Ransomware hit your practice.
Do this first.
Breathe. Then work the list: five calls, in order. Print this page and tape it inside your server room door.
-
1
Your IT support
Tell them: systems are locked, screens show a ransom note. Have them disconnect affected machines from the network — unplug the cable, don't just close the laptop. Do not power anything off: dead machines lose forensic evidence.
-
2
Your cyber insurance breach hotline
The 24/7 number on your policy. They assign a breach coach and approve the vendors. Call them before you hire anyone or pay anything.
-
3
A healthcare breach attorney
Don't have one? Your insurer will assign one. From this point on, everything goes through counsel — that's what keeps the forensics under privilege.
-
4
The FBI — ic3.gov
File a report at ic3.gov. It helps law enforcement track the group, and a paper trail of cooperation looks good to regulators later.
-
5
Your partners and administrator
Short and factual: what happened, what's contained, who's engaged. No speculation, nothing in writing beyond the facts.
Do not
- Pay the ransom yet. Payment doesn't guarantee your files back, and paying some groups is illegal.
- Keep using the systems. Every click can spread it further.
- Delete anything. Logs, emails, the ransom note itself — that's evidence.
- Post about it. No social media, no press, until your attorney says so.
After the first hour
Your attorney runs the playbook from here: forensics first, then notifications. Under HIPAA you have 60 days to notify HHS and affected patients — but your counsel decides the timing and the wording, not the clock.
This is a first-response sheet, not legal advice. Your breach attorney makes the legal calls — this just gets you to them faster.
Want someone who answers the phone when this happens?
Every practice should have this conversation before they need it.
Get in Touch