When something goes wrong, such as ransomware, a stolen laptop or a misdirected file, the first hour is chaotic. People are stressed, systems may be offline, and the email account where you kept your contacts may be the very thing that is down. A one-page incident contact sheet, prepared in advance and stored where you can reach it, saves time and prevents mistakes when time matters most.
It answers a simple question: who do we call, in what order, and how do we reach them at any hour? It does not replace your incident response plan, but it makes the plan usable.
Administrator or executive director, with a backup
Privacy officer and security officer, with backups
Director of nursing or clinical lead
IT lead or help desk
Communications or family-contact lead
Human resources
List mobile numbers and a second way to reach each person. Include who has authority to make key decisions such as taking systems offline.
Emergency phone line and after-hours instructions
Account manager and escalation contact
Your account or contract number
The claims or incident hotline, which is often separate from the general number
Your policy number and the broker's contact
Any instructions in your policy about notifying the carrier before engaging outside help. Many policies require prompt notice and may specify approved vendors, so read yours now.
An attorney experienced in healthcare privacy and breach response, with an after-hours number
Counsel's role in directing any forensic investigation, if your policy or attorney advises it
If your insurer has an approved panel, list those firms and the process for engaging them.
Your electronic health record vendor's support line and security contact
Pharmacy, eFax, phone, internet and cloud providers
Payroll and billing vendors
Anyone else whose systems connect to yours
Internet and phone carriers' business support numbers, with account numbers and circuit identifiers
Building and facility contacts for power or physical issues
State health department contact for facilities
Law enforcement contact. The FBI field office and local police are options for criminal incidents; ask your counsel when to involve them.
Contact points for reporting to HHS under HIPAA breach notification requirements, which your privacy officer should know
Board chair or owner
Corporate or parent organization
Bank, in case of payment fraud
Public relations or communications support, if you have it
Keep it to one or two pages. Short lists get used.
Put the order first. Who is called first, second and third?
Store it in several places. Print copies for the administrator's office, the nursing station and the homes of key leaders. Keep a copy on a phone and in a cloud location that does not depend on your own network.
Add the date of the last review.
Test the numbers. Call each one at least once a year to confirm it still works.
Update after changes. New staff, new vendors and a new insurance policy all trigger an edit.
At the top, list the first few steps: note the time, disconnect affected devices from the network but do not power them off unless advised, call the IT provider, notify the privacy officer and call the insurer's hotline. Avoid deleting anything. Your plan may differ, so adapt this list with your IT provider and counsel.
Spend thirty minutes walking through a scenario, such as ransomware on a Friday evening, using only the contact sheet. You will quickly find missing numbers and unclear roles.
UnityCare IT can help you draft the sheet, confirm our own after-hours procedures and run a short tabletop exercise so your team knows how to use it.
An outsourced IT department with proactive maintenance and one number to call.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172