The following is a composite case study based on common patterns in ShieldForce-protected hospice agency incident responses. Details have been generalized.
The Agency
A regional hospice provider serving approximately 180 active patients across four counties. Fifty-two staff members including nurses, social workers, chaplains, aides, and administrative staff. EHR: Netsmart myUnity. Email: Microsoft 365. No dedicated IT staff — a part-time IT consultant who handled routine support.
The agency had engaged ShieldForce eight months prior following a conversation at a regional hospice association meeting. Before ShieldForce, they had basic antivirus and a backup drive in the office. After onboarding, they had EDR on all endpoints, advanced email security, MFA enforced across M365, immutable cloud backups, 24/7 SOC monitoring, and a documented incident response plan.
The Attack
At 11:23pm on a Friday, ShieldForce's SOC detected anomalous process behavior on a Windows workstation in the agency's billing office. A process was attempting to enumerate network shares — a classic lateral movement behavior that precedes ransomware deployment.
The alert fired to the on-call SOC analyst. The analyst reviewed the telemetry: the process had been initiated from a user account that had logged in at 9:47pm via a credential that matched the billing manager's account. The billing manager was not scheduled to work Friday night.
At 11:31pm, the SOC analyst initiated containment: the affected workstation was isolated from the network. The billing manager's account was suspended. A second workstation in the billing office that the attacker had already accessed was also isolated.
At 11:39pm — sixteen minutes after the initial alert — the SOC analyst called the agency's designated incident contact: the Executive Director.
The First Hour
The Executive Director, woken by the call, followed the incident response plan. She called the agency's legal counsel (a healthcare privacy attorney whose number was in the plan). She notified the board chair. She confirmed that clinical operations — the nurses on call, the care coordination system — were unaffected: the two isolated workstations were billing machines with no direct access to the clinical EHR.
The SOC continued investigation: the attacker had gained access through a phishing email that had targeted the billing manager approximately eleven days prior. The email had captured the billing manager's Microsoft 365 credentials. The attacker had been monitoring the email account for eleven days, reading billing communications and mapping the network.
The ransomware payload — identified as a variant associated with the Akira group — had been staged on the two billing workstations but had not yet deployed. The SOC's detection and containment had occurred in the reconnaissance and pre-deployment phase.
No patient data was encrypted. No clinical systems were affected. No ransom was demanded because the attack had not reached the deployment stage.

