Prepare for ransomware as both a cybersecurity incident and a patient-care continuity event. A healthcare organization should know who will lead the response, how staff will keep critical services running, which systems and data must be restored first, and how recovery will be verified. HHS warns that every healthcare organization, regardless of size, is a potential target.
What healthcare ransomware readiness needs to cover
A ransomware plan should connect cybersecurity response to clinical and operational decisions. It needs to guide the organization from detection through containment, recovery, and review—not just describe how to remove malicious software.
For U.S. organizations, HHS guidance provides two useful but distinct reference points: HIPAA Security Rule requirements for covered entities and business associates, and the voluntary Healthcare and Public Health Cybersecurity Performance Goals (CPGs), which help prioritize cybersecurity practices. The CPGs are not a substitute for determining which legal requirements apply to your organization.
Build an incident response plan people can use
Maintain an incident response plan alongside the contingency plans needed to sustain operations during an emergency. Keep the plans current, make them accessible when normal systems are unavailable, and practice them with the people expected to carry them out. HHS identifies incident planning and preparedness—including maintained and exercised plans—as a priority.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- FortiWiFi-30G Hardware plus 1 Year FortiCare Premium and FortiGuard Unified Threat Protection (UTP) (SKU: FWF-30G-A-BDL-950-12)
- All-in-one next-generation security: Delivers enterprise-grade protection with AI-powered firewalling, secure SD-WAN, and built-in Wi-Fi 6 for fast, reliable business connectivity.
- Delivers an integrated security suite combining firewall, intrusion prevention, web filtering, and application control in one subscription. Protects your organization from malware, ransomware, and phishing attacks while maintaining network performance and simplified management.
- Responsive performance for daily use: Achieves up to 4 Gbps firewall throughput, 570 Mbps NGFW, and 500 Mbps threat protection, keeping apps, users, and data secure without slowdowns.
- Reliable Wi-Fi 6 coverage: Dual-band wireless (2.4 GHz + 5 GHz) supports 802.11 a/b/g/n/ac/ax for stronger signal, higher speed, and better efficiency in crowded office networks.
Assign responsibilities before an incident
Map responsibilities to named roles and alternates. This role map is an implementation recommendation, not an HHS-prescribed organization chart.
- Incident command: Coordinate decisions, priorities, and escalation.
- Technical response: Investigate affected systems, contain the incident, remove ransomware, and support restoration.
- Clinical and operational leadership: Decide how to deliver care and maintain essential processes during downtime.
- Privacy and legal review: Assess the handling of protected health information (PHI), applicable obligations, and notification questions.
- Communications and executive escalation: Coordinate internal and external updates and bring decisions to the appropriate leadership.
Prepare for normal communication systems to fail
Write down escalation contacts and safe ways to reach internal teams and external responders if email, identity services, or network systems are unavailable. The reviewed HHS guidance does not prescribe a particular communications product or vendor.
Know what must keep running and what to restore first
Maintain current inventories of endpoints, servers, applications, and critical data. Include the dependencies needed to deliver care so responders can understand what an outage affects and what must be available before a service can return.
Identify critical applications and data, then document recovery priorities and dependencies. Pair that order with emergency operations and downtime workflows, so clinical and operational teams know how to function while systems are unavailable. HHS contingency-planning guidance covers identifying critical applications and data, disaster recovery, and continuation of critical processes in emergency mode.
Free tools Windows power users keep installed
One-click scans. No signup required.
Protect backups and prove they can be restored
Maintain frequent backups and a recovery plan. HHS advises organizations to consider offline backups because some ransomware variants can disrupt online backups. An offline copy is one possible approach, not a complete backup strategy by itself.
Periodically restore representative data and systems to verify that copies are intact and that the organization can recover them. Use the results to identify gaps in the recovery plan, including whether restoration works with the organization’s systems and priorities.
Rank #3
- SonicWall Capture Advanced Threat Protection (ATP) For TZ570 - 1 Year License (02-SSC-5083)
- Multi-Engine Sandboxing Technology: Detects and blocks zero-day threats, ransomware, and unknown malware before they enter your network.
- Real-Time Deep Memory Inspection (RTDMI): Uncovers evasive, memory-based attacks that traditional defenses miss by analyzing code behavior at runtime.
- Seamless Firewall Integration: Works in tandem with SonicWall firewalls and security services for automated breach prevention and response.
- Cloud-Based Threat Intelligence: Leverages SonicWall's global GRID network to provide continuous updates and intelligent analysis of emerging threats.
If using an encrypted external drive for an offline copy, evaluate whether it fits the organization’s backup architecture. Consider capacity and retention, encryption and key management, compatibility, access controls, custody, connection procedures, recovery speed, auditability, and restoration testing. HHS supports considering offline backups; it does not endorse a particular device, brand, capacity, or encryption implementation.
Exercise the plan and prioritize safeguards
Run tabletop scenarios and recovery exercises with leaders and operational stakeholders as well as technical staff. Practice decisions and handoffs, not only technical recovery. Update the plan based on what the exercises reveal, and repeat exercises as systems, dependencies, and responsibilities change.
The voluntary HHS CPGs can help organizations prioritize measures such as incident planning, unique credentials, separate privileged accounts, asset inventory, and centralized log collection. Use them as a practical baseline alongside—not in place of—an assessment of applicable legal requirements.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Follow a deliberate response and recovery sequence
Use the organization’s tested procedures and trained response team. Containment choices depend on the affected environment and potential consequences for patient care, so there is no universal isolation instruction that fits every incident.
- Detect and analyze: Determine which systems, applications, and networks are affected; when and how the event began; whether it is ongoing; and whether it has spread.
- Contain: Limit impact and propagation using procedures suited to the incident and the organization’s care and operational needs.
- Eradicate and remediate: Remove ransomware instances and address the weaknesses that enabled entry or spread.
- Recover: Restore data and return systems to normal operations under the contingency plan. Prioritize critical applications and patient-care processes, and verify backup integrity as restoration proceeds.
- Review obligations and learn: Assess the incident, document relevant facts and decisions, address applicable notification duties, and update plans and controls based on what happened.
Assess HIPAA breach status based on the facts
Under HHS guidance, ransomware presence is a security incident, but whether it constitutes a HIPAA breach is fact-specific. Encryption alone does not settle the question. The assessment should consider whether PHI may have been impermissibly acquired, accessed, used, or disclosed, including the possibility of exfiltration, and should document the facts and reasoning.
HHS says covered entities and business associates must maintain security incident procedures and response and reporting processes, as well as contingency planning that includes data backup, disaster recovery, and emergency operations. The requirements applicable to a particular organization or incident—and any reporting duties or deadlines—need incident-specific review with appropriate legal counsel and current authoritative guidance.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

