Ransomware Readiness: 10 Questions Every Small Practice Should Ask
Ransomware is one of the most disruptive cyber threats facing healthcare organizations today. Unlike many cyber incidents, ransomware can quickly lock employees out of critical systems, interrupt patient care, delay billing, and create complex compliance and reporting obligations.
Many healthcare practices have invested in cybersecurity tools, but ransomware readiness goes beyond prevention. The real question is whether your organization could detect an attack, limit the damage, recover critical systems, and continue serving patients if ransomware made it through your defenses.
The questions below address the specific controls, processes, and recovery capabilities that often determine the severity of a ransomware incident’s impact on an organization. Use this assessment to identify potential gaps, evaluate your preparedness, and better understand how your practice would respond if ransomware disrupted operations tomorrow.
1. Could one stolen password expose your entire environment?
Compromised credentials are a common starting point for ransomware attacks, making access controls one of the most important defenses.
Multi-factor authentication is required for email, VPN, and administrator accounts.
Former employee accounts are removed promptly.
Administrative privileges are limited to those who need them.
Remote access tools are restricted and secure.
Warning Signs
- Shared administrator accounts are still in use.
- MFA is optional rather than required.
- Former employee accounts remain active.
- Administrative privileges are not governed.
2. Are known vulnerabilities being addressed before attackers find them?
Cybercriminals often look for known vulnerabilities. Keeping systems updated helps close those gaps before attackers can exploit them.
A process exists to regularly review missing patches.
Critical patches are applied within a defined timeframe.
Internet-facing systems are prioritized.
Operating systems and applications are kept up to date.
Warning Signs
- Software updates are delayed until someone has time.
- Unsupported operating systems are still in use.
- Patch status is not regularly reviewed.
- Internet-facing systems are updated on the same schedule as everything else.
3. Could your team spot a phishing attempt?
Phishing emails remain one of the most common ransomware entry points because they rely on human error rather than technical vulnerabilities.
Risky file types and macros are restricted.
Email authentication protocols (SPF, DKIM, and DMARC) are configured.
Employees can easily report suspicious emails.
Staff receive ongoing phishing awareness training.
Warning Signs
- Employees receive training only during onboarding.
- Suspicious emails often go unreported.
- Email Authentication is not properly configured.
- Staff are unsure how to verify unexpected requests or attachments.
4. Are your employees part of the security strategy?
Technology plays a critical role in preventing ransomware, but employees also need to understand how their actions affect security. A strong security culture encourages people to report concerns quickly, ask questions, and treat cybersecurity as part of daily operations.
Security awareness training occurs regularly.
Phishing simulations are conducted.
Employees know how to report suspicious activity.
Participation and improvement are tracked.
Warning Signs
- Training is viewed as a compliance exercise rather than a business priority.
- Employees are hesitant to report mistakes.
- Security topics are discussed only after incidents occur.
- Leadership is not actively involved in reinforcing cybersecurity practices.
5. Would you know if ransomware was spreading through your network?
The sooner unusual activity is detected, the more likely your organization is to contain an attack before it reaches critical systems.
Endpoint detection and response (EDR) or advanced security tools are deployed.
Employees understand when to report an incident
Alerts are regularly reviewed.
Critical systems are segmented to limit lateral movement.
Warning Signs
- Devices have inconsistent security protections.
- Security alerts are rarely reviewed.
- All systems share the same network with few restrictions.
- You would rely on an employee reporting a problem before an incident is discovered.
6. Does everyone know their role during an incident?
When ransomware strikes, uncertainty can slow response efforts and increase damage.
A ransomware response plan is documented.
Key responsibilities are clearly assigned.
Contact information is available offline.
Response procedures are reviewed regularly.
Warning Signs
- Employees do not know who to contact during an incident.
- Response procedures exist but have never been tested.
- Critical contact information is stored only on affected systems.
7. Could your team contain an attack quickly?
The actions taken during the first few minutes of a ransomware incident often determine how far the attack spreads.
Employees understand how to isolate affected devices.
Procedures exist for preserving evidence.
Leadership knows when to activate the response team.
Initial containment steps have been documented and discussed.
