Immediate Incident Response Steps After a Ransomware Note Appears on Radiology Workstations

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Immediate Incident Response Steps After a Ransomware Note Appears on Radiology Workstations

Kevin Henry

Incident Response

September 01, 2026

6 minutes read
Share this article
Immediate Incident Response Steps After a Ransomware Note Appears on Radiology Workstations

Isolate Infected Radiology Workstations

Act immediately to achieve Ransomware Containment and stop lateral spread. Physically disconnect affected workstations from the network by removing Ethernet cables and disabling Wi‑Fi and Bluetooth, but keep systems powered to preserve volatile evidence.

  • Quarantine the radiology subnet, block suspect ports/protocols, and disable shared drives to cut propagation paths.
  • Pause integrations between modalities, PACS/RIS, and the VNA; stop automatic forwarding of studies from infected endpoints.
  • Prevent user interaction with the ransom note; instruct staff not to click links, open attachments, or run unknown tools.
  • Label and secure isolated devices to avoid accidental reconnection or use.

Document the exact time isolation began, the devices involved, and who executed each action. Avoid reboots or shutdowns unless directed by the incident response lead for safety reasons.

Alert IT and Security Teams

Trigger your incident bridge and escalate through documented Incident Command Communication. Engage the CIRT, PACS administrators, radiology leadership, clinical engineering, networking, legal, compliance, and the patient safety officer.

  • Provide concise facts: number of affected workstations, locations, screenshots of the ransom note, observed behavior, and timestamps.
  • Open an incident ticket, assign an incident commander, and set a predictable update cadence (for example, every 15–30 minutes).
  • Route all external communications through approved channels; instruct staff not to contact the threat actor.
  • Notify your SOC/MSSP and relevant vendors to align monitoring and containment steps.

Record all decisions, commands issued, and configuration changes for later review and accountability. Treat this as a high-severity Cybersecurity Incident Notification within your organization.

Preserve Evidence for Forensic Analysis

Protect the trail needed to understand entry points, scope, and malware behavior through disciplined Digital Forensics Evidence Preservation. Evidence enables root-cause analysis and supports remediation, reporting, and potential legal action.

  • Photograph and capture the ransom note, desktop messages, running processes, and active network connections with timestamps.
  • Collect relevant logs from endpoints, domain controllers, EDR, PACS/RIS, firewalls, VPNs, and identity providers; secure copies to write‑once media.
  • Acquire memory and disk images from representative systems using approved tools; calculate and store cryptographic hashes.
  • Maintain strict chain of custody: who collected what, when, where it’s stored, and access granted.
  • Avoid installing new software on infected machines or deleting files; changes can destroy artifacts.

Store evidence in a restricted repository with tamper‑evident controls. Coordinate with external forensic partners early so collection meets their standards.

Avoid Paying Ransom

Do not pay the ransom. Payment does not guarantee working decryption keys, may invite repeat extortion, and can create legal and ethical exposure.

  • Prioritize containment, eradication, and restoration from known‑good backups rather than negotiation.
  • Consult legal and compliance before any engagement with the threat actor; consider sanctions and regulatory risks.
  • Leverage vendor and law‑enforcement guidance on known malware families and potential decryptors.
  • Communicate a clear organizational stance against payment and reinforce it in staff briefings.

Focus resources on recovery and long‑term hardening. Transparent communication with stakeholders builds trust while you restore services.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Assess Impact on Patient Care

Conduct a rapid Patient Safety Assessment to keep care safe while systems are impaired. Define what studies can proceed, which must be diverted, and how clinicians will receive results during downtime.

  • Activate radiology downtime procedures: paper requisitions, manual patient identification, and documented handoffs.
  • Prioritize emergent and critical imaging; defer elective cases when safe to do so.
  • Coordinate with emergency, surgery, ICU, and oncology to align imaging priorities and alternatives.
  • Provide radiologists with access to essential priors where possible and define a path for communicating critical results.

Track any delays or adverse events and escalate risks through the clinical chain of command. Communicate clearly to patients about expected timelines and alternatives.

Notify Regulatory Authorities

Engage your privacy officer and legal team to manage Healthcare Compliance Reporting and external Cybersecurity Incident Notification. Determine whether protected health information or device safety was affected and which statutes apply.

  • Assess obligations under HIPAA/HITECH, applicable state breach laws, and sector reporting requirements relevant to your facility.
  • Notify law enforcement and appropriate government bodies per policy and law, coordinating content and timing with counsel.
  • Inform affected third parties when integrations or vendors are implicated; align messages to avoid conflicting statements.
  • Document rationale for all notifications, including scope, individuals impacted, and mitigation steps taken.

Maintain a single source of truth for external statements to reduce confusion and preserve trust. Keep detailed records to support audits and inquiries.

Initiate System Recovery Procedures

Follow tested Backup Restoration Protocols to rebuild safely and deliberately. Restore only after containment and forensic triage confirm you have a clean baseline.

  • Eradicate: remove malware, revoke tokens, rotate credentials (especially privileged), and patch vulnerabilities linked to initial access.
  • Reimage affected endpoints from gold images; verify integrity with EDR and vulnerability scans before reconnecting to the network.
  • Restore PACS/RIS/VNA databases and application servers from known‑good, offline backups; validate with checksums and logs.
  • Recover in phases: bring up core identity, networking, and storage first; then imaging modalities, PACS, reporting, and integrations.
  • Perform functional and clinical acceptance tests with radiology and IT before resuming routine operations.
  • Increase monitoring and alerting thresholds post‑restoration; watch for persistence or re‑infection indicators.
  • Run a lessons‑learned to strengthen controls, refine playbooks, and train staff on improved procedures.

This guide outlines Immediate Incident Response Steps After a Ransomware Note Appears on Radiology Workstations and prioritizes safety, evidence, and resilient recovery. By coordinating clinical operations and technical remediation, you restore critical imaging services with confidence.

FAQs

What should be the first action after detecting ransomware on radiology workstations?

Immediately isolate the affected workstations from the network by disconnecting cables and disabling wireless, but leave them powered to preserve evidence. Notify the incident commander and security team at once and start documenting every action.

How can patient care be protected during a ransomware attack?

Activate radiology downtime procedures, prioritize emergent studies, and communicate alternatives to clinicians through a structured command channel. Provide clear routing for orders and results, and coordinate diversions or rescheduling when necessary.

When should law enforcement be notified about a ransomware incident?

Notify law enforcement promptly after initial containment and evidence preservation, following your organizational policy and legal guidance. Prepare a concise incident summary and designate a single point of contact to manage interactions.

Is it advisable to pay the ransom in healthcare ransomware cases?

In most cases, no. Payment is unreliable, encourages further attacks, and may carry legal or regulatory risks; prioritize containment and recovery from clean backups in consultation with legal, compliance, and law enforcement.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles