Ransomware in the Clinic: Emergency Plan for 24 Hours, 72 Hours, and 30 Days
A ransomware incident in a hospital is not an IT glitch, but a patient care crisis. The operational roadmap from detection to the final BSI report — with lessons learned from real incidents.

Ransomware in the Clinic: The First 24 Hours, the First 72 Hours, the First Month
Hospitals are the most heavily affected CRITIS sector in Germany in 2026. Cyberattacks on clinics have more than tripled since 2020; ransomware is by far the most common form of attack. That it happens is no longer the question. The question is: what to do when it happens.
This roadmap is intended for hospital managements, IT directors, data protection officers, and crisis team managers. It traces the sequence of events that has proven successful in real incidents — from the first suspicious screen message to the final BSI report after 30 days. Not as a theory, but as an operational playbook.
Three preliminary remarks. First: Anyone who only reads this roadmap during an ongoing incident has already lost. It only works if the structures — crisis management team, escalation chain, reporting templates, backup strategy — are established beforehand. Second: A cyberattack in a hospital is not an IT problem. It is a healthcare supply crisis with an IT cause. Management runs through the crisis team, not the helpdesk. Third: NIS2 has significantly increased the pressure. Section 32 of the BSIG mandates an initial 24-hour report to the BSI, a 72-hour assessment report, and a final report after 30 days. Anyone who misses these deadlines risks fines of up to €10 million and personal liability for the management under Section 38 of the BSIG. Whether your institution falls under NIS2 at all can be clarified in two minutes with our NIS2 affectedness check.
The First 30 Minutes — Detection and Containment
A typical beginning: An admission employee can no longer access the HIS. A call comes from radiology stating that the images are not loading. The IT hotline receives multiple tickets from various wards simultaneously. What initially looks like a server problem turns out to be encrypted files after 15 minutes.
These first 30 minutes decide whether the incident becomes a controlled crisis or a widespread outage. Three steps are non-negotiable:
1. Rapid triage by IT managers. Are individual endpoints affected, or is it spreading? Is only the HIS affected, or also Active Directory, PACS, LIS, pharmacy systems? Initial indicators of ransomware: files with unusual extensions (.lockbit, .ryuk, .conti), ransom notes in directories, disabled endpoint detection, unusual activity in Active Directory logs.
2. Immediate network isolation of affected segments. Disconnect infected workstations from the network — physically if possible, otherwise via switch port disablement or firewall rules. Critical question: Does the attacker already have domain admin rights? If so, the entire domain is compromised. In that case: disconnect all servers from the network, turn off Active Directory, restart only after forensic assessment.
3. Convene the crisis management team. Executive management, IT management, medical management, nursing management, data protection, press office. Ideally, a pre-defined list with private phone numbers and deputies. Activate the crisis team room — physically, not digitally, because the digital tools themselves may be compromised.
What does not happen in the first 30 minutes: recovery, forensics, ransom negotiation, external communication. Only three things: detect, contain, escalate.
The First 24 Hours — Triage, Crisis Team, Initial BSI Report
Hours 1 to 4: Damage assessment. Which care processes are affected? Emergency department, OR, intensive care unit, lab, imaging, pharmacy, billing, patient identification. Which systems are down? HIS, PACS, LIS, RIS, AD, email, telephony, elevator control, HVAC, access control. Which devices are compromised versus shut down preventively? Which backups are available and not affected themselves?
In parallel: transition to manual operation. The famous paper sheets from the drawer. Patient identification via wristband with admission number. Medication via handwritten order. Findings by phone and fax. Following a ransomware attack in 2016, the Lukaskrankenhaus Neuss operated in manual mode for weeks — without any loss of patients because the crisis team functioned and the emergency folder was close at hand.
Hours 4 to 12: Calling in external support. Three calls are critical:
External IT Forensics. Anyone who does not have a contract with a 24/7 forensics service provider should call now at the latest — and expect to wait hours for feedback in a crisis. Providers with healthcare experience are rare; get to know the key companies in advance, emergency number in the crisis team folder.
Data Protection Officer. In parallel to the BSI report, the GDPR reporting obligation under Art. 33 GDPR runs. If unauthorized access to or theft of patient data is suspected, the responsible data protection supervisory authority must be informed within 72 hours. In case of high risk, the affected individuals must also be notified under Art. 34 GDPR.
Insurer. Call the cyber insurance, report the claim immediately. Many policies require notification within 24 hours, otherwise coverage is voided. Insurers often have their own forensics pools that are already covered by the policy — this saves negotiations with unknown providers in the acute phase.
