Skip to main content

Hit by ransomware? Isolate affected systems now. Do not reboot or reformat.

SheMo Noransom舍末无勒

Industry solution

Healthcare Ransomware Response and Recovery

When a hospital is hit, registration, consultation, orders, billing, laboratory and imaging fail at the same moment and care falls back to paper. This page covers the healthcare threat picture, a recovery priority built around clinical continuity, and the handling of patient data and compliance obligations.

Critical business systems

  • HIS hospital information system with registration and billing
  • EMR / CPOE electronic records and order entry
  • PACS medical imaging archive and communication
  • LIS laboratory and RIS radiology information systems
  • Pharmacy, IV compounding and SPD consumables systems
  • Health insurance settlement interfaces and public-facing platforms
  • Health check, follow-up and appointment platforms
  • Core databases (Oracle / SQL Server) and virtualization platforms

Threat landscape

Public reporting places healthcare and public health among the most heavily targeted sectors in recent years — the US federal annual internet crime report identified health care as the critical infrastructure sector most affected by ransomware in 2025, and independent public tallies recorded several hundred ransomware incidents against hospitals, clinics and care providers in the same period. Government agencies have also issued dedicated advisories on families including Rhysida, Interlock and Medusa, explicitly noting healthcare impact.

Healthcare's exposure profile is distinctive:

  • Systems must run around the clock, leaving a very narrow patch window. HIS and PACS downtime is costly, so upgrades and reboots must be scheduled, and vulnerabilities persist.
  • Highly heterogeneous devices and systems. Many medical devices ship with their own workstations running vendor-locked legacy operating systems that cannot take standard security software or arbitrary patches.
  • Many connected parties. Vendor remote maintenance, health alliance interconnection, regional platform integration, insurance and third-party service interfaces — weak authentication on any one becomes an entry point.
  • Extremely sensitive data. Records, results, images, identity and insurance information are highly sensitive personal data, and double-extortion exposure carries lasting consequences.
  • Often flat internal networks. With little segmentation between outpatient, inpatient, diagnostic and administrative areas, one infected endpoint can reach the whole hospital.

Business impact

In healthcare the impact lands first on clinical continuity, and only then on data.

  • Outpatient and inpatient workflows degrade. Registration, consultation, order entry, billing, dispensing, and test requests and reports all move to paper, sharply reducing throughput and lengthening waits.
  • Emergency and critical care are affected. Past history, allergies and medication records cannot be consulted, laboratory and imaging results cannot be retrieved in time, and clinical decisions rely on paper and verbal handover — raising risk.
  • Spillover to neighbouring facilities. Published research notes that when one hospital goes offline due to a cyberattack, nearby unaffected hospitals see measurable increases in emergency department volume and ambulance arrivals, straining regional capacity.
  • Data exposure and compliance pressure. Leaked records and identity information trigger handling and notification duties under personal information protection rules, alongside incident reporting obligations to the competent authorities.
  • Heavy back-entry burden after recovery. Paper records created during the outage — prescriptions, test requisitions, nursing notes — must be entered once systems return, a substantial workload that has to stay consistent with the clinical record.

Our response plan

  1. Isolate while activating clinical downtime procedures

    On the technical side, isolate affected segments, cut lateral paths and preserve evidence. On the clinical side, activate the downtime procedure at the same time: switch to paper prescriptions and requisitions, define the manual workflow and its owners, arrange staffing support for key departments, and publish guidance for patients. From the first minute a healthcare incident is a joint technical and clinical operation, with imaging and evidence capture running in parallel across core databases, the virtualization platform and PACS storage.

  2. Identify the family, entry point and exfiltration risk

    Establish the family and encryption mode, then trace the entry point: vendor remote maintenance channels, VPN and health alliance links, exposed service ports, phishing email, regional platform interfaces. Assess exfiltration in parallel: examine anomalous egress traffic, staged archives and upload records to judge whether records and images were taken. That conclusion drives notification and reporting duties, so it must come early rather than after recovery concludes.

  3. Prioritise recovery by clinical continuity

    A workable clinical recovery order: first tier — patient master index, registration and encounter records, current inpatient information, orders and medication, billing and insurance settlement; second tier — LIS laboratory data, current PACS imaging, pharmacy and consumables management; third tier — historical records and imaging archives, research and statistical data, administrative systems. The principle is to restore the register-consult-order-bill-dispense chain first, then bring history back in batches.

  4. Execute recovery with clinical validation

    Complete recovery in an isolated environment and validate jointly with IT and clinical departments: do patient counts and current admissions match, are orders and medication records continuous, do billing and insurance settlement figures agree, can laboratory results and images be retrieved, do interfaces need re-running. At the same time, agree how paper records from the outage will be entered, by whom, by when and how they will be checked. Once validated, return systems in priority batches and maintain heightened monitoring afterwards.

