Tomorrow, that will be you.
Your receptionist is on the line. The screen at the front desk is locked. Black background, red text. The first patient is in 68 minutes. You're 15 minutes away.
Unplugging destroys forensic evidence and won't reverse the encryption. Paying confirms you're a soft target — most who pay get hit again within 12 months. Calling the vendor first delays the regulatory clock that has already started.
The screen is the crime scene. You photograph it. Then you decide who to call, in what order.
You're on-site. Sixteen patients are scheduled today. One is already in the waiting room. The screen is still showing the ransom note.
Ethically, healthcare depends on trust — delaying disclosure after a data breach can damage that trust more than the breach itself, and patients need timely information to protect themselves.
Legally, under Singapore's Personal Data Protection Act (PDPA), clinics must assess quickly, notify the Personal Data Protection Commission (PDPC) within 3 days if required, and inform affected patients as soon as practicable.
The IT vendor cannot diagnose the source of the breach. Your local backup is encrypted along with the live system. The cloud backup might be intact. Police have logged the report. You have 11,000 patient records on this system. Fourteen years of practice.
Every other call — the regulator, the insurer, the clinic owner two suburbs over — is a conversation you can only have properly after the one with your lawyer.
What you say in the next eight hours will appear in a document somewhere. Your lawyer's job is to make sure it's the right document, in the right order, said the right way.
Your lawyer's draft notification has arrived. Two pages. One section is titled: "Reasonable security measures in place at the time of the breach."
What you have: antivirus software, password-protected workstations, a one-person IT vendor at SGD 600/month.
What you don't have: a documented security policy. Staff training records. An incident response plan that pre-dates today.
Documenting security measures retroactively is the single move that turns a breach notification into a fraud investigation. The moment a regulator finds timestamps that don't survive scrutiny, the conversation stops being about what was lost — and starts being about what you signed.
Negligence is recoverable. Falsified records are not.