All Resources
Industry IT

Ransomware Preparedness for Small Clinics

A ransomware attack on a clinic isn't primarily an IT event, it's an operational one: patients waiting in a lobby with no chart access, a schedule nobody can see, and a decision that needs to happen fast under pressure. The clinics that recover quickly are almost always the ones that had a plan written down before the attack, not the ones improvising in the moment.

Published August 10, 2026 Updated August 10, 2026 10 min read By Joshua Arimoro Greater Sudbury & Ontario
The short answer

Ransomware preparedness for a small clinic means having a documented downtime procedure that lets the front desk keep operating without computers, immutable backups the ransomware itself can't reach or encrypt, clear recovery time objectives for how long full restoration should take, and a written list of who to call first, in order, before an incident happens.

Why clinics specifically get targeted

Ransomware operators look for targets where downtime is expensive and where the victim is likely to pay quickly to make the problem go away. A clinic with a full day of booked patients, no way to access charts, and a waiting room filling up is exactly that kind of target. It isn't personal, it's an economic calculation the attacker is making, and small clinics with lighter security budgets than hospitals make attractive, lower-effort targets.

A downtime procedure: operating without computers

Every clinic needs a written plan for operating on paper for at least a day, because that's realistically the minimum time even a well-prepared recovery takes. Waiting until the day of an incident to figure out how to check a patient in without the practice-management system is a recipe for chaos on top of a crisis.

  • A printed or offline copy of the day's appointment schedule, refreshed daily
  • Paper intake and consent forms kept in stock, not just stored as a digital template
  • A documented process for triaging urgent versus reschedulable appointments
  • A designated person responsible for communicating with patients about delays
  • A way to take payment that doesn't depend on the affected systems

Immutable backups: the difference between an inconvenience and a catastrophe

The single biggest factor in how a ransomware incident ends is whether backups survived. Attackers specifically look for and try to destroy backup copies before triggering encryption, because a victim with clean backups has far less reason to pay. Immutable backups, meaning copies that cannot be altered or deleted even by someone with administrative credentials for a set period, remove that leverage.

Backups stored using the same login credentials as the rest of the network don't count as truly protected, since those are exactly the credentials an attacker who's already inside the network is likely to have.

Backup characteristicWhy it matters in a ransomware event
Immutable for a set retention windowAttacker cannot delete or encrypt it even with stolen admin credentials
Stored off the production networkA compromised server can't reach and corrupt it directly
Tested with real restoresConfirms recovery will actually work under pressure, not just in theory
Covers Microsoft 365 and cloud dataCloud platforms don't back themselves up to the standard a clinic needs

Would your clinic survive a ransomware event tomorrow?

We build and test ransomware preparedness plans for small clinics, from immutable backups to the downtime procedure your front desk actually needs.

Book a Ransomware Readiness Review

Setting realistic recovery objectives

Two numbers matter most in recovery planning: how much data loss is acceptable, and how much downtime is acceptable. These are usually called recovery point objective and recovery time objective, and setting them before an incident, rather than during one, changes the entire tone of a crisis. A clinic that has agreed in advance that a half-day of data loss and a one-day recovery window are acceptable can make calmer decisions than one negotiating those numbers for the first time mid-crisis.

These objectives should be realistic given the clinic's actual backup infrastructure, not aspirational. An IT provider can help translate a clinic's tolerance for downtime into the technical backup design that actually delivers it.

Who to call first, in order

A written, printed call list, kept somewhere that doesn't depend on the compromised network, removes guesswork at the worst possible moment. The order matters: containing the incident and engaging the right expertise early tends to shape the whole outcome.

  1. IT provider, to begin technical containment and assess scope
  2. Cyber insurance provider, many policies require early notification and have designated incident-response vendors
  3. Legal counsel, to advise on notification obligations under PHIPA and any other applicable rules
  4. Practice management or ownership, to activate the downtime procedure and communicate with staff
  5. Affected software vendors, once scope is understood, to coordinate on recovery of their platforms

Preparation checklist before anything happens

  • Confirm backups are immutable and have been restore-tested within the last quarter
  • Print and store the downtime procedure somewhere accessible without computer access
  • Confirm cyber insurance coverage and any required incident-response vendor
  • Keep the call list updated with current names and phone numbers, not old contacts
  • Review MFA coverage across all accounts, since compromised credentials are the most common entry point

Related reading

The safeguards side of PHIPA that underpins much of this planning is covered in our guide to PHIPA IT requirements for Ontario clinics. Practices managing large imaging files should also see dental imaging storage and backup for the specifics of protecting that data. And the day-to-day support relationship that keeps clinical software running is covered in EMR and EHR IT support for clinics.

Sources and further reading

Frequently asked questions

Should our clinic ever pay a ransom?

That decision involves legal, insurance, and law enforcement considerations well beyond IT, and should be made with legal counsel and your cyber insurer, not decided in advance or by an IT provider alone.

How quickly can a clinic realistically recover from ransomware?

It depends heavily on whether clean, immutable backups exist. Clinics with tested backups can often be operational within a day or two; clinics without them may face weeks of rebuilding and, in the worst cases, permanent data loss.

Do we need a paper downtime procedure if we're fully cloud-based?

Yes. Cloud-based systems can still become inaccessible during an incident, whether due to compromised credentials, a network outage, or an attack on the identity layer. A paper fallback is still worth having.

Does cyber insurance cover ransomware recovery costs?

Many policies do, often with specific requirements about which incident-response vendors must be used and how quickly the insurer must be notified. Review your policy's specific terms and confirm requirements with your broker before an incident occurs.

About the author

Joshua Arimoro

Joshua Arimoro is the Principal Consultant at Nickel City Tech Solutions, a managed IT and cybersecurity provider based in Lively, Ontario, serving businesses across Greater Sudbury and Northern Ontario. He works hands-on with Microsoft 365, server and network infrastructure, endpoint management, and backup and recovery for small and mid-sized organisations.

More about our team

Build ransomware preparedness before you need it

From immutable backups to a written incident response plan, we help small clinics prepare for the scenario nobody wants to think about.

Keep exploring

Related services, locations, and resources

Related services

Related resources