HIPAA Ransomware Attack Response: Step-by-Step Guide

Critical steps for containment, law enforcement coordination, and breach notification

Immediate Action Required

Response Timeline

First 24 Hours (Containment Phase)

  • Activate incident response protocol immediately
  • Identify all infected systems and isolate from network
  • Document the ransom note with all details (sender, demands, timeline)
  • Preserve forensic evidence - do not clean or attempt recovery
  • Contact your cyber insurance provider and law firm
  • Engage a reputable forensic investigation firm
  • Assess impact on patient care and operational continuity
  • Determine which systems contain patient data
  • Notify your CIO/CISO and executive leadership

24-72 Hours (Assessment & Law Enforcement)

  • File a report with the FBI (ic3.gov or local field office)
  • Report to HHS if patient data appears compromised
  • Conduct forensic analysis of the attack vector
  • Determine if data was exfiltrated or only encrypted
  • Assess the scope of patient data potentially affected
  • Work with forensics team and law enforcement on investigation
  • Evaluate whether decryption keys are available
  • Do not pay ransom without law enforcement and counsel guidance

1-2 Weeks (Breach Assessment & Recovery Planning)

  • Complete forensic investigation and determine breach classification
  • Prepare detailed breach assessment documentation
  • Work with forensics to confirm if data was accessed/exfiltrated
  • Determine number of affected patients
  • Develop comprehensive recovery and restoration plan
  • Create breach notification messaging and timeline
  • Begin system restoration from clean backups
  • Prepare OCR notification if breach is confirmed

First 30 Days (Notification & Recovery)

  • Send breach notifications to affected patients (if required)
  • Notify media if 500+ patients affected in any jurisdiction
  • File OCR breach report if data was accessed
  • Provide patient credit monitoring and identity protection
  • Complete system restoration and validation testing
  • Restore normal business operations in phases
  • Document all incident response actions

60+ Days (Remediation & Prevention)

  • Submit OCR final notification if required
  • Implement security improvements and hardening
  • Update backup and disaster recovery procedures
  • Conduct staff retraining on phishing and security
  • Update incident response plan with lessons learned
  • Monitor for evidence of data sales or misuse
  • Maintain documentation for potential investigations

Law Enforcement Coordination

Ransomware attacks often warrant law enforcement involvement:

Breach Assessment

A critical question is whether the attack constitutes a HIPAA breach:

Recovery and Prevention

Recovery from ransomware:

Prevention measures:

Frequently Asked Questions

Should I pay the ransom?
FBI and HHS recommend against paying ransoms, as it funds criminal activity and does not guarantee data recovery. There are no HIPAA exceptions that require paying ransom. Explore other recovery options first, including backups and law enforcement assistance. Consult with your legal and law enforcement contacts before any payments.
How quickly must I report a ransomware attack?
You must file an FBI report if there is evidence of unauthorized access or data acquisition. File within 24 hours if possible. Breach notification to patients must occur within 60 days if data was accessed or the attack compromised patient data. Report to HHS OCR as part of breach notification process.
Is a ransomware attack always a breach?
Not necessarily. If you have forensic evidence the attacker only encrypted data without accessing or exfiltrating it, you may not have a reportable breach. However, HIPAA requires you to conduct a thorough investigation using forensic experts. When in doubt, treat it as a breach and notify patients.
What should I do if systems are locked?
Immediately isolate affected systems from the network to prevent spread. Do not attempt recovery actions that might destroy forensic evidence. Contact law enforcement and a forensic investigator before attempting recovery. Document all actions taken during the first hours of discovery.

Strengthen Your Ransomware Defenses

Comprehensive security risk analysis can identify weaknesses before an attack occurs.

Get Your Security Analysis