Many organizations have an incident response plan in theory. It is a thick binder or a forty-page document written to satisfy an auditor, and it lives on a shared drive that will be unavailable during an actual incident. When something happens, such as ransomware on a Sunday night, nobody opens it.
A better starting point is a one-page plan that fits on a single sheet, posted on a wall and printed in the downtime kit. It does not replace detailed procedures, but it makes sure the first hour goes well. Here is what to put on it.
List the signs staff should treat as possible security incidents.
Ransom notes or files that suddenly will not open
Computers acting strangely, such as sudden slowness or unexpected pop-ups
A user reporting they entered a password on a suspicious page
Unexpected password reset or MFA prompts
A lost or stolen device
Resident information sent to the wrong person
Unusual vendor or executive requests for payment or data
Tell staff the rule: if in doubt, report it.
Stop using the affected device, but do not turn it off unless instructed
Disconnect it from the network if you know how, by unplugging the cable or turning off Wi-Fi
Do not delete messages, files or notes
Call the incident number immediately, not email, since email may be compromised
Write down what you saw and the time
This is the most valuable part of the page. Include names, roles and phone numbers, including cell numbers.
Incident lead: Administrator or designee
IT provider or helpdesk: Primary and after-hours numbers
Clinical lead: Director of nursing or designee
Legal counsel: Preferably one with healthcare privacy experience
Law enforcement: Local contact and FBI field office information, noting that CISA and the FBI encourage reporting ransomware incidents
Review the list at least twice a year, and whenever someone changes roles.
Assign a few clear jobs.
Incident lead: Makes decisions, coordinates and keeps leadership informed
Technical lead: Directs containment and investigation with IT
Communications lead: Handles internal messages, and families or media only after approval
Scribe: Keeps a timeline of actions, decisions and who was told what
In a small facility, one person may hold more than one role. The point is that everyone knows who is in charge.
A short list prompts the right questions.
Is resident care or safety affected? Activate downtime procedures.
Could protected health information be involved? Notify the privacy officer and begin the breach risk assessment, remembering the 60-day outer limit for HIPAA notifications.
Do we need outside forensic help? Call the insurer's hotline before hiring on your own, since coverage may depend on approved vendors.
Should we contact law enforcement? Often yes for criminal activity.
Are there contractual, state or regulatory notice duties?
Do not pay a ransom or negotiate without legal and insurer involvement
Do not wipe or reimage machines before evidence is preserved, unless advised
Do not discuss the incident on social media or with the press without approval
Do not use potentially compromised email to coordinate. Have a backup channel, such as a phone call group or a messaging app outside your network
List the follow-up items briefly: restore systems from verified backups, reset credentials, conduct a lessons-learned review and update the plan and training.
Run a thirty-minute walkthrough once or twice a year. Pose a scenario and ask each person what they would do. Note where the page is unclear, then revise it. NIST publishes incident response guidance, and the NIST Cybersecurity Framework 2.0 includes response and recovery functions you can use to expand your plan later.
Print copies for the administrator's office, nurses' stations, the downtime kit and each leader's phone or wallet. Store a digital copy outside your main network, such as in a separate cloud location.
UnityCare IT helps healthcare organizations draft one-page response plans and run tabletop exercises that test them. If you do not have a plan yet, this is a good place to start, and we can build it with you.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172