The short answer: disconnect affected machines from the network (don’t power them off), call your IT provider’s emergency line before anything else, touch nothing on the encrypted machines, don’t pay or reply, and start your paper workflow while professionals work. Speed matters, but the wrong speed — rebooting, deleting, negotiating — destroys evidence and recovery options.

Minute 0–5: Contain

  • Unplug the network cable (or kill Wi-Fi) on any machine showing the note or behaving strangely. Isolation stops spread.
  • Do NOT power machines off. Memory can hold encryption keys and evidence that vanish on shutdown. Disconnect, don’t shut down.
  • If spread seems active — files changing across multiple machines — disconnect the switch or turn off Wi-Fi at the access points. A whole-office network pause is cheaper than a whole-office encryption.

Minute 5–15: Call for help

  • Call your IT provider’s emergency line. Phoenix clients: the machine was likely already isolated automatically by endpoint detection, and our SOC is calling you — but call anyway: 612-642-2753. If your provider doesn’t have a 24/7 emergency line, write that down for later.
  • Name one internal decision-maker — usually the owner or practice manager. Everyone else keeps hands off keyboards.
  • Start a timeline note on paper or a phone: what was seen, when, by whom. Insurers and investigators will ask.

Minute 15–60: Protect the practice

  • Don’t touch the ransom note beyond photographing it with a phone. No replying, no “just seeing the price,” no paying. Contact with attackers is a specialist’s job, and payment is a last-resort decision made with counsel and insurers — none of our clients has ever needed to.
  • Don’t delete anything or run cleanup tools. Well-meaning “scans” destroy the forensic picture that determines whether patient data was actually taken — which drives your legal duties.
  • Change critical passwords from a clean device — a phone on cellular, not an office computer: email first, then banking, then remote access.
  • Notify your cyber insurer’s hotline if you carry coverage. Early notice preserves coverage; late notice can void it.
  • Switch to paper workflow — the schedule was in this morning’s huddle, appointment cards and a printed day-sheet keep patients moving.

What recovery looks like when preparation was real

With immutable, tested backups and 24/7 detection, the typical timeline is: isolation within minutes, clean recovery point identified within hours, priority systems restored the same day, and a written root-cause report within the week. Without those things, the timeline is measured in weeks and the outcome negotiated with criminals. The difference is decided before the note appears — that’s the whole argument for managed detection and response paired with real disaster recovery.

Post this near the front desk: 1) Unplug network, not power. 2) Call IT emergency line. 3) One decision-maker, everyone else hands off. 4) Photograph, don’t touch. 5) Paper workflow. 6) No payment conversations without counsel.

HIPAA-covered practices: a ransomware event may trigger breach-assessment duties even if you recover cleanly. Our HIPAA explainer covers the documentation side, and we support the technical half of any notification analysis.