Active incident

In the middle of an incident? Start here.

You'll reach a senior, healthcare-focused security practitioner, not a ticket queue. We help you contain it, preserve what you'll need later, and keep care running.

While we get on the line, protect yourself

  1. Isolate, don't destroyDisconnect affected systems from the network, but don't power them off or wipe them. Powering down erases memory and the forensic trail you'll need later.
  2. Preserve the evidenceCapture logs and disk/memory images before you rebuild anything. The most useful data is the most volatile, it disappears first.
  3. Lock down accessDisable accounts you suspect are compromised and rotate critical credentials. Assume the way in is still open until you've proven otherwise.
  4. Don't engage the attackerDon't pay, negotiate, or message them before you understand the scope and have looped in legal counsel and your cyber-insurer.
  5. Start a timelineWrite down every action with a timestamp. You'll need it for the HIPAA breach analysis, your insurer, and any law-enforcement case.
  6. Call your insurer and counselMany cyber policies require prompt notice and may direct the response. We can run point or work alongside whoever they assign.

What happens when you call

  • You talk to a senior practitioner right away, CISSP, CISA, and GIAC GCFA digital-forensics background. No junior intake queue.
  • We help scope and contain without taking more offline than necessary, in a hospital, downtime is a patient-safety event, not just an outage.
  • We preserve forensic evidence and reconstruct what actually happened, so decisions rest on facts rather than guesses.
  • We support your HIPAA breach-notification decisions and coordinate with your insurer, counsel, and law enforcement.
  • We help you recover and harden so it can't happen the same way twice.
See our full Incident Response & Recovery service →