Healthcare ransomware prevention is a layered program built on risk analysis, asset visibility, phishing-resistant MFA, rapid patching, network segmentation, endpoint detection, isolated backups, vendor controls and tested incident response.
The 10 controls below align with HHS's healthcare Cybersecurity Performance Goals and the NIST Ransomware Risk Management Profile, finalized on June 11, 2026. The goal is to stop ransomware from entering the environment, limit lateral movement, protect electronic protected health information (ePHI), preserve access to clinical systems and restore operations after an attack.
Healthcare Ransomware Prevention at a Glance
| Priority | What to implement | Evidence of effective implementation |
|---|---|---|
| Risk management | Complete an ePHI risk analysis and inventory IT, cloud, operational technology and medical-device assets | Every important asset has an owner, classification and remediation status |
| Identity security | Use phishing-resistant MFA, unique credentials and separate privileged accounts | No shared administrator accounts, with regular reviews of privileged access |
| Vulnerability management | Patch internet-facing systems, remove unsupported software and close unnecessary services | Known exploited vulnerabilities have documented remediation deadlines |
| Email and endpoint security | Deploy email protection, endpoint protection and endpoint detection and response | Security alerts are assigned, investigated and resolved |
| Network segmentation | Separate clinical, administrative, device and backup environments | A compromised workstation cannot freely reach critical systems |
| Backup and recovery | Keep offline or otherwise isolated backups and test restoration | The organization can restore priority systems within defined recovery targets |
| Supplier security | Assess vendors, restrict remote access and require incident reporting | Business associates and technology suppliers have documented security obligations |
| Response readiness | Exercise ransomware and downtime procedures with clinical and executive teams | Exercises produce assigned actions and measurable improvements |
The HHS Cybersecurity Performance Goals cover many of these controls, including vulnerability management, email security, MFA, unique credentials, privileged-account separation, asset inventory, endpoint detection, network segmentation and vendor requirements.
1. Start With a Healthcare-Specific Risk Analysis and Asset Inventory
A healthcare organization cannot protect systems it does not know exist. Create and update an inventory covering:
- Electronic health record systems
- Patient portals and telehealth platforms
- Laboratory, pharmacy and radiology systems
- Servers, workstations and laptops
- Cloud services and software-as-a-service applications
- Network-connected medical devices
- Backup systems
- Vendor and remote-access connections
- Administrative and operational technology
Classify each asset by its effect on patient safety, clinical operations, ePHI confidentiality, revenue and recovery time. Give the strongest access controls, monitoring and recovery priority to systems that affect patient care or contain sensitive data.
The HIPAA Security Rule requires covered entities and business associates to conduct an accurate and thorough risk analysis of threats and vulnerabilities affecting ePHI. HHS also recommends identifying known, unknown and unmanaged assets to improve vulnerability response.
2. Close Common Ransomware Entry Points
Ransomware often starts with stolen credentials, phishing, an exposed vulnerability or unauthorized remote access. Healthcare organizations should:
- Patch internet-facing servers, VPN appliances, firewalls and remote-access systems first.
- Track vulnerabilities listed in the CISA Known Exploited Vulnerabilities Catalog.
- Remove unnecessary internet-facing services.
- Disable unused remote desktop services.
- Restrict remote administration to approved users, devices and locations.
- Require MFA for email, VPN, remote access, cloud applications and administrator accounts.
- Use email filtering, anti-spoofing controls and malicious-link protection.
- Train staff to report suspicious messages, unexpected login prompts and possible malware immediately.
Security awareness training should be practical rather than limited to an annual presentation. Staff should know how to verify an unusual payment request, report a suspicious attachment, respond to a suspected credential theft attempt and escalate a possible ransomware incident.
HHS lists known vulnerability mitigation, email security and MFA among its essential healthcare cybersecurity goals. CISA also recommends timely patching, reduced exposure of remote services, MFA and tested backups.
3. Make Identity Security a Primary Control
A stolen healthcare account can provide access to email, clinical applications, file shares and administrative tools. Reduce that risk by using:
- Phishing-resistant MFA for privileged users, remote access, email and externally accessible systems.
- Unique credentials for every workforce member, service account and administrator.
- Separate user and privileged accounts so routine email and web activity does not use administrator privileges.
- Least-privilege access to ePHI, shared drives, clinical applications and cloud services.
- Rapid deprovisioning when employees, contractors, volunteers or suppliers leave or change roles.
- Privileged-access monitoring for unusual logins, geographic anomalies and mass file activity.
HHS recommends unique credentials to limit lateral movement and separate privileged accounts to reduce the consequences of a compromised standard account.
4. Segment Clinical, Administrative, Device and Backup Networks
Network segmentation limits what an attacker can reach after compromising one computer. Where operationally feasible, separate:
- Clinical workstations and general office devices
- Electronic health record infrastructure
- Medical-device networks
- Pharmacy, laboratory and imaging systems
- Administrative systems
- Backup and recovery infrastructure
- Vendor remote-access environments
Use firewall rules and access-control lists to permit only the connections each system requires. Monitor traffic between segments and review exceptions regularly.
Segmentation will fail if excessive connectivity, shared credentials or unmanaged devices provide another route between environments. Test the design rather than treating the network diagram as proof that the controls work.
HHS describes network segmentation as placing mission-critical assets in separate network segments to reduce lateral movement after an initial compromise.
5. Deploy Endpoint Detection and Response
Traditional antivirus remains useful, but it should not be the only endpoint control. Use endpoint protection and, where practical, endpoint detection and response (EDR) across servers, workstations and supported clinical endpoints.
