When a cyber incident hits, the first hour is rarely lost to technology. It is lost to questions. Who can authorize taking the network offline? Who calls the insurance carrier? Who talks to staff, families or the press? Who is allowed to say that protected health information may have been exposed? If those questions are answered for the first time during the crisis, the answers will be slow, inconsistent and sometimes wrong.
The remedy is to assign decision rights before anything happens. It takes one meeting and a one-page document, and it is among the most valuable preparations an operator can make.
Most incidents involve three distinct kinds of work. Mixing them in one person is a common mistake, because the person fixing the problem cannot also be briefing leadership and drafting notices.
The incident lead has authority to make business decisions quickly. In a small or mid-size organization, this is usually the administrator, executive director or owner. Their responsibilities include:
Approving major actions, such as shutting down systems, switching to downtime procedures or paying for emergency help.
Deciding when to involve outside parties such as legal counsel, the cyber insurance carrier, law enforcement and regulators.
Balancing care and safety against containment. A technician may want to take a system offline; the lead weighs what that means for residents.
Declaring the incident over.
One person owns messages, so staff, residents, families and partners hear a consistent story. This is often the administrator's designee, a marketing or community relations lead, or the compliance officer working with counsel. They are responsible for:
Drafting and approving internal and external messages.
Keeping a log of who was told what, and when.
Routing all media and partner questions to a single point of contact.
Making sure no one improvises explanations on social media or at the front desk.
The technical lead directs the investigation and recovery, whether that is an internal IT person, an outside partner or both. Responsibilities include:
Containing the problem, such as isolating affected devices or accounts.
Preserving evidence and logs before anything is wiped or rebuilt.
Reporting facts and honest estimates to the incident lead, including what is unknown.
Restoring systems in an order set by the incident lead.
The technical lead should report facts. The incident lead should decide what to do about them.
Depending on your size, name additional contacts.
Privacy or compliance officer. Evaluates whether a breach of protected health information occurred and what the HIPAA Breach Notification Rule requires, working with legal counsel.
Clinical lead, such as the DON. Ensures resident care continues safely during downtime.
Scribe. Records decisions and times. A written timeline is valuable for insurance, regulators and later review.
Legal counsel. Advises on privilege, notification duties and contracts.
Incidents do not wait for convenient schedules. For each role, name a deputy. Include after-hours contact details, and keep a printed copy in a secure location. If email and systems are down, an electronic-only plan is useless.
Write down, in plain language, who may do what without asking. For example:
The technical lead may isolate a device or disable an account immediately.
Shutting down a system that residents' care depends on requires the incident lead's approval, unless there is an active threat spreading rapidly.
Only the communications lead sends messages outside the organization.
Any payment, including a ransom demand, is decided by the incident lead with counsel and insurer input, and never by IT alone.
Any determination that protected health information was breached is made with the compliance officer and counsel.
The document should fit on one page: roles, names, phone numbers, backups and the decision rules above. Add the insurer's hotline, your IT partner's emergency number and legal counsel's number.
A plan nobody has rehearsed will not hold up. Once or twice a year, run a short tabletop exercise: describe a scenario, such as an email account takeover or a locked-up file server, and walk through who does what. Note the gaps, update the page and run it again. Thirty to sixty minutes is enough to find most weaknesses.
UnityCare IT helps healthcare and senior-living operators write practical incident response plans, assign roles and run tabletop exercises. We prefer to help you work out these decisions now, in a quiet room, rather than during an outage.
An outsourced IT department with proactive maintenance and one number to call.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172