Case study / Healthcare

Regional health system, PACS isolation.

A US regional health system, 6 hospitals, 8,000 staff, 200,000 patient encounters per year. Ransomware hit imaging (PACS) during clinical hours. EHR and lab were operational but unverified. Customer identity withheld under confidentiality.

What happened.

At 14:32 imaging workstations started returning unreadable files. Within an hour, radiology was offline across all six hospitals. The clinical question was urgent: was the EHR safe? Was the lab system safe? If yes, the care delivery infrastructure could keep running while imaging recovered separately. If no, the entire health system needed to be isolated.

The customer's existing backup tools could restore individual workloads, but not verify them as clean. The recovery team faced a worst-case choice: a blanket rollback of every clinical system, which would stop the EHR and the lab and turn the incident into a multi-day care-delivery outage.

Per-workload recovery, not blanket rollback.

01

Three independent scans

Cybersnap.io scanned EHR, imaging, and lab as three separate workload populations. Per-workload recovery candidates were ranked independently.

02

EHR verified clean

Patient records, scheduling, and clinical documentation systems showed no ransomware indicators across 24 hours of snapshot history. Clinical operations could continue.

03

Lab verified clean

LIS and diagnostic systems were verified independently. Lab results continued to deliver normally to patient care teams.

04

Imaging isolated

PACS and radiology systems were isolated. Their closest clean snapshot, SS-03:00, was identified within minutes. Sandbox validation confirmed clean restore.

05

Imaging restored

Radiology came back online from SS-03:00 within hours, separately from the rest of the clinical environment. No data loss beyond the 3-hour compromise window.

06

Audit trail for HIPAA

Cybersnap.io exported the full per-workload scan evidence and verdict log for the HIPAA breach analysis and state breach notification review.

The numbers.

Clinical workloads operational
2 of 3
EHR and lab continued serving patients throughout the incident.
Care delivery saved
11 hours
Hours of patient care that would have been lost to a blanket rollback.
Imaging recovery
3 hours
Time from verdict to PACS back online from SS-03:00.
Patient data loss
0
No patient records lost. Only the 3-hour imaging compromise window required re-acquisition.
HIPAA evidence
Audit-grade
The exported audit trail was accepted by HIPAA breach review and state regulators.
State breach notification
Avoided
The per-workload isolation contained PHI exposure within reportable thresholds.
What the CIO said

“Per-workload recovery is the difference between a contained imaging incident and a system-wide outage. Cybersnap.io gave us the evidence to make that distinction in minutes.”

— CIO, anonymized customer. Reference call available under NDA after a Cybersnap.io briefing.

Evaluating Cybersnap.io for a healthcare environment?

Book a confidential briefing. We will walk you through the platform, HIPAA-aligned deployment, and the reference process.