Ransomware Preparedness for Small Clinics
A ransomware attack on a clinic isn't primarily an IT event, it's an operational one: patients waiting in a lobby with no chart access, a schedule nobody can see, and a decision that needs to happen fast under pressure. The clinics that recover quickly are almost always the ones that had a plan written down before the attack, not the ones improvising in the moment.
Ransomware preparedness for a small clinic means having a documented downtime procedure that lets the front desk keep operating without computers, immutable backups the ransomware itself can't reach or encrypt, clear recovery time objectives for how long full restoration should take, and a written list of who to call first, in order, before an incident happens.
Why clinics specifically get targeted
Ransomware operators look for targets where downtime is expensive and where the victim is likely to pay quickly to make the problem go away. A clinic with a full day of booked patients, no way to access charts, and a waiting room filling up is exactly that kind of target. It isn't personal, it's an economic calculation the attacker is making, and small clinics with lighter security budgets than hospitals make attractive, lower-effort targets.
A downtime procedure: operating without computers
Every clinic needs a written plan for operating on paper for at least a day, because that's realistically the minimum time even a well-prepared recovery takes. Waiting until the day of an incident to figure out how to check a patient in without the practice-management system is a recipe for chaos on top of a crisis.
- A printed or offline copy of the day's appointment schedule, refreshed daily
- Paper intake and consent forms kept in stock, not just stored as a digital template
- A documented process for triaging urgent versus reschedulable appointments
- A designated person responsible for communicating with patients about delays
- A way to take payment that doesn't depend on the affected systems
Immutable backups: the difference between an inconvenience and a catastrophe
The single biggest factor in how a ransomware incident ends is whether backups survived. Attackers specifically look for and try to destroy backup copies before triggering encryption, because a victim with clean backups has far less reason to pay. Immutable backups, meaning copies that cannot be altered or deleted even by someone with administrative credentials for a set period, remove that leverage.
Backups stored using the same login credentials as the rest of the network don't count as truly protected, since those are exactly the credentials an attacker who's already inside the network is likely to have.
| Backup characteristic | Why it matters in a ransomware event |
|---|---|
| Immutable for a set retention window | Attacker cannot delete or encrypt it even with stolen admin credentials |
| Stored off the production network | A compromised server can't reach and corrupt it directly |
| Tested with real restores | Confirms recovery will actually work under pressure, not just in theory |
| Covers Microsoft 365 and cloud data | Cloud platforms don't back themselves up to the standard a clinic needs |
Would your clinic survive a ransomware event tomorrow?
We build and test ransomware preparedness plans for small clinics, from immutable backups to the downtime procedure your front desk actually needs.
Book a Ransomware Readiness ReviewSetting realistic recovery objectives
Two numbers matter most in recovery planning: how much data loss is acceptable, and how much downtime is acceptable. These are usually called recovery point objective and recovery time objective, and setting them before an incident, rather than during one, changes the entire tone of a crisis. A clinic that has agreed in advance that a half-day of data loss and a one-day recovery window are acceptable can make calmer decisions than one negotiating those numbers for the first time mid-crisis.
These objectives should be realistic given the clinic's actual backup infrastructure, not aspirational. An IT provider can help translate a clinic's tolerance for downtime into the technical backup design that actually delivers it.
Who to call first, in order
A written, printed call list, kept somewhere that doesn't depend on the compromised network, removes guesswork at the worst possible moment. The order matters: containing the incident and engaging the right expertise early tends to shape the whole outcome.
- IT provider, to begin technical containment and assess scope
- Cyber insurance provider, many policies require early notification and have designated incident-response vendors
- Legal counsel, to advise on notification obligations under PHIPA and any other applicable rules
- Practice management or ownership, to activate the downtime procedure and communicate with staff
- Affected software vendors, once scope is understood, to coordinate on recovery of their platforms
Preparation checklist before anything happens
- Confirm backups are immutable and have been restore-tested within the last quarter
- Print and store the downtime procedure somewhere accessible without computer access
- Confirm cyber insurance coverage and any required incident-response vendor
- Keep the call list updated with current names and phone numbers, not old contacts
- Review MFA coverage across all accounts, since compromised credentials are the most common entry point
Related reading
The safeguards side of PHIPA that underpins much of this planning is covered in our guide to PHIPA IT requirements for Ontario clinics. Practices managing large imaging files should also see dental imaging storage and backup for the specifics of protecting that data. And the day-to-day support relationship that keeps clinical software running is covered in EMR and EHR IT support for clinics.
Sources and further reading
Frequently asked questions
Should our clinic ever pay a ransom?
That decision involves legal, insurance, and law enforcement considerations well beyond IT, and should be made with legal counsel and your cyber insurer, not decided in advance or by an IT provider alone.
How quickly can a clinic realistically recover from ransomware?
It depends heavily on whether clean, immutable backups exist. Clinics with tested backups can often be operational within a day or two; clinics without them may face weeks of rebuilding and, in the worst cases, permanent data loss.
Do we need a paper downtime procedure if we're fully cloud-based?
Yes. Cloud-based systems can still become inaccessible during an incident, whether due to compromised credentials, a network outage, or an attack on the identity layer. A paper fallback is still worth having.
Does cyber insurance cover ransomware recovery costs?
Many policies do, often with specific requirements about which incident-response vendors must be used and how quickly the insurer must be notified. Review your policy's specific terms and confirm requirements with your broker before an incident occurs.
Joshua Arimoro
Joshua Arimoro is the Principal Consultant at Nickel City Tech Solutions, a managed IT and cybersecurity provider based in Lively, Ontario, serving businesses across Greater Sudbury and Northern Ontario. He works hands-on with Microsoft 365, server and network infrastructure, endpoint management, and backup and recovery for small and mid-sized organisations.
More about our teamBuild ransomware preparedness before you need it
From immutable backups to a written incident response plan, we help small clinics prepare for the scenario nobody wants to think about.
Related services, locations, and resources
Related services
- Managed IT Services
Proactive monitoring, patching, and predictable monthly support.
- Cybersecurity Services
Endpoint protection, MFA, email filtering, and M365 hardening.
- Backup & Disaster Recovery
Backup strategy, monitoring, and recovery testing.
- Business IT Support
Remote and on-site help desk for day-to-day issues.
Related service areas
Related resources
- What PHIPA Means for a Clinic's IT (Plain Language Guide)
PHIPA never mentions firewalls or backups by name, so most clinic owners are left guessing what 'reasonable…
- Supporting EMR and EHR Environments: A Practical Guide
A slow EMR is rarely the software's fault. It's usually the workstation, the network, or the printer standi…
- Dental Imaging Storage and Backup: A Practical Guide
Dental imaging files grow faster than most practices plan for, and a backup that's never been restored isn'…
- IT Support for Mining Supply and Service Contractors in Sudbury
Mining supply and service contractors in Sudbury deal with remote sites, prequalification questionnaires, a…
