Sandhills Medical sat on a ransomware breach affecting 170,000 patients for nearly a year before telling anyone. That’s not an oversight. That’s a systemic failure in how healthcare organizations handle cybersecurity incidents from the moment they happen to the moment patients find out.

Healthcare data breach ransomware incident
Ransomware breaches in healthcare continue to expose sensitive patient data long after attackers have moved on.

The Inc Ransom group hit Sandhills, exfiltrated data, and presumably moved on to the next target weeks or months before the public notification finally appeared. The 170,000 affected individuals spent most of that year completely unaware that their protected health information was out in the wild.

Why Healthcare Keeps Losing the Clock Race

Ransomware groups don’t encrypt your data the moment they get in. They spend days or weeks mapping your network, escalating privileges, and staging data for exfiltration. The encryption event you eventually notice is the end of their process, not the beginning.

Healthcare organizations are disproportionately vulnerable to long dwell times for predictable reasons. Legacy clinical systems run without EDR coverage. Network segmentation between clinical and administrative environments is often minimal or purely nominal. Staff are stretched thin, and security teams are underfunded relative to the attack surface they’re protecting.

That dwell time is exactly where threat detection and defense in depth pay for themselves. If you catch lateral movement early, the attacker hasn’t had time to reach your patient database. By the time encryption triggers, you’re already doing damage control on a much bigger problem than downtime.

The Inc Ransom group specifically is known for targeting healthcare. This wasn’t a random hit.

What a Real Incident Response Plan Covers

A lot of organizations have incident response documentation that covers containment and recovery. Far fewer have a clear, pre-approved disclosure process with defined timelines and responsibilities. That gap is why breaches discovered in April turn into notifications sent the following February.

If your IR plan doesn’t answer these questions before an incident happens, you’re writing policy under fire:

  • Who has the legal authority to approve a breach notification?
  • What’s your maximum internal review window before regulators get notified?
  • Who owns external communications, and is your legal team in the loop from hour one?
  • Do you have a pre-drafted notification template that only needs facts filled in?
  • Is there a dedicated contact for affected individuals, separate from your main support line?

HIPAA sets a 60-day clock for breach notifications after discovery, and that clock doesn’t start when you finish your forensics review. It starts when you had enough information to reasonably determine a breach occurred. Investigators and legal teams sometimes treat “discovery” as a flexible concept. Regulators increasingly do not.

Silver Fox threat actor using tax notification phishing campaign
Threat actors like Silver Fox use social engineering and targeted campaigns to gain the initial foothold that makes breaches like Sandhills’ possible.

The real cost of delayed disclosure goes beyond regulatory fines. Patients who don’t know their medical records were stolen can’t monitor for insurance fraud, prescription abuse, or synthetic identity attacks built on their health data. Every month of delay is a month those patients are exposed without knowing it.

Hardening Your Environment Before the Ransom Note Arrives

Disclosure reform matters, but it’s downstream of the actual security posture problem. The goal is to reduce what an attacker can reach and how long they can stay before your defenses notice them.

Start with visibility. You can’t detect what you can’t see, and a surprising number of healthcare environments have large swaths of their network running with minimal logging, no behavioral monitoring, and firewall rules that haven’t been reviewed in years. Brute-force attempts against RDP and VPN endpoints often go unblocked for hours or longer because no one set up automated response rules.

Credential exposure is the typical entry point. Phishing delivers a set of valid credentials, and then the attacker authenticates normally. From a perimeter standpoint, that traffic looks legitimate. Your brute-force controls catch the spray-and-pray stuff, but a single valid credential walking in through a legitimate auth portal doesn’t trigger most alerting rules out of the box.

The practical hardening steps that actually reduce dwell time and blast radius look like this: segment your clinical network from administrative systems with enforced, not just documented, controls; require MFA on every external-facing authentication surface without exception; deploy behavioral monitoring that looks for unusual access patterns rather than just signature matches; review and tighten firewall egress rules so exfiltration triggers alerts before terabytes leave; and run tabletop exercises that specifically test your disclosure process, not just your recovery steps.

Security hardening before an attack is measurably cheaper than breach response after one.

Frequently Asked Questions

How long do ransomware groups typically dwell before encrypting?
Average dwell times across ransomware incidents range from several days to over two weeks, though some intrusions go undetected for months. The encryption event is a late-stage action; data exfiltration often happens well before it.
What does HIPAA actually require for breach notification timing?
Covered entities must notify affected individuals within 60 days of discovering a breach. Breaches affecting 500 or more individuals in a state also require media notification. HHS must be notified within 60 days as well, or annually for smaller breaches.
Does better threat detection actually reduce regulatory exposure?
Yes, in two ways. Faster detection shortens dwell time and limits what attackers can steal. It also gives you a clearer, earlier discovery date, which paradoxically may seem risky but actually starts your compliance clock sooner and shows regulators that you have functioning monitoring in place.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.