Industry solution
Healthcare Ransomware Response and Recovery
When a hospital is hit, registration, consultation, orders, billing, laboratory and imaging fail at the same moment and care falls back to paper. This page covers the healthcare threat picture, a recovery priority built around clinical continuity, and the handling of patient data and compliance obligations.
Critical business systems
- HIS hospital information system with registration and billing
- EMR / CPOE electronic records and order entry
- PACS medical imaging archive and communication
- LIS laboratory and RIS radiology information systems
- Pharmacy, IV compounding and SPD consumables systems
- Health insurance settlement interfaces and public-facing platforms
- Health check, follow-up and appointment platforms
- Core databases (Oracle / SQL Server) and virtualization platforms
Threat landscape
Public reporting places healthcare and public health among the most heavily targeted sectors in recent years — the US federal annual internet crime report identified health care as the critical infrastructure sector most affected by ransomware in 2025, and independent public tallies recorded several hundred ransomware incidents against hospitals, clinics and care providers in the same period. Government agencies have also issued dedicated advisories on families including Rhysida, Interlock and Medusa, explicitly noting healthcare impact.
Healthcare's exposure profile is distinctive:
- Systems must run around the clock, leaving a very narrow patch window. HIS and PACS downtime is costly, so upgrades and reboots must be scheduled, and vulnerabilities persist.
- Highly heterogeneous devices and systems. Many medical devices ship with their own workstations running vendor-locked legacy operating systems that cannot take standard security software or arbitrary patches.
- Many connected parties. Vendor remote maintenance, health alliance interconnection, regional platform integration, insurance and third-party service interfaces — weak authentication on any one becomes an entry point.
- Extremely sensitive data. Records, results, images, identity and insurance information are highly sensitive personal data, and double-extortion exposure carries lasting consequences.
- Often flat internal networks. With little segmentation between outpatient, inpatient, diagnostic and administrative areas, one infected endpoint can reach the whole hospital.
Business impact
In healthcare the impact lands first on clinical continuity, and only then on data.
- Outpatient and inpatient workflows degrade. Registration, consultation, order entry, billing, dispensing, and test requests and reports all move to paper, sharply reducing throughput and lengthening waits.
- Emergency and critical care are affected. Past history, allergies and medication records cannot be consulted, laboratory and imaging results cannot be retrieved in time, and clinical decisions rely on paper and verbal handover — raising risk.
- Spillover to neighbouring facilities. Published research notes that when one hospital goes offline due to a cyberattack, nearby unaffected hospitals see measurable increases in emergency department volume and ambulance arrivals, straining regional capacity.
- Data exposure and compliance pressure. Leaked records and identity information trigger handling and notification duties under personal information protection rules, alongside incident reporting obligations to the competent authorities.
- Heavy back-entry burden after recovery. Paper records created during the outage — prescriptions, test requisitions, nursing notes — must be entered once systems return, a substantial workload that has to stay consistent with the clinical record.
Our response plan
Isolate while activating clinical downtime procedures
On the technical side, isolate affected segments, cut lateral paths and preserve evidence. On the clinical side, activate the downtime procedure at the same time: switch to paper prescriptions and requisitions, define the manual workflow and its owners, arrange staffing support for key departments, and publish guidance for patients. From the first minute a healthcare incident is a joint technical and clinical operation, with imaging and evidence capture running in parallel across core databases, the virtualization platform and PACS storage.
Identify the family, entry point and exfiltration risk
Establish the family and encryption mode, then trace the entry point: vendor remote maintenance channels, VPN and health alliance links, exposed service ports, phishing email, regional platform interfaces. Assess exfiltration in parallel: examine anomalous egress traffic, staged archives and upload records to judge whether records and images were taken. That conclusion drives notification and reporting duties, so it must come early rather than after recovery concludes.
Prioritise recovery by clinical continuity
A workable clinical recovery order: first tier — patient master index, registration and encounter records, current inpatient information, orders and medication, billing and insurance settlement; second tier — LIS laboratory data, current PACS imaging, pharmacy and consumables management; third tier — historical records and imaging archives, research and statistical data, administrative systems. The principle is to restore the register-consult-order-bill-dispense chain first, then bring history back in batches.
