Blog / Threats
Threats
Ransomware in a Clinic: What Nine Days Without the EHR Really Looks Like
Healthcare ransomware stops refills, referrals and the front desk, not just files. What nine days of EHR downtime looks like, and how a small practice prepares.
Day one: the front desk finds the paper forms
The practice manager of a four-physician pediatric practice arrives on a Monday to find the electronic health record will not open. The vendor's status page says nothing. The IT firm calls back at nine with the word nobody wants to hear before coffee.
By ten the waiting room has eleven families in it. The front desk has found the paper intake forms in a cabinet, from before the EHR went in. A nurse is writing weights and temperatures on sticky notes. The first physician sees a child with a fever and cannot see her allergy list or the note from the last visit. She asks the mother. The mother thinks it was amoxicillin, but is not sure.
Refills stall on day two, because the e-prescribing link runs through the same system. The pharmacy calls. Then the pharmacies call. Referrals to the specialist go out by fax, once someone finds the fax. Billing stops entirely.
Day nine is when the EHR comes back, restored from a backup the vendor kept. The practice then has to decide something harder than any of this: whether the attacker copied the records before locking them. Under HIPAA that decision, with its 60-day clock, is now the manager's responsibility, and she has no logs to answer the question with.
I have watched a cyberattack stop a hospital. A small practice does not get the hospital's incident team. It gets the practice manager, a legal pad and whatever was prepared before Monday.
What this means in plain words
Healthcare ransomware is malicious software that scrambles the systems a practice runs on, then demands payment for the key. In a clinic the systems are not abstract. They are the chart, the prescription, the schedule and the claim.
EHR downtime is the period when the electronic health record is unavailable. Most downtime procedures were written for a power cut lasting an afternoon. Nine days is a different document.
Exfiltration is the attacker copying records before encrypting them, because a stolen patient list is worth money whether or not the ransom is paid.
A reportable breach, under HIPAA, is any impermissible use or disclosure of protected health information unless the practice can demonstrate a low probability of compromise. Ransomware is presumed to be one. Proving otherwise requires evidence you either kept or did not.
Notification clocks vary by regulator. HIPAA gives 60 days from discovery to notify affected individuals. Abu Dhabi's ADHICS v2 requires the Department of Health to be told within 24 hours. Both clocks start whether or not you are ready.
The attack is survivable. How well you survive it is decided beforehand, the way a surgical checklist decides most of what happens in theatre before the first incision.
The numbers that matter
There were 772 large healthcare breaches in 2025 affecting 138.5 million people, and 87% of breaches in the first half of 2026 were hacking incidents, according to HIPAA Journal's 2026 analysis. Hacking, not lost laptops, is now the typical cause.
The median healthcare breach in the first half of 2026 affected 2,451 individuals, per HIPAA Journal's H1 2026 figures. That is not a hospital system. That is a practice the size of the one in this story. Smaller providers are now the typical victim.
ADHICS v2.0, issued by the Department of Health Abu Dhabi in 2024, requires breach notification to the Department within 24 hours. For a UAE clinic, the first day of the attack is also the reporting deadline.
What to do this week
- Confirm where the EHR backup lives, who controls it, and when it was last restored as a test. If the vendor keeps it, get the restore time in writing. If you keep it, put one copy where the network cannot reach it. (CIS 11 Data Recovery)
- Print the downtime kit and put it where the front desk can find it in the first ten minutes: intake forms, a medication reconciliation sheet, a paper schedule template, and the phone numbers of your three busiest pharmacies. (CIS 17 Incident Response Management)
- Write the one-page incident plan with names, not roles: who calls the IT firm, who calls the insurer, who calls the regulator, who talks to patients. Include the 60-day HIPAA clock and, for UAE practices, the 24-hour ADHICS clock. (CIS 17 Incident Response Management)
- Turn on the logs that show which records were opened or exported, and keep them somewhere the attacker cannot delete. These logs are what let you answer "was anything copied" with evidence instead of hope. (CIS 8 Audit Log Management)
- Find the patient data outside the EHR: the recall texting tool, the fax-to-email inbox, the spreadsheet on the manager's desktop. Encrypt or remove what does not need to be there. (CIS 3 Data Protection)
- Run a 30-minute tabletop with the whole team: "It is Monday and the EHR is gone." You will find the gaps in half an hour that the real event would find over nine days. (CIS 17 Incident Response Management)
Where AccuSights fits
Our assessment is written for a practice, not a data center: where the records live, whether the backup has ever been restored, and whether the logs exist to answer the breach question with evidence. The Cyber Hygiene Test takes three minutes and asks in plain language. For a clinician's view of what to fix first, book 15 minutes with an engineer, and I will make sure the answer fits the way a clinic runs.
