When a cyber incident hits a healthcare organization, the first hours are usually chaotic. Systems are down or behaving strangely, staff are asking questions, and everyone wants to help. Without clear roles, people duplicate effort, step on each other and make decisions that are hard to undo.
A good response is a team effort with defined responsibilities. Knowing who does what before an incident gives you a head start.
Someone should be in charge of coordination. In a small or mid-size facility this is often the administrator, executive director or compliance officer. The incident lead does not need technical expertise. Their job is to make sure the right people are engaged, decisions get made, and a record of actions and times is kept.
Counsel, ideally with experience in healthcare privacy and breach response, guides the response through a legal lens.
Advises on whether the incident involves protected health information and whether HIPAA breach notification obligations apply, including the timelines under the Breach Notification Rule.
Considers state breach notification laws, which vary and may apply on top of HIPAA.
Helps decide when to notify regulators, residents, insurers and law enforcement.
Often engages the forensic firm directly, which may help keep investigation findings within attorney-client privilege. Your counsel can explain how that works in your situation.
Reviews external statements before they go out.
Forensics specialists determine what happened. They work out how the attacker got in, what systems were touched, whether data was taken and whether the attacker is still present. They preserve evidence, such as logs and system images, and produce findings that support notification decisions and recovery.
Their conclusions matter. Whether protected information was actually accessed or acquired often drives what you must report, so rushing to say "nothing was taken" before the investigation concludes is risky.
Your IT team or provider handles hands-on technical work.
Contains the incident, such as isolating affected devices and disabling compromised accounts.
Works with forensics to preserve evidence rather than wiping systems too soon.
Restores operations from backups once it is safe.
Strengthens defenses afterward, such as resetting credentials and closing the entry point.
Supports clinical downtime procedures so care continues.
IT should coordinate with counsel and forensics before major actions like rebuilding systems, because some steps destroy evidence.
Someone must manage what is said, to whom and when. That includes staff, residents and families, referral partners, the press if relevant, and regulators. Communication should be accurate, consistent and approved by counsel. Avoid speculation, and do not promise things you cannot confirm. Staff should know who the single spokesperson is and be told not to post about the incident on social media.
Whoever leads should keep a running log with times, decisions and who made them. It helps counsel with notification timelines, helps forensics build a timeline and helps you learn afterward. Keep it somewhere that does not depend on the affected systems.
Cyber insurance carrier. Policies often require prompt notice and may require use of approved vendors. Check your policy before hiring anyone.
Clinical leadership. The DON and department heads keep resident care safe during downtime.
Law enforcement. Counsel can advise on contacting authorities such as the FBI.
Write a one-page contact list with names and after-hours numbers for each role.
Identify counsel and a forensic firm in advance, or confirm what your insurer provides.
Decide who the incident lead and spokesperson are.
Keep a printed copy of the plan, since email and shared drives may be unavailable.
Run a tabletop exercise once a year to rehearse.
UnityCare IT fills the technical response role and works alongside your counsel, forensic firm and insurer rather than replacing them. We can help you build the contact sheet, document your systems so responders get oriented quickly, and rehearse the plan before you need it.
Security monitoring, HIPAA safeguards, backups and staff training for healthcare and small businesses.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172