Building an Incident Response Plan on One Page

Many organizations have an incident response plan in theory. It is a thick binder or a forty-page document written to satisfy an auditor, and it lives on a shared drive that will be unavailable during an actual incident. When something happens, such as ransomware on a Sunday night, nobody opens it.

A better starting point is a one-page plan that fits on a single sheet, posted on a wall and printed in the downtime kit. It does not replace detailed procedures, but it makes sure the first hour goes well. Here is what to put on it.

The top of the page: how to recognize an incident

List the signs staff should treat as possible security incidents.

Ransom notes or files that suddenly will not open

Computers acting strangely, such as sudden slowness or unexpected pop-ups

A user reporting they entered a password on a suspicious page

Unexpected password reset or MFA prompts

A lost or stolen device

Resident information sent to the wrong person

Unusual vendor or executive requests for payment or data

Tell staff the rule: if in doubt, report it.

First steps for anyone

Stop using the affected device, but do not turn it off unless instructed

Disconnect it from the network if you know how, by unplugging the cable or turning off Wi-Fi

Do not delete messages, files or notes

Call the incident number immediately, not email, since email may be compromised

Write down what you saw and the time

The contact list

This is the most valuable part of the page. Include names, roles and phone numbers, including cell numbers.

Incident lead: Administrator or designee

IT provider or helpdesk: Primary and after-hours numbers

Clinical lead: Director of nursing or designee

Compliance or privacy officer

Legal counsel: Preferably one with healthcare privacy experience

Cyber insurance hotline and policy number

EMR vendor support

Corporate or ownership contacts, if applicable

Law enforcement: Local contact and FBI field office information, noting that CISA and the FBI encourage reporting ransomware incidents

Review the list at least twice a year, and whenever someone changes roles.

Roles in the first hour

Assign a few clear jobs.

Incident lead: Makes decisions, coordinates and keeps leadership informed

Technical lead: Directs containment and investigation with IT

Communications lead: Handles internal messages, and families or media only after approval

Scribe: Keeps a timeline of actions, decisions and who was told what

In a small facility, one person may hold more than one role. The point is that everyone knows who is in charge.

Decision points

A short list prompts the right questions.

Is resident care or safety affected? Activate downtime procedures.

Could protected health information be involved? Notify the privacy officer and begin the breach risk assessment, remembering the 60-day outer limit for HIPAA notifications.

Do we need outside forensic help? Call the insurer's hotline before hiring on your own, since coverage may depend on approved vendors.

Should we contact law enforcement? Often yes for criminal activity.

Are there contractual, state or regulatory notice duties?

Things not to do

Do not pay a ransom or negotiate without legal and insurer involvement

Do not wipe or reimage machines before evidence is preserved, unless advised

Do not discuss the incident on social media or with the press without approval

Do not use potentially compromised email to coordinate. Have a backup channel, such as a phone call group or a messaging app outside your network

After the incident

List the follow-up items briefly: restore systems from verified backups, reset credentials, conduct a lessons-learned review and update the plan and training.

Practice with a tabletop exercise

Run a thirty-minute walkthrough once or twice a year. Pose a scenario and ask each person what they would do. Note where the page is unclear, then revise it. NIST publishes incident response guidance, and the NIST Cybersecurity Framework 2.0 includes response and recovery functions you can use to expand your plan later.

Keep it accessible

Print copies for the administrator's office, nurses' stations, the downtime kit and each leader's phone or wallet. Store a digital copy outside your main network, such as in a separate cloud location.

UnityCare IT helps healthcare organizations draft one-page response plans and run tabletop exercises that test them. If you do not have a plan yet, this is a good place to start, and we can build it with you.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172