Ransomware hit your practice.
Do this first.

Breathe. Then work the list: five calls, in order. Print this page and tape it inside your server room door.

  1. 1

    Your IT support

    Tell them: systems are locked, screens show a ransom note. Have them disconnect affected machines from the network — unplug the cable, don't just close the laptop. Do not power anything off: dead machines lose forensic evidence.

  2. 2

    Your cyber insurance breach hotline

    The 24/7 number on your policy. They assign a breach coach and approve the vendors. Call them before you hire anyone or pay anything.

  3. 3

    A healthcare breach attorney

    Don't have one? Your insurer will assign one. From this point on, everything goes through counsel — that's what keeps the forensics under privilege.

  4. 4

    The FBI — ic3.gov

    File a report at ic3.gov. It helps law enforcement track the group, and a paper trail of cooperation looks good to regulators later.

  5. 5

    Your partners and administrator

    Short and factual: what happened, what's contained, who's engaged. No speculation, nothing in writing beyond the facts.

Do not

  • Pay the ransom yet. Payment doesn't guarantee your files back, and paying some groups is illegal.
  • Keep using the systems. Every click can spread it further.
  • Delete anything. Logs, emails, the ransom note itself — that's evidence.
  • Post about it. No social media, no press, until your attorney says so.

After the first hour

Your attorney runs the playbook from here: forensics first, then notifications. Under HIPAA you have 60 days to notify HHS and affected patients — but your counsel decides the timing and the wording, not the clock.

This is a first-response sheet, not legal advice. Your breach attorney makes the legal calls — this just gets you to them faster.

Want someone who answers the phone when this happens?

Every practice should have this conversation before they need it.

Get in Touch