Breach Counsel and the Response Team: Who Does What

When a cyber incident hits a healthcare organization, the first hours are usually chaotic. Systems are down or behaving strangely, staff are asking questions, and everyone wants to help. Without clear roles, people duplicate effort, step on each other and make decisions that are hard to undo.

A good response is a team effort with defined responsibilities. Knowing who does what before an incident gives you a head start.

The incident lead

Someone should be in charge of coordination. In a small or mid-size facility this is often the administrator, executive director or compliance officer. The incident lead does not need technical expertise. Their job is to make sure the right people are engaged, decisions get made, and a record of actions and times is kept.

Legal counsel

Counsel, ideally with experience in healthcare privacy and breach response, guides the response through a legal lens.

Advises on whether the incident involves protected health information and whether HIPAA breach notification obligations apply, including the timelines under the Breach Notification Rule.

Considers state breach notification laws, which vary and may apply on top of HIPAA.

Helps decide when to notify regulators, residents, insurers and law enforcement.

Often engages the forensic firm directly, which may help keep investigation findings within attorney-client privilege. Your counsel can explain how that works in your situation.

Reviews external statements before they go out.

Forensic investigators

Forensics specialists determine what happened. They work out how the attacker got in, what systems were touched, whether data was taken and whether the attacker is still present. They preserve evidence, such as logs and system images, and produce findings that support notification decisions and recovery.

Their conclusions matter. Whether protected information was actually accessed or acquired often drives what you must report, so rushing to say "nothing was taken" before the investigation concludes is risky.

IT and your managed service provider

Your IT team or provider handles hands-on technical work.

Contains the incident, such as isolating affected devices and disabling compromised accounts.

Works with forensics to preserve evidence rather than wiping systems too soon.

Restores operations from backups once it is safe.

Strengthens defenses afterward, such as resetting credentials and closing the entry point.

Supports clinical downtime procedures so care continues.

IT should coordinate with counsel and forensics before major actions like rebuilding systems, because some steps destroy evidence.

Communications

Someone must manage what is said, to whom and when. That includes staff, residents and families, referral partners, the press if relevant, and regulators. Communication should be accurate, consistent and approved by counsel. Avoid speculation, and do not promise things you cannot confirm. Staff should know who the single spokesperson is and be told not to post about the incident on social media.

Documentation throughout

Whoever leads should keep a running log with times, decisions and who made them. It helps counsel with notification timelines, helps forensics build a timeline and helps you learn afterward. Keep it somewhere that does not depend on the affected systems.

Other participants

Cyber insurance carrier. Policies often require prompt notice and may require use of approved vendors. Check your policy before hiring anyone.

Clinical leadership. The DON and department heads keep resident care safe during downtime.

Law enforcement. Counsel can advise on contacting authorities such as the FBI.

Practical steps before an incident

Write a one-page contact list with names and after-hours numbers for each role.

Identify counsel and a forensic firm in advance, or confirm what your insurer provides.

Decide who the incident lead and spokesperson are.

Keep a printed copy of the plan, since email and shared drives may be unavailable.

Run a tabletop exercise once a year to rehearse.

Working with UnityCare IT

UnityCare IT fills the technical response role and works alongside your counsel, forensic firm and insurer rather than replacing them. We can help you build the contact sheet, document your systems so responders get oriented quickly, and rehearse the plan before you need it.

Related service

Security monitoring, HIPAA safeguards, backups and staff training for healthcare and small businesses.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172