Hours 12 to 24: Initial BSI report. Section 32 of the BSIG requires the initial report within 24 hours of becoming aware of a significant security incident. "Significant" is intentionally not narrowly defined here — in the case of ransomware in a hospital, the incident practically always meets the threshold.
The report is submitted via the BSI reporting portal (Mein-Unternehmenskonto, MUK). Concise content:
General description of the incident
Time of detection
Affected systems and care areas
Suspected vector (if already known)
Containment measures taken so far
24/7 contact point for inquiries
Anyone who does not have the initial report template ready will write it under pressure. Prepared templates save 30 to 60 minutes — time that is more urgently needed elsewhere in the crisis management team.
Hours 24 to 72 — Assessment, Forensics, Assessment Report
Day 2: Full containment and start of forensics. Forensics specialists are on site or connected remotely. Their first task: secure evidence without altering the evidentiary content. Disk images of infected systems, logs from firewalls, Active Directory, mail servers, endpoint detection tools. Collecting these logs before the restart is non-negotiable — later it is too late.
Three critical decisions run in parallel:
To pay ransom — yes or no? In Germany, payment is not illegal per se, but it can become punishable by law if a proven connection to sanctioned groups is established (e.g., recorded on EU sanctions lists). The Federal Criminal Police Office (BKA) generally advises against it. Insurers often do not cover ransom payments or do so only under strict conditions. In practice: even after payment, complete recovery is not guaranteed — decryptors are often faulty, data partially unusable, and double extortion (decryption key plus threat of data publication) is not uncommon.
Recovery strategy. From backups or rebuilding from scratch? Backups must be verified as clean before reconnection — some ransomware families sit in the network for weeks and also infect older backups. A clean restart often requires new hardware or complete reinstallation from reliably clean images.
External communication. Patients, relatives, referring physicians, local media. The press office coordinates, approved texts are authorized by management. Important: Clear communication about what is working (emergency care is running, ER is reachable) and what is not (planned surgeries postponed, appointments rescheduled). False reassurance backfires as soon as the truth becomes visible.
Hour 72: BSI assessment report. Content:
Detailed impact on care operations
Severity classification
Status of measures initiated
Initial findings on the cause (initial vector, timeline)
Estimated timeframe for recovery
The GDPR report to the responsible data protection authority is due in parallel, provided patient data is affected. Both reports often happen on the same day — separate inputs, separate authorities, no joint procedure.
Day 3 to Day 30 — Recovery and Final Report
The phase that receives the least attention in practice — and takes the longest.
Days 3 to 7: Prioritized restart. The sequence is not IT-driven, but prioritized by care needs. First, whatever directly affects patients (HIS, PACS, LIS, pharmacy), then administration. This is a clinical decision, not a technical one. Per system: rebuilding from verified backups or reinstallation, applying patches, hardening configuration, step-by-step reconnection to the network, functional tests, intensified monitoring.
Days 8 to 21: Stabilization. The system is running again, but under observation. Enhanced logs, endpoint detection on all critical devices, frequent backup tests. The staff also needs training — often all passwords must be changed, new workflows take effect, and clear escalation paths apply. In the Lukaskrankenhaus in 2016, all employees had to switch to 16-character passwords and accept a new security concept.
In parallel: improvement measures. What made the attack possible in the first place? In a typical clinic incident, it is one to three vulnerabilities: an unpatched internet server, a phishing email with a macro attachment, or compromised maintenance credentials of a service provider. These are closed before the system goes back to normal operation — not after.
Day 30: Final BSI report. Content:
Complete review of the incident
Confirmed root cause
Consequences — damage, affected data, recovery costs
Lessons learned and specific adjustments to the security concept
Planned next steps
This report is not only mandatory — it is the basis if fine proceedings, civil lawsuits, or insurance disputes follow later. Write it carefully, attach the forensics report, have it approved by management, and include it in the ISMS file.
The Most Common Mistakes in the First Hours
Patterns repeat after real incidents. Four mistakes cost the most:
"Let's see if we can solve this ourselves first." Attempting to proceed without forensics destroys evidence and increases the risk of the ransomware returning. In case of any serious suspicion: call in external help — even if it turns out to be a false alarm in the end.
"We can report to the BSI later, we're busy right now." The 24-hour deadline begins with knowledge of the significant incident. It is non-negotiable. Anyone who misses it risks fines regardless of the actual damage of the incident itself.