  5. Report, harden, and institutionalise drills

    Help assemble the factual record to support reporting to the competent authorities — China's Administrative Measures for National Cybersecurity Incident Reporting took effect on 1 November 2025 and set explicit reporting deadlines for critical information infrastructure operators, which healthcare institutions should apply according to their classification and regulator's requirements. Technical hardening covers network segmentation (outpatient, inpatient, diagnostics, administration, device zones), funnelling vendor access through a jump host, compensating isolation for legacy medical device workstations, taking the backup estate out of the production domain with immutable copies, and at least one downtime and recovery drill each year.

Common ransomware families

Hardening recommendations

  • Make the downtime procedure a formal, rehearsed process. Paper prescription and requisition templates, manual workflows, departmental responsibilities, external communication lines and back-entry rules should all be defined in advance and drilled annually. In healthcare this is the single most effective control, because it determines clinical safety during an outage.
  • Segment the network. Establish boundaries and access control between outpatient, inpatient, diagnostic equipment, administrative and external-facing zones, and isolate medical device workstations, so one infected endpoint cannot reach the whole hospital.
  • Funnel vendor remote maintenance through one control point. Route HIS, PACS, LIS and device vendor access through a jump host, granted temporarily on demand, fully audited and revoked afterwards, with no permanently open remote tools or shared accounts.
  • Compensating controls for legacy device workstations. Hosts that cannot be upgraded need network isolation, access whitelisting, removable media control and single-purpose use, rather than free communication on the internal network.
  • Enable archiving and an off-site standby for core databases. Run Oracle in ARCHIVELOG mode with a maintained physical standby on a separate segment under separate credentials, and keep at least one offline or immutable backup copy.
  • Plan PACS backup separately. Imaging volumes are large and grow fast, requiring a dedicated backup and archiving strategy rather than reliance on online storage redundancy.
  • Strengthen identity and endpoints. MFA on key accounts, prompt removal of departed and rotated staff accounts, and EDR across servers and office endpoints with tamper protection enabled.
  • Prepare the reporting process in advance. Define the internal escalation path, the external reporting line and the responsible owners, so reports can be filed within the required deadlines when an incident occurs.

Emergency response

Data already encrypted? Stop and let an engineer look first

We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.

Related scenarios

FAQ

Frequently asked questions

  • With HIS down, can outpatient services be restored first?

    Yes, and it is usually the right choice. Recovery is sequenced by clinical continuity: restore the patient master index, registration and encounter records, current inpatient data, orders and medication, and billing and insurance settlement first, so the register-consult-order-bill-dispense chain works again; laboratory history, imaging archives and research data follow in batches. We set the priority list together with IT and the clinical departments, and plan the back-entry of paper records from the outage at the same time.

  • Our PACS imaging data is encrypted — can it be recovered?

    Often, depending on three factors. Encryption coverage: imaging files are large, and many families encrypt only headers or segments of large files, leaving the rest extractable. Storage form: PACS data usually sits on dedicated storage or a NAS, where array and read-only snapshots survive far more often than on ordinary filesystems. Archive copies: long-term imaging typically has an archive tier or offline media that is frequently intact. Bear in mind the sheer volume — recovery duration and storage requirements need planning in advance, and we set out a phased approach during assessment.

  • Patient records may have leaked — do we need to report it?

    That is a judgement for your legal, compliance and supervisory stakeholders; technically we first establish whether exfiltration occurred and its scope. China's Administrative Measures for National Cybersecurity Incident Reporting took effect on 1 November 2025 and set explicit reporting deadlines for critical information infrastructure operators after an incident; healthcare institutions also have duties under their sector regulator and personal information protection rules. Our forensic report provides the timeline, the scope of affected data and the evidentiary basis for the exfiltration assessment, to support those filings.

  • How do we enter the paper records created during the outage?

    Back-entry belongs in the recovery plan from the start, not as an afterthought once systems return. The usual approach: during the outage use standardised, numbered paper forms with a named custodian per department; after recovery, enter them in chronological batches, prioritising what affects ongoing care and settlement (orders, medication, billing, test requests); then reconcile — patient counts and total charges against the paper record. Keep documentation of the whole process for later review.

  • Medical device workstations cannot run antivirus — what can we do?

    Such hosts are usually constrained by vendor certification and cannot take arbitrary security software or patches, so the approach is to substitute network and usage controls for endpoint protection: place them on a dedicated segment with only the required ports open, whitelist the destinations they may reach, forbid web browsing and email, tightly control removable media, and keep them single-purpose rather than dual-use for office work. Bring them into the asset register and monitoring scope so anomalous communication is detected quickly. Agree the design with the device vendor, so compliance and warranty are not affected.

Updated