Questions people ask
Is a ransomware attack a HIPAA breach? Under HIPAA, ransomware that encrypts patient records is treated as a breach unless the practice can show, with documentation, that there is a low probability the information was compromised. That showing is a formal risk assessment, not a feeling. Most practices that cannot prove the attacker never copied the data will end up notifying, and the notification clock runs from the day you discover the attack.
How long do clinics take to recover from ransomware? The plain answer is: as long as it takes to restore from a backup the attacker could not reach, plus the time to rebuild every system that touched the infected network. With a tested, offline backup and a written downtime plan, a small practice can be charting again in days. Without either, nine days is not unusual, and the cleanup of paper charts afterward takes longer still.
Do we have to notify patients if data was encrypted but not stolen? You will need to prove the second half of that sentence. If your logs show what the attacker did and did not access, and a documented assessment concludes there is a low probability of compromise, notification may not be required under HIPAA. If you cannot show it, the presumption is that a breach occurred. UAE practices should note that ADHICS v2 requires notice to the Department of Health within 24 hours regardless.
You would not begin an operation without the checklist on the wall. Put the downtime kit on the same wall, and Monday becomes a bad day instead of a bad month.
Questions people ask
Is a ransomware attack a HIPAA breach?
Under HIPAA, ransomware that encrypts patient records is treated as a breach unless the practice can show, with documentation, that there is a low probability the information was compromised. That showing is a formal risk assessment, not a feeling. Most practices that cannot prove the attacker never copied the data will end up notifying, and the notification clock runs from the day you discover the attack.
How long do clinics take to recover from ransomware?
The plain answer is: as long as it takes to restore from a backup the attacker could not reach, plus the time to rebuild every system that touched the infected network. With a tested, offline backup and a written downtime plan, a small practice can be charting again in days. Without either, nine days is not unusual, and the cleanup of paper charts afterward takes longer still.
Do we have to notify patients if data was encrypted but not stolen?
You will need to prove the second half of that sentence. If your logs show what the attacker did and did not access, and a documented assessment concludes there is a low probability of compromise, notification may not be required under HIPAA. If you cannot show it, the presumption is that a breach occurred. UAE practices should note that ADHICS v2 requires notice to the Department of Health within 24 hours regardless.
Controls this post maps to
CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.
Sources
Dr. Kashmala Khalid, Co-Founder, healthcare and defense programs. The clinical and regulatory authority behind the healthcare and defence programmes. Compliance with the precision of a surgeon and none of the fear-mongering. About the team →
Keep reading
Three more from the same shelf.
Your Vendor Got Hacked: What a Third-Party Data Breach Means for You, and the One-Hour Vendor Review
A third-party data breach lands on your desk even when the hack was not yours. Which vendors matter, what to ask them, and a review that takes one hour.
Practical controlsA Backup Strategy for a Small Business That Survives Ransomware: 3-2-1-1-0 and the Restore Test Nobody Runs
A backup strategy for a small business that survives ransomware: why sync is not backup, what 3-2-1-1-0 means, and the monthly restore test nobody runs.
ThreatsAI Cyber Attacks: What Actually Changed for a Small Business, and What Did Not
AI cyber attacks made phishing personal, fluent and cheap. What changed for a small business in 2026, what did not, and the controls that still hold.
