Incident Severity Levels: A Simple Triage Scale

When a suspicious email, lost laptop or unusual system behavior is reported, the first minutes matter. Teams without a shared way to judge seriousness tend to do one of two things: treat everything as a crisis and burn people out, or treat everything as routine and miss the one that matters. A short severity scale solves this by tying each level to specific people who must be told and specific actions that should happen.

Below is a simple three-level model suitable for a small or mid-size healthcare organization. Adapt the wording to your own structure.

Why a scale helps

Faster decisions. Staff do not have to debate whether to wake the administrator.

Consistent communication. The right people hear about problems at the right time.

Better records. Each incident is classified the same way, which makes review and improvement easier.

Support for compliance. HIPAA requires covered entities to have security incident procedures, and a documented scale is a practical part of them.

The three levels

Level 1: Low

A problem with limited impact and no sign that protected information or critical operations are affected.

Examples: a blocked phishing email that no one clicked, a single failed login pattern against one account that was stopped by multifactor authentication, a lost device that was confirmed encrypted and locked.

Who is told: the IT contact or help desk. Record it in the incident log. Management sees a summary in the regular report.

Typical actions: investigate, close, document and note any lessons.

Level 2: Moderate

A confirmed or likely problem that affects a limited number of users, systems or records, or that could escalate if not handled promptly.

Examples: an employee entered a password on a fake sign-in page, malware on one workstation, an email sent to the wrong recipient with resident information, a department's system down for several hours.

Who is told: IT lead or provider, the administrator, and the privacy and security officer promptly. Department heads are informed if their area is affected.

Typical actions: contain the issue, such as resetting credentials or isolating a device, begin a more detailed investigation, preserve evidence and start assessing whether protected information was involved.

Level 3: High

A serious event with significant impact or likely exposure of protected health information, or one that disrupts patient care or the whole facility.

Examples: ransomware, a compromised email account with access to resident data, a server containing records taken offline, evidence that data was copied out.

Who is told: the administrator and executive leadership immediately, the privacy and security officer, your IT provider, legal counsel, and your cyber insurance carrier according to your policy. Depending on the facts, regulators, law enforcement and affected individuals may need to be notified.

Typical actions: activate the incident response plan, switch to downtime procedures for clinical operations, contain and preserve evidence, and begin the breach risk assessment under the HIPAA Breach Notification Rule.

How to decide the level

Ask a few questions in order:

Is resident care or safety affected right now?

Could protected health information have been accessed, disclosed or lost?

How many people, systems or records are involved?

Is the problem still happening, or is it contained?

If the answer to the first or second question is yes, start at level 2 or 3 until proven otherwise. It is easier to downgrade an incident than to explain why you underestimated it.

Keep the scale usable

Put it on one page with examples from your own environment.

Include after-hours phone numbers for each role.

Train staff to report quickly and without fear of blame. The earlier you hear about a problem, the lower