Currently dealing with a breach or active incident?Call 406-924-3731×
≡
Blog

Data breach at your Montana medical practice? Here's your emergency action plan

What to do the moment someone says "I think we've been hacked": the first three calls to make, and six steps to contain a breach without destroying evidence.

By Big Sky Support

Data breach at your Montana medical practice? Here's your emergency action plan
PUBLISHED
March 5, 2026
READING TIME
6 min read
CATEGORIES
Incident Response
Healthcare
HIPAA
Make three calls first
Incident response specialists, healthcare counsel, and your insurer, before touching anything.
Don't start fixing
Isolate systems only under expert guidance, and preserve every piece of evidence.
Monitoring isn't response
In real breaches, most IT providers end up calling specialists anyway.

The worst time to build a relationship with crisis specialists is while your practice is in crisis.

When someone at your practice says, "I think we've been hacked," you don't just have an IT problem. You have a patient safety, regulatory, and business survival event in motion. The next few hours decide whether it becomes a controlled incident or a full-scale crisis.

The worst thing you can do is start guessing or hoping it's a false alarm. The best thing you can do is slow down, make the right first calls, and follow a structured plan.

Your first three calls

Make these calls before you try to fix anything.

1. Cybersecurity incident response specialists

This should be your first call, before anyone reboots systems, restores backups, or deletes files. You need a team that handles incident response and digital forensics as core work, not an occasional project; that can quickly assess what's happening, contain the threat, and protect the data that's left; and that knows how to preserve evidence so it holds up in regulatory reviews and legal proceedings.

In serious incidents, many general IT companies end up calling specialists like us anyway. You can skip the middle layer and work directly with the specialists from the first sign of trouble.

2. Healthcare legal counsel

Contact an attorney who understands HIPAA breach notification, Montana's reporting requirements, and how to structure an investigation under legal privilege. Counsel will guide what gets documented, who needs to be notified, and how to limit liability while still meeting your obligations.

3. Your cyber or malpractice insurer

Notify your insurer as soon as you reasonably suspect a breach. Many policies require prompt notice as a condition of coverage and specify which vendors must be used or pre-approved. Waiting on this call can put coverage for forensics, notifications, and legal support at risk.

Six critical steps on the ground

While your response team mobilizes, your practice can take these steps.

1. Pull out your incident response plan

If you have a written plan, follow it step by step. If you don't, your cybersecurity team becomes your plan in real time, telling you who does what, which systems to touch and which to leave alone, and how to organize communication. That's one of the main reasons to have specialists lined up before an incident.

2. Isolate the threat under expert guidance

Don't start unplugging everything without a plan. Under your response team's direction, disconnect clearly affected systems or network segments from the network and internet, and don't power systems off unless you're told to, because shutting down can destroy evidence stored in memory. Think of it like isolating a patient: contain the infection without making the diagnosis harder.

3. Preserve all evidence

Don't delete suspicious files, clear logs or browser histories, or rebuild systems before they've been examined. Every log entry and artifact is evidence your forensics and legal teams need to determine what happened, which data and which patients were affected, and how long it went on. This is exactly where specialized incident response differs from everyday IT cleanup.

4. Notify key internal stakeholders

Inform the practice owners, senior leaders, and a small group of operational and clinical leads who need to know. Keep communication calm and clear, focused on what to do and what not to do, like avoiding certain systems and deleting nothing. Hold off on broad announcements until you have facts.

5. Support the investigation

Your cybersecurity and legal teams will work together to identify the entry point and attack path, establish the scope and timeline, and map exactly what patient data was accessed or put at risk. Your role is to provide access, answer operational questions, and help them understand your workflows and systems.

6. Prepare for notification and remediation

Once the investigation has enough clarity, legal counsel will advise on any required HIPAA notifications to patients and regulators, plus state and contractual reporting. Your cybersecurity team will handle remediation and hardening: patching, password resets, configuration changes, network segmentation, and rebuilds if necessary.

The goal isn't just getting back online. It's getting back online safely and in compliance.

Why you shouldn't face a breach alone

The moment you suspect a breach is confusing and stressful, and having trusted specialists identified ahead of time changes everything. Most general IT companies do good work keeping systems running day to day, but in a true security crisis, many of them call incident response and forensics teams like ours. You can decide now whether to wait for that second call in the middle of an emergency, or build a direct relationship with the crisis specialists from the start.

We focus on incident response and digital forensics for Montana healthcare, investigations and documentation built to hold up under HIPAA scrutiny, and helping practices prepare before anything happens with plans, testing, and training, as well as guiding them through and after an incident.

FAQ

Common questions

Short answers to the questions we hear most about this topic.

Should we call our IT provider first after a suspected breach?

You can let them know, but your first technical call should be to an incident response and forensics team. Your IT provider will likely be involved, but handling a breach takes specific skills and processes that go beyond normal support.

How quickly do we need to act on a suspected breach?

As quickly as possible. The first hours matter for containment, evidence preservation, and insurance notice requirements. But quickly doesn't mean rashly. Act fast, under expert guidance.

Do we have to notify patients and regulators after every incident?

Not always. HIPAA presumes that unauthorized access to unsecured patient information is a reportable breach unless a documented risk assessment shows a low probability the data was compromised. That determination should be made with your legal counsel and cybersecurity team, based on the facts the investigation uncovers.

What if our suspected breach turns out to be a false alarm?

That's a good outcome. It means you exercised your plan and know your response path works. The cost of a false alarm call is small compared to a real incident handled too slowly.

Glossary

Terms used in this article

Plain definitions, so nothing above needs a second search.

Incident Response
The work of containing an active security incident, removing the attacker, and restoring normal operations. It's what you need when a breach or ransomware attack is actually happening.
Incident Response Plan
A written playbook for what your organization does when a security incident happens: who leads, who to call, how to contain affected systems, and how to handle notification.
Digital Forensics
Collecting and analyzing evidence from systems and accounts to reconstruct what an attacker did, when, and how. It supports breach notification decisions, insurance claims, legal matters, and law enforcement.
Evidence Preservation
Protecting logs, disk images, and other artifacts during an incident so investigators can prove what happened. Wiping and rebuilding systems too early destroys this evidence.
Breach Notification
The legal duty to tell affected patients, regulators, and sometimes the media after a breach of patient data. HIPAA requires notice without unreasonable delay and no later than 60 days after the breach is discovered.
Legal Privilege
Protection that can keep certain communications and investigation work confidential when they're done at the direction of your attorney. Counsel often structures breach investigations this way.
Cyber Insurance
Insurance that helps cover the costs of a cyber incident, like investigation, recovery, notification, and legal fees. Carriers increasingly require specific security controls before they'll issue or renew a policy.
TALK TO US

Line up your response team before you need one.

Same day onsite for contract clients. Everyone else pays $165 an hour, with no emergency surcharge, and gets forensic imaging before remediation.

See incident responseAll articles