Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Ransomware Incident Response for Healthcare: A 72-Hour PlaybookIncident & Breach Response
5 min readFor Data Privacy Officers

Ransomware Incident Response for Healthcare: A 72-Hour Playbook

When the Texas Hearing Institute discovered suspicious network activity on March 20, 2026, they faced a 98-day timeline from detection to patient notification. The Interlock ransomware group exfiltrated 540 GB of data and, when ransom demands went unmet, published patient records online. This isn't about prevention. It's a reality check: your incident response plan will determine whether a breach becomes a containment success or a compliance disaster.

The Problem: Why Your Current IR Plan Won't Work

Most healthcare incident response plans assume immediate breach detection. The Texas Hearing Institute case shows the real timeline: detection on March 20, confirmation of data exposure by April 22, and finalization of affected individuals by June 19. That's three months of investigation, legal review, and forensic analysis while patient data is at risk.

Ransomware-as-a-service groups like Interlock use double-extortion tactics: they encrypt systems and exfiltrate data before detection. Your plan must account for both the HIPAA Security Rule's requirement to secure electronic protected health information and the HITECH Act's 72-Hour Notification Requirement to HHS when a breach affects 500 or more individuals. You're racing against regulatory clocks that start ticking the moment you discover the incident.

What You Need Before Starting

Don't wait for suspicious network activity to assemble these resources:

Immediate access roster: Document contact information for your Computer Security Incident Response Team, third-party forensic specialists (with pre-negotiated response SLAs), legal counsel familiar with HIPAA breach notification requirements, and your cyber insurance carrier. Texas Hearing Institute engaged third-party cybersecurity specialists immediately. Have that contract signed before you need it.

Communication templates: Draft notification letters for patients, business associates, HHS, and state attorneys general. Include placeholders for dates, affected data elements, and mitigation steps. When you're 48 hours into an incident, you don't want your legal team drafting from scratch.

Data inventory map: Maintain a current inventory of where protected health information lives, who has access, and what business associates touch that data. When forensic specialists ask "what systems could have been accessed?", you need answers in hours, not weeks.

Preserved forensic environment: Configure your SIEM or log aggregation tool to retain logs for at least 90 days. Enable detailed logging on file servers, email systems, and authentication infrastructure. Without preserved logs, you can't establish a timeline.

Step-by-Step Implementation

Hour 0-2: Containment and initial assessment

When you identify suspicious activity, your first action determines everything that follows. Isolate affected systems from the network, but do NOT power them down. Ransomware groups often deploy persistence mechanisms that activate on reboot.

Document the initial indicator: Was it an EDR alert? User report? Unusual network traffic? Note the timestamp using a time source you can verify later. This becomes your "date of discovery" for HIPAA notification purposes.

Activate your incident response retainer. Your forensic specialist needs to begin evidence collection immediately. Every hour of delay means potential log rotation and lost evidence.

Hour 2-24: Forensic investigation begins

Your third-party specialist will image affected systems and begin timeline analysis. Simultaneously, your internal team needs to answer three questions:

  1. What patient data exists on potentially compromised systems?
  2. What access controls were in place on those systems?
  3. What evidence exists that data was actually accessed or exfiltrated?

The difference between "accessed" and "potentially accessed" determines your notification obligations. HIPAA's Breach Notification Rule requires notification unless you can demonstrate a low probability that PHI was compromised through a risk assessment. Document that assessment meticulously.

Day 2-30: Scope determination and eradication

This is where Texas Hearing Institute spent April 22 through June 19: determining exactly who was affected. Your forensic team will trace the attacker's lateral movement, identify what files were accessed, and correlate those files to patient records.

Simultaneously, eradicate the threat. This means rebuilding compromised systems from known-good backups or clean images, rotating credentials, and patching the initial access vector. Don't just remove the ransomware. Remove the access path.

For the ransom decision: understand that paying does not guarantee data deletion, does not prevent publication, and may violate OFAC sanctions depending on the threat actor. Texas Hearing Institute chose not to pay. Interlock published the data anyway. Your decision should be informed by legal counsel, cyber insurance requirements, and an honest assessment of your backup recovery capabilities.

Day 30-60: Notification preparation

Once you've finalized the list of affected individuals, you have 60 days from discovery to notify them under HIPAA. Draft your notification letters to include:

  • Description of what happened (in plain language)
  • Types of information involved
  • Steps you're taking to investigate and prevent recurrence
  • What individuals should do to protect themselves
  • How to contact you with questions

Your decision on offering credit monitoring should be based on the sensitivity of exposed data and your risk tolerance for class-action litigation.

Validation: How to Verify It Works

You can't validate incident response in production. Validate it through tabletop exercises every six months.

Run a scenario: "An employee reports their email account is sending messages they didn't write. It's Friday at 4:00 PM." Walk through your playbook step by step. Who makes the containment decision? Who contacts the forensic firm? What gets documented, and where?

Time each decision point. If it takes 45 minutes to reach your IR retainer, that's 45 minutes the attacker is moving laterally. Measure your gaps, then fix them.

Review actual incidents quarterly. Ask: what would that timeline look like for us? Where would we lose time?

Maintenance: Ongoing Tasks

Update your IR plan whenever you onboard a new business associate, deploy a new system that touches PHI, or change your network architecture. A plan based on last year's environment is already obsolete.

Rotate your IR team quarterly. If only your CISO knows how to activate the forensic retainer, you have a single point of failure. Cross-train your security engineers and privacy officers.

Review your cyber insurance policy annually. Confirm your coverage includes forensic investigation, legal counsel, notification costs, and credit monitoring services.

Test your backups monthly. Ransomware groups specifically target backup infrastructure. If you can't restore from backups, your only option is paying the ransom or rebuilding from scratch. Neither is a position you want to negotiate from.

Your incident response plan isn't a compliance checkbox. It's the difference between a contained breach and a catastrophic exposure. Build it, test it, and maintain it like patient safety depends on it. Because it does.

Digital advertisement promoting the whitepaper “The State of Application Security in Modern Software,” showing the cover f the whitepaper and text highlighting AppSec risks, AI code threats, API vulnerabilities, and a button to download the whitepaper.

You Might Also Like