Warning Signs
- Employees would immediately reboot infected devices.
- Staff is uncertain whether systems should be disconnected from the network.
- There is no clear process for escalating incidents.
- The organization has never practiced an incident response scenario.
8. Could you restore your data without paying a ransom?
If ransomware encrypts your systems, recovery depends on whether you can restore clean, accessible data.
Backups follow the 3-2-1 rule: three copies, two storage locations, one offsite or offline copy.
At least one backup is isolated from our network.
We regularly test backup restoration.
Backup access is protected with separate credentials.
Warning Signs
- Backups have never been tested.
- All backups remain connected to the production network.
- Multiple employees have unrestricted access to backup systems.
9. How quickly could your practice return to normal operations?
Recovery involves much more than turning systems back on. It requires knowing which applications are most critical, how quickly they need to be restored, and how staff and patients will be kept informed.
Critical systems have been prioritized.
Acceptable downtime has been defined.
Full recovery testing has been performed.
Communication plans exist for staff and patients.
Warning Signs
- No formal recovery priorities exist.
- Backup restores have never been tested at scale.
- Business operations depend heavily on a single application.
- Communication plans would need to be created during the incident.
10. Are you prepared for compliance and reporting requirements?
For healthcare organizations, ransomware often extends beyond downtime and becomes a potential compliance issue. Determining whether protected health information was accessed or exfiltrated is often just as important as restoring systems.
Security risk assessments are performed and documented.
Procedures exist for determining whether data was accessed or exfiltrated.
Breach notification requirements are understood.
Compliance responsibilities are assigned before an incident occurs.
Warning Signs
- Regulatory obligations have not been reviewed recently.
- Leadership is unclear about reporting requirements.
- Risk assessments are outdated or incomplete.
- Compliance decisions would be made only after an incident occurs.
What do your results mean?
Mostly Checked
Your practice has many foundational safeguards in place to reduce ransomware risk. Continue reviewing controls, testing recovery plans, and updating procedures as systems, staffing, and threats change.
Some Checked
Your practice has made progress, but remaining gaps could slow response or increase downtime during a ransomware event. Prioritize the areas that would have the greatest impact on patient care, data access, and recovery.
Few Checked
Your practice may have meaningful exposure to ransomware and related cybersecurity threats. Addressing these foundational controls can help protect systems, patient data, and daily operations.
Keep Your Practice Safe with Lutz
Every question in this checklist is designed to identify a potential gap in your ransomware readiness. Whether it's access controls, backup testing, employee training, or incident response planning, the goal isn't perfection. It's understanding where your practice may be vulnerable and addressing those weak spots.
If you found areas where the answer was "not yet" or "I'm not sure," you're not alone. Many healthcare practices know cybersecurity matters but struggle to determine which risks to focus on first. That's where an outside assessment can help.
Lutz’s Outsourced IT team helps healthcare organizations evaluate their current environment, identify gaps, and prioritize practical improvements that strengthen security and support business continuity. As part of Lutz's Healthcare industry specialty, our team understands the unique challenges medical practices face and can help you build a roadmap to better protect your systems and patient data. To start a conversation, contact us.
Recent News & Insights
Ransomware Readiness: 10 Questions Every Small Practice Should Ask
The Market & The Midterms
Lutz Announces 2026 Senior through Manager Promotions
Lutz Announces 2026 Shareholder & Director Promotions

%20(1).jpg?width=264&height=160&name=Website%20Featured%20Content%20Images%20(2)%20(1).jpg)
%20(1).jpg?width=264&height=160&name=Website%20Featured%20Content%20Images%20(4)%20(1).jpg)
-Mar-08-2024-08-50-35-9527-PM.png?width=300&height=175&name=Untitled%20design%20(1)-Mar-08-2024-08-50-35-9527-PM.png)

%20(1)-1.jpg?width=264&height=160&name=Website%20Featured%20Content%20Images%20(2)%20(1)-1.jpg)
-1.jpg?width=264&height=160&name=Website%20Featured%20Content%20Images%20(1)-1.jpg)
%20(1).jpg?width=264&height=160&name=Website%20Featured%20Content%20Images%20(3)%20(1).jpg)