Execute recovery with clinical validation
Complete recovery in an isolated environment and validate jointly with IT and clinical departments: do patient counts and current admissions match, are orders and medication records continuous, do billing and insurance settlement figures agree, can laboratory results and images be retrieved, do interfaces need re-running. At the same time, agree how paper records from the outage will be entered, by whom, by when and how they will be checked. Once validated, return systems in priority batches and maintain heightened monitoring afterwards.
Report, harden, and institutionalise drills
Help assemble the factual record to support reporting to the competent authorities — China's Administrative Measures for National Cybersecurity Incident Reporting took effect on 1 November 2025 and set explicit reporting deadlines for critical information infrastructure operators, which healthcare institutions should apply according to their classification and regulator's requirements. Technical hardening covers network segmentation (outpatient, inpatient, diagnostics, administration, device zones), funnelling vendor access through a jump host, compensating isolation for legacy medical device workstations, taking the backup estate out of the production domain with immutable copies, and at least one downtime and recovery drill each year.
Common ransomware families
- Some versions decryptable
Rhysida
Rhysida is a RaaS operation active since 2023, marked by the .rhysida extension and a CriticalBreachDetected.pdf ransom note. It hits healthcare, education, manufacturing and government, ships an ESXi encryptor, and a subset of early Windows samples can be recovered with a free decryptor.
- No public decryptor
Interlock
Interlock emerged in September 2024 as a double-extortion crew marked by .interlock / .1nt3rlock extensions and the !__README__!.txt note. It relies on drive-by downloads, ClickFix fake-CAPTCHA social engineering and edge-device zero-days, and was covered by a CISA #StopRansomware advisory in 2025. No public decryptor exists.
- Some versions decryptable
GlobeImposter
GlobeImposter has been active since 2017 and is highly prevalent in China through its Chinese-zodiac variants (such as .Dragon4444) and Olympian-gods variants (such as .Ares666). It spreads by brute-forcing RDP/SMB and moving laterally, and caused widespread hospital infections in China in 2018. Mainstream variants have no decryptor.
- Free decryptor available
Phobos
Phobos is a RaaS family that relies mainly on brute-forced RDP and has spawned a long list of variants (.eking, .faust, .elbie, .devos and more). It has been a persistent presence in Chinese server-ransomware cases, and in July 2025 Japan's National Police Agency released a free decryptor covering part of the lineage.
- No public decryptor
TellYouThePass
TellYouThePass is the archetypal vulnerability-driven ransomware family in China, mass-deployed against internet-facing ERP, OA, finance and middleware systems. It appends .locked and hits both Windows and Linux servers. No public decryptor exists.
Hardening recommendations
- Make the downtime procedure a formal, rehearsed process. Paper prescription and requisition templates, manual workflows, departmental responsibilities, external communication lines and back-entry rules should all be defined in advance and drilled annually. In healthcare this is the single most effective control, because it determines clinical safety during an outage.
- Segment the network. Establish boundaries and access control between outpatient, inpatient, diagnostic equipment, administrative and external-facing zones, and isolate medical device workstations, so one infected endpoint cannot reach the whole hospital.
- Funnel vendor remote maintenance through one control point. Route HIS, PACS, LIS and device vendor access through a jump host, granted temporarily on demand, fully audited and revoked afterwards, with no permanently open remote tools or shared accounts.
- Compensating controls for legacy device workstations. Hosts that cannot be upgraded need network isolation, access whitelisting, removable media control and single-purpose use, rather than free communication on the internal network.
- Enable archiving and an off-site standby for core databases. Run Oracle in ARCHIVELOG mode with a maintained physical standby on a separate segment under separate credentials, and keep at least one offline or immutable backup copy.
- Plan PACS backup separately. Imaging volumes are large and grow fast, requiring a dedicated backup and archiving strategy rather than reliance on online storage redundancy.
- Strengthen identity and endpoints. MFA on key accounts, prompt removal of departed and rotated staff accounts, and EDR across servers and office endpoints with tamper protection enabled.
- Prepare the reporting process in advance. Define the internal escalation path, the external reporting line and the responsible owners, so reports can be filed within the required deadlines when an incident occurs.
Emergency response
Data already encrypted? Stop and let an engineer look first
We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.
