What Should Be in a Houston Medical Practice's Incident Response Plan for a Ransomware Attack?
If ransomware hits your practice tonight, only one thing will matter in the first hour: a written plan your team already knows, not one you're writing from scratch while patient records sit locked. Under HIPAA, a breach involving patient health information starts a 60-day clock to notify every affected patient, and regulators expect practices to show they had a real response process in place before the incident, not one improvised after. A working incident response plan covers five things: containment, notification, eradication, recovery, and the paper trail proving you followed it — most Houston practices we assess are missing at least two of the five.
Why the Plan Has to Be Written Down, Not Just “Known”
Every practice owner believes their office manager or IT contact “knows what to do” if something goes wrong. That confidence rarely survives the actual event. Ransomware usually hits outside business hours, the person who “knows what to do” may be on vacation or may have left the practice entirely, and decisions made under pressure without a checklist tend to make the damage worse — powering off an infected machine and destroying forensic evidence, for example, or restoring from a backup before confirming it's clean.
There's also a compliance dimension. If a breach investigation ever happens, regulators don't ask whether your staff is capable — they ask for the document. A HIPAA risk analysis is expected to identify ransomware as a threat and show a documented response plan as a mitigating control. “We would have figured it out” is not something you can hand an investigator.
Staff turnover makes this worse over time. The employee who set up your backup system or who has the vendor's support number memorized may not be the person answering the phone when ransomware actually hits — practices lose that tribal knowledge every time someone changes jobs. A written plan is the only version of that knowledge that doesn't walk out the door.
The First Hour: Containment Before You Call Anyone
The first hour decides how far the damage spreads. Before anyone starts making phone calls, the plan should walk through:
- Isolate, don't power off: Disconnect the infected device from the network (unplug the cable, disable Wi-Fi) but leave it running. Powering it off can destroy the evidence needed to figure out how the attacker got in and whether other systems are affected.
- Identify patient zero: Find the first device that showed symptoms and check what it's connected to — shared drives, practice management systems, backup targets — so you know how far to check for spread.
- Loop in IT immediately: Your managed IT provider or internal IT contact should be the very next call, before leadership discussions about ransom payment or public statements. They need time on the clock to assess scope.
- Don't negotiate or pay before assessing: Paying a ransom doesn't guarantee working decryption keys, doesn't undo a data breach that already occurred, and can trigger separate legal exposure depending on who the attacker turns out to be. That decision comes after assessment, not instead of one.
Who You're Required to Notify, and How Fast
Once the practice confirms patient health information was affected, HIPAA's breach notification rule sets hard deadlines, not suggestions:
- Affected patients: Written notice within 60 days of discovering the breach — not 60 days from when the attack started, from when you found out about it.
- HHS Office for Civil Rights: Breaches affecting 500 or more individuals must be reported to OCR within 60 days, at the same time as patient notification. Smaller breaches can be logged and reported annually, but still need to be tracked as they happen.
- Media notification: Required if a breach affects 500 or more residents of a single state or jurisdiction — an obligation many smaller practices don't realize applies to them.
- Your cyber insurance carrier: Most policies require notification within a specific window — often 24 to 72 hours — and missing that window can jeopardize coverage entirely, separate from the HIPAA timeline.
What Belongs in the Written Plan Itself
A usable incident response plan is short enough that someone can follow it under stress. At minimum it should include:
- A designated incident commander: One named person (with a backup) who has authority to make containment decisions without waiting for a partner meeting.
- A contact tree: Direct phone numbers for your managed IT provider, cyber insurance carrier, breach counsel, and internal leadership — not email addresses that go unread during an active incident.
- A current systems and backup inventory: What's backed up, where, how often, and exactly how to restore it — the middle of an attack is the wrong time to discover no one knows the recovery process.
- Notification templates: A draft patient notification letter and staff talking points prepared in advance, so the 60-day clock isn't spent partly on legal drafting.
- A post-incident review step: A short process for documenting what happened and what changes afterward — this is also the record that shows regulators and insurers the practice takes its safeguards seriously.
How Managed IT Shortens the Timeline and Limits the Damage
[PLACEHOLDER: Brief description of a real or representative Houston medical practice ransomware incident — how it started, how fast it was contained, and the recovery time/outcome. Replace this paragraph with a real client story before publishing, or keep it as a generic pattern if none is available yet.]
We came highly recommended to a plastic surgery practice by the new practice manager. We have worked with this practice manager at the different plastic surgery in Katy TX a few years back, so when got hired at this firm she saw that HIPAA gaps in the infrastructure and the long responds time with current Managed service provider, she knew that she needed us to take over to make the firm secured.
It took about 3 months for us to get hired since the previous Managed Service provider had a contract and owners needed the contract to expired. When we took and over we started to put our security stack in place and locked the system down, we found that that there was compromised email that was being monitored for about 3 months, fortunately we took the steps necessary to remove access and lock the system down
The technical controls in the plan matter as much as the paperwork. Behavior-based endpoint detection with 24x7 SOC response can isolate a ransomware process within minutes of it starting to encrypt files, often before it reaches a second device — turning a practice-wide outage into a single-workstation cleanup. Microsoft 365 backup with a full year of retention means patient records and email can be restored to a point before the infection, rather than negotiating with an attacker for a decryption key. Proactive cloud account security monitoring catches the compromised login that often precedes a ransomware deployment by days, giving the practice a chance to lock things down before encryption ever starts.
These are the technical controls built into Scorpion's Assured and Complete plans, and they're also exactly the controls HIPAA risk analyses, cyber insurance applications, and a well-written incident response plan all point back to. The plan tells your team what to do; the technology buys them the time to do it.
If your practice doesn't have a written plan today, a HIPAA risk analysis is a reasonable place to start — before an attacker decides the timeline for you.
Scorpion Technology has served small businesses and healthcare practices across Houston, Dallas, Austin, and San Antonio for over 19 years. We specialize in HIPAA-compliant IT for medical practices and professional services firms, with a 15-minute guaranteed response time for all managed clients. Our team is local, responsive, and built around keeping your practice running — not just fixing problems when they break. Learn more at ScorpionITSupport.com or call 713-623-1266.
