A cyber incident in a medical practice can affect appointments, communications, billing and access to clinical systems. The first priority is to make the situation safer without destroying evidence or creating additional disruption. Use this checklist to coordinate the opening response with your IT provider, software vendors and leadership team.
The first 15 minutes
Call the incident contactUse the documented urgent support number. Explain what was observed, when it began, who is affected and whether clinical work is disrupted.
Keep the affected device availableDisconnect it from networks when directed, but do not wipe, reset or continue investigating it yourself. Volatile evidence may matter.
Use a known-safe channelIf email may be compromised, coordinate by telephone or another previously approved channel. Do not trust new payment or password instructions received by email.
Record decisionsStart a simple timeline of observations, calls, containment actions and decision makers. Use factual language and avoid speculation.
Contain access and communication
Protect identityRevoke suspicious sessions, reset affected credentials from a trusted device and enforce MFA. Check forwarding rules, delegated access and recently added authentication methods.
Control remote accessReview VPN, Remote Desktop, TeamViewer, AnyDesk and support tools. Disable unapproved or unexplained access without removing evidence.
Warn the right peopleBrief reception, clinicians and administration on what they should stop doing, which channel to use and how to report related messages or symptoms.
Protect paymentsNotify finance personnel and relevant banking contacts when email or invoice fraud is possible. Independently verify changes to supplier payment details.
Clinical systems and recovery
Engage software vendors through known contactsConfirm whether the incident affects the practice-management system, integrations, prescriptions, pathology, imaging or hosted services.
Activate downtime proceduresUse the practice's approved process for appointments, urgent clinical work, phone calls and later reconciliation. Do not create uncontrolled copies of sensitive data.
Validate recovery before reconnectingConfirm the threat is contained, affected accounts are secured, restored systems are clean and monitoring is active before returning to normal operation.
Hold a structured reviewDocument the cause, business impact, notifications, improvements and responsible owners. Test that corrective actions remain effective.
Important contextDo not enter patient information, passwords or incident evidence into a public website or general-purpose AI service. Preserve it within approved systems and follow your legal, insurer and regulatory advice.