Monitor for:
- Mass file renaming or encryption
- Unusual PowerShell or command-line activity
- New administrative accounts
- Credential-dumping behavior
- Unexpected use of remote-management tools
- Abnormal access to file shares
- Attempts to disable security software
- Large outbound transfers of ePHI
HHS includes EDR as an enhanced cybersecurity goal for detecting relevant threats and attacker techniques at endpoints. Detection helps only when alerts are assigned, investigated and tied to a documented containment process.
6. Protect Backups From the Ransomware Event
Backups support recovery. They do not replace prevention. A ransomware group may try to encrypt or delete backups before attacking production systems.
Maintain:
- Frequent backups of critical clinical and business data
- At least one backup copy that is offline or unavailable from the normal production network
- Separate administrative credentials for backup infrastructure
- Documented recovery priorities
- Regular restoration tests
- Monitoring that detects failed or incomplete backup jobs
HHS states that frequent backups, tested restorations and offline backups support ransomware recovery. Test restoration of the systems that affect patient care first, including the EHR, medication systems, laboratory systems, imaging systems and identity services.
A backup strategy is incomplete if the organization has never shown that it can restore usable data within an acceptable period.
7. Secure Connected Medical Devices and Legacy Systems
Medical devices create additional ransomware risk because they may run older software, depend on vendor support or connect directly to clinical networks. Include imaging systems, infusion pumps, monitoring equipment, laboratory analyzers and biomedical workstations in the cybersecurity program.
For each device:
- Record its owner, location, network connection and clinical function.
- Identify the manufacturer's patch and support status.
- Remove unnecessary internet exposure.
- Place the device in a restricted network segment.
- Control vendor maintenance access.
- Coordinate patches with clinical engineering and patient-safety teams.
- Document compensating controls for devices that cannot be patched.
- Prepare manual or downtime procedures for clinically important devices.
The FDA states that healthcare delivery organizations should evaluate network security and protect hospital systems. Device manufacturers and healthcare delivery organizations must address cybersecurity risks that could affect patient safety and device performance.
8. Control Business Associates and Technology Suppliers
A healthcare organization's ransomware exposure includes its cloud providers, billing companies, managed service providers, electronic prescribing platforms, laboratories and other business associates.
Supplier controls should address:
- MFA and least-privilege access
- Remote-access approval and monitoring
- Vulnerability and patch-management responsibilities
- Backup and recovery expectations
- Security incident reporting
- Subcontractor oversight
- Evidence of security testing
- Secure termination of access
- Responsibilities for forensic investigation and breach assessment
HHS's Cybersecurity Performance Goals call for healthcare organizations to identify, assess and mitigate third-party risks. HHS also states that business associate agreements must require reporting of security incidents involving ePHI.
A signed business associate agreement does not prove that a supplier is secure. Review the supplier's access, architecture, incident history and recovery capabilities.
9. Test the Ransomware Response Before an Incident
Every healthcare organization should maintain a ransomware-specific incident response plan involving:
- IT and security
- Clinical operations
- Executive leadership
- Legal and privacy
- Compliance
- Communications
- Facilities
- Biomedical engineering
- Key vendors
The plan should define:
- Who can declare a ransomware incident
- How infected systems are isolated
- How clinical downtime procedures are activated
- How patient-safety decisions are escalated
- How evidence is preserved
- How internal and external communications are coordinated
- How backups are validated before restoration
- How vendors, law enforcement and regulators are contacted
- How the organization determines whether ePHI was accessed or exfiltrated
HHS recommends detecting and analyzing the incident, containing its spread, removing the malware, fixing the exploited weakness, restoring systems and conducting a post-incident review.
Run tabletop exercises often enough to expose changes in systems, staffing and vendor relationships. Include a scenario in which the EHR, email and phone systems are unavailable at the same time.
What to Do if Ransomware Is Suspected
If a healthcare organization suspects ransomware:
- Activate the incident response plan immediately.
- Isolate affected computers and systems according to the response plan.
- Prevent further spread while preserving forensic evidence.
- Move affected clinical departments to approved downtime procedures.
- Contact security leadership, legal counsel, privacy officers and relevant vendors.
- Determine the scope, affected systems and possible data exfiltration.
- Do not restore systems until the entry point and attacker persistence have been investigated.
- Assess HIPAA, contractual, state and federal reporting obligations.
HHS explains that ransomware involving ePHI may constitute a HIPAA breach, depending on the facts. Its guidance states that encrypted ePHI is generally presumed to have been compromised unless the organization demonstrates a low probability of compromise through the required risk assessment.
For breaches affecting 500 or more individuals, HHS currently requires notification to the Secretary without unreasonable delay and no later than 60 calendar days after discovery. Smaller breaches have different reporting procedures.
A Practical Implementation Order for Healthcare Leaders
When resources are limited, implement the controls in this order:
- Inventory critical systems, ePHI locations, medical devices and remote-access paths.
- Enable MFA for email, VPN, remote access and privileged accounts.
- Patch or isolate internet-facing and known-exploited vulnerabilities.
- Separate privileged accounts from normal user accounts.
- Verify offline or isolated backups and complete a restoration test.
- Segment clinical, device and backup environments.
- Deploy or improve EDR and security alert monitoring.
- Review business associate and supplier access.
- Exercise ransomware downtime and recovery procedures.
- Use the results to update the risk analysis and security investment plan.
Use HHS's Cybersecurity Performance Goals as a baseline for prioritizing the work. Use the NIST Ransomware Risk Management Profile to organize the wider program around identifying, protecting, detecting, responding and recovering.
Bottom Line
HIPAA compliance is a floor, not a recovery test. The practical test is whether the organization can detect unusual activity, stop lateral movement, continue safe patient care and restore critical systems from verified backups.