Free Download

If Your Practice Gets Hit, You Won't Have Time to Think

A free, print-ready checklist covering exactly what to do in the first 15 minutes, the first hour, and the days that follow a cybersecurity incident, before you need it.

Get the Checklist → One short form. Straight to your inbox.
Phase 1, Detect and Isolate checklist page
Emergency response directory page
Cybersecurity Incident Response field guide cover
8 pages · yours in one click
$0M
Average ransom demand in a healthcare breach
0 Days
Average downtime once a practice is hit
0 Days
To notify HHS once a breach is discovered
The Journey

Five Phases, In the Order They Have to Happen

Detection and containment come first. Restoring anything before forensic clearance can reintroduce the problem, so the sequence matters as much as the steps inside it.

01
First 15 Min
Detect & Isolate

Contain the threat before it spreads

Identify every affected device or account, disconnect it from the network, and leave the system exactly as it is.

Don't power the device off. A powered-down device destroys the evidence a forensic team needs.
02
First Hour
Make the Right Calls

The order you call in can protect your coverage

Cyber insurance first, then your attorney, then IT or your managed security provider, then leadership. Most policies require notification before remediation starts.

Don't engage the attackers. No contact and no payment without your insurer's guidance.
03
2 to 24 Hours
Contain & Assess

Forensics leads, you preserve and keep moving

The forensic team assigned by your insurer scopes the breach. Your job is preserving logs, emails, and devices, and keeping the practice running on paper where you can.

04
Within 60 Days
HIPAA & Notification

The clock starts at discovery, not at the breach

Your attorney determines reportability. Unauthorized access to unsecured PHI is presumed reportable to HHS unless an exception applies, and affected patients need written notice.

05
After Clearance
Restore & Recover

Recovery is a sequence, not a switch

Clean backup, new credentials everywhere, careful resumption of billing, and a post-incident review within 30 days to close the gap that let this happen.

What's Inside

Built to Sit by the Workstation, Not in a Drawer

The exact first-15-minute isolation steps, and the two things you should never do.

Who to call first, it is not your IT contractor, and why the order matters for your coverage.

What has to happen before the HIPAA 60-day notification clock starts working against you.

A fill-in-the-blank emergency contact sheet to keep by every workstation.

The Cost of Not Having a Plan

The average ransom demand in a healthcare cyberattack is $1.3 million. The average practice that gets hit is down for 18 days, no claims going out, no revenue coming in. Most practices have some kind of IT support. Very few have an actual plan for the first hour.

This checklist is the plan. Five phases, in order, from the moment you suspect something is wrong through HIPAA notification and getting your billing back online.

Get the Checklist →
$1.3M
Average ransom demand
18 Days
Average downtime
60 Days
To notify HHS from discovery
5+ Yrs
Physician-led revenue recovery
30+
Independent practice clients
200+
Podcast episodes on running a practice

Get Your Copy →

We'll send the checklist straight to your inbox.

One download. No spam. Straight to your inbox.
Get the Checklist →