The First Hours After Ransomware Hits Your Practice
Cyberattacks on health care organizations now disrupt care, not just computers. Physicians need a downtime plan that has been practiced, printed, and understood before the screens go dark.
The first sign is small. A front desk computer will not open the schedule. Then the EHR slows to a stop, a strange message appears on a shared drive, and IT asks everyone to unplug their workstations. By midmorning, the clinic has patients in the waiting room, no access to medication lists, and no clear idea when systems will return.
Ransomware attacks against hospitals, practices, and the vendors they depend on have become a persistent threat. HHS has repeatedly warned health care organizations about the risk, and recent large incidents have shown that an attack on a single clearinghouse or technology partner can disrupt care and cash flow for practices that were never directly breached. Physicians cannot delegate this entirely to IT, because the clinical response is ours.
Build a downtime plan clinicians can use
Most organizations have an IT recovery plan. Fewer have a clinical downtime plan that a physician, nurse, or front desk worker could follow on paper. It should answer practical questions. How will we identify today's patients? How will we see medication lists and allergies? How will we document, order tests, and prescribe? How will we communicate with each other if email and messaging are also down?
- Keep printed downtime forms and a current contact list in a known location.
- Arrange for a regularly updated, read only copy of key patient information that can be accessed offline.
- Identify which services you would pause and which must continue.
- Know how you would reach pharmacies, labs, and referring hospitals by phone.
The time to discover your downtime plan is incomplete is not the morning you need it.
Practice it at least once a year
A plan in a binder is a hypothesis. Run a tabletop exercise with physicians, nurses, front desk staff, and billing. Walk through the first hour, the first day, and the first week of an outage. You will find gaps quickly. The printer that needs the network. The phone system that runs through the internet. The staff member who is the only one who knows the backup password.
Include the business side. How would you pay staff and cover rent if claims could not be submitted for several weeks? Talk with your bank and advisors about contingency funding before you need it.
Ask better questions of your vendors
Your exposure extends to every partner that touches your data. Ask EHR, billing, and clearinghouse vendors how they back up systems, how quickly they expect to restore service after an incident, and how they would notify you. Review your cyber insurance policy with a broker who can explain what is and is not covered.
Basic security measures still matter, including multifactor authentication, timely software updates, tested offline backups, and phishing training that respects staff time. None of these is glamorous. All of them reduce risk.
This week, ask one question at your next staff huddle. If the computers went down right now, what would we do first? The answers will tell you how ready you are.
This article is for professional education and does not replace clinical judgment. Treatment decisions should be based on the individual patient and current guidelines.