Related scenarios
Oracle Database Encrypted by Ransomware
When Oracle datafiles (.dbf), control files and archived redo logs are encrypted, hospital HIS, large ERP and group finance systems typically go down as a whole. This page covers triage order, the role of control files and archived logs, and when block-level repair or RMAN restore applies.
Database Encrypted by Ransomware
When database files are encrypted, every business system that depends on them stops at once. This page explains how we triage an encrypted database, how recoverability is assessed, and when file repair, backup-plus-log restore, or rebuild is the right path.
ESXi / Hyper-V Virtualization Encrypted by Ransomware
Hypervisor-level encryption causes the widest blast radius of any ransomware event: dozens of production VMs go dark within an hour or two. This page covers what Linux ESXi encryptors actually do — shut down guests, encrypt vmdk, delete snapshots — the recovery value of flat disk files, and how Hyper-V and Proxmox cases differ.
Backups Deleted or Destroyed
Modern ransomware follows a fixed sequence: destroy the backups, then encrypt the data — deleting shadow copies, encrypting repositories, disabling jobs, and exploiting backup software flaws to steal credentials. This page covers what can still be inventoried once backups fail, why replication propagates encrypted files off-site, and what offline and immutable copies are really worth.
File Servers and NAS Encrypted by Ransomware
When shared folders on a file server or NAS are encrypted, drawings, contracts, archives, quotations and design sources all become unusable at once — and mapped drives spread the impact to every endpoint. This page covers how to gauge spread, what shadow copies and snapshots realistically offer, and how to sequence recovery by business value.
Related services
Incident Response
Round-the-clock intake: contain first, preserve evidence second, recover third.
Data Recovery
Recovery beyond decryption: backup repair, database repair and remnant extraction.
Attack Forensics & Attribution
Establish the intrusion path, timeline and impact — in a report usable for police reporting and compliance.
Security Hardening
Close the handful of paths attackers actually use: exposure, weak credentials, patches, privilege, backups.
FAQ
Frequently asked questions
With HIS down, can outpatient services be restored first?
Yes, and it is usually the right choice. Recovery is sequenced by clinical continuity: restore the patient master index, registration and encounter records, current inpatient data, orders and medication, and billing and insurance settlement first, so the register-consult-order-bill-dispense chain works again; laboratory history, imaging archives and research data follow in batches. We set the priority list together with IT and the clinical departments, and plan the back-entry of paper records from the outage at the same time.
Our PACS imaging data is encrypted — can it be recovered?
Often, depending on three factors. Encryption coverage: imaging files are large, and many families encrypt only headers or segments of large files, leaving the rest extractable. Storage form: PACS data usually sits on dedicated storage or a NAS, where array and read-only snapshots survive far more often than on ordinary filesystems. Archive copies: long-term imaging typically has an archive tier or offline media that is frequently intact. Bear in mind the sheer volume — recovery duration and storage requirements need planning in advance, and we set out a phased approach during assessment.
Patient records may have leaked — do we need to report it?
That is a judgement for your legal, compliance and supervisory stakeholders; technically we first establish whether exfiltration occurred and its scope. China's Administrative Measures for National Cybersecurity Incident Reporting took effect on 1 November 2025 and set explicit reporting deadlines for critical information infrastructure operators after an incident; healthcare institutions also have duties under their sector regulator and personal information protection rules. Our forensic report provides the timeline, the scope of affected data and the evidentiary basis for the exfiltration assessment, to support those filings.
How do we enter the paper records created during the outage?
Back-entry belongs in the recovery plan from the start, not as an afterthought once systems return. The usual approach: during the outage use standardised, numbered paper forms with a named custodian per department; after recovery, enter them in chronological batches, prioritising what affects ongoing care and settlement (orders, medication, billing, test requests); then reconcile — patient counts and total charges against the paper record. Keep documentation of the whole process for later review.
Medical device workstations cannot run antivirus — what can we do?
Such hosts are usually constrained by vendor certification and cannot take arbitrary security software or patches, so the approach is to substitute network and usage controls for endpoint protection: place them on a dedicated segment with only the required ports open, whitelist the destinations they may reach, forbid web browsing and email, tightly control removable media, and keep them single-purpose rather than dual-use for office work. Bring them into the asset register and monitoring scope so anomalous communication is detected quickly. Agree the design with the device vendor, so compliance and warranty are not affected.
Updated