"We don't need a crisis team, IT will handle it." Doesn't work. Care questions, communication issues, HR matters, vendor coordination, external forensics, authority contact — IT alone has neither the mandate nor the resources. Crisis management in a hospital is a leadership task, from minute one.
"Just restore backups and it'll be fine." Backups managed within the same Active Directory are often compromised themselves. Most modern ransomware families target and destroy backups before encryption. Only offline stored or immutable backups are reliable — and even these must be verified before reconnection.
What Must Happen Before the Incident
The operational roadmap only works with preparation. Six building blocks that must be established in advance:
1. Documented crisis team structure. Who is in it, who acts as deputy, private phone numbers, clear competencies, and escalation thresholds. Updated semi-annually, distributed as a physical card to all crisis team members.
2. Physical emergency folder available. On paper, not in the IT system. Content: crisis team list, forensics service providers, BSI contact, MUK login, insurance policy, template texts for the three reports, admission and treatment forms for manual operation. Stored in at least two independent locations.
3. Backup strategy 3-2-1 with an offline component. Three copies, two media types, one offline or immutable. Quarterly tested restoration, documented. For hyperscaler backups: multi-factor authentication for backup admins, separate identities from production AD.
4. Tabletop exercise at least once a year. Half-day simulation of a cyberattack with the real crisis management team. What works, what doesn't. Weak points become painlessly visible during the exercise — in a real case, they are expensive.
5. Forensics contract in advance. Stand-by contracts with 24/7 response time. Ideally, annual test engagements so the provider knows your environment and does not have to learn the topology during a crisis.
6. Documented escalation chains. Who decides what at what point? Who is allowed to disconnect the network from the internet? Who communicates with the media? Who is legally liable for which decision? This clarification must be in writing and known to all involved.
NIS2 compliance under Section 30 of the BSIG demands nothing less. Hospitals that do not have these components are not only in trouble when an incident occurs — they are regulatory vulnerable and lack a shield in fine proceedings.
Lessons from Real Cases
Lukaskrankenhaus Neuss (February 2016). Weeks of manual operation after a ransomware attack. The crisis team functioned, and patient care was maintained. Lesson: Advance planning for manual operation — including practiced forms and telephone chains — is vital for survival.
Klinikum Lippe (November 2022). After intensive negotiations, the data was decrypted. The question of a ransom payment remained controversial in public reporting. Lesson: Have a negotiation option, but do not plan for it as Plan A — clean backups remain the gold standard.
Caritas-Klinik Dominikus Berlin (February 2024). Recovery without documented ransom payment, but weeks of operational restrictions. Lesson: A clean backup strategy saves the extortion amount — but costs recovery time that must be bridged communicatively and operationally.
MVZ Tirschenreuth/Kemnath (Autumn 2025). Multiple locations affected simultaneously because a central IT infrastructure was compromised. Lesson: Distributed infrastructure and cleanly segmented networks reduce single points of failure — a central AD without replication separation is a single point of failure.
ChipSoft Netherlands (April 2026). A ransomware attack on a single software vendor crippled about 80 percent of Dutch hospitals. Lesson: Supply chain risk is real and systemic — a cyberattack on one clinic can hit a clinic that did everything right itself. Vendor security under Section 30 (2) No. 4 BSIG is therefore not a formality.
Conclusion
A ransomware incident in a clinic is the most demanding crisis currently known to the German healthcare system. The operational roadmap is clear — 30 minutes containment, 24 hours initial report, 72 hours assessment, 30 days final report — but it only works with preparation.
The five most important levers: documented crisis team, physical emergency folder, tested offline backups, stand-by forensics contract, annual tabletop exercise. Anyone who has these five will survive an incident. Anyone who does not is taking risks — financially, regulatorily, and reputationally.
NIS2 is tightening the screw. Section 32 BSIG with the 24/72/30-day logic makes preparation mandatory — and the personal liability of the management under Section 38 BSIG ensures that omissions have consequences, even beyond the immediate incident.
Cybersecurity in a hospital is not an IT task, but a care task. It belongs on the agenda of executive management, not in the inbox of the helpdesk.
At Entropy CS, we offer Managed Incident Detection & Response for healthcare facilities — 24/7 SOC team with healthcare specialization, EDR/XDR integration, threat intelligence from healthcare ISACs, prepared incident playbooks for ransomware scenarios, and NIS2-compliant reporting documentation. Our free Risk Assessment takes 30 minutes and provides an honest evaluation of your incident readiness — including specific gaps in your crisis management team, backup strategy, and reporting processes.


