT SHEET: Ransomware and HIPAA. U.S. Department of Health and Human Services. linkThat a ransomware encryption of ePHI is presumed a reportable breach unless a documented risk assessment shows a low probability of compromise, and what the Security Rule expects before and after, including tested backups.
  2. 2.HHS Office for Civil Rights (2026). Breach Notification Rule. U.S. Department of Health and Human Services. linkThe breach-notification timeline: individuals within 60 days, HHS annually under 500 affected or within 60 days at 500 or more, and prominent-media notice at 500 or more affected.
  3. 3.HHS Office for Civil Rights (2026). Business Associates. U.S. Department of Health and Human Services. linkThat EHR, backup, and IT vendors are business associates whose BAA governs their breach-notice duties, and that a vendor's breach can still be the practice's obligation to its patients.
  4. 4.U.S. Department of Homeland Security (2026). Ready.gov Business. Ready.gov (DHS/FEMA). linkThe federal continuity framework for recovery — tested backups, a documented restore sequence, and emergency communications while systems are down.
  5. 5.HHS Office for Civil Rights (2026). Individuals' Right under HIPAA to Access their Health Information. U.S. Department of Health and Human Services. linkThat patients retain the right to obtain copies of their records even during an outage, so unfulfilled requests are logged and completed rather than dropped.

https://www.gale.care/for-providers/ecc-ransomware-day-one · 5 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.

Findability, by specialty

How practices like yours get found in local search and AI answers — the honest playbook, per specialty.

SEO for private practices · SEO for AI search / answer engines (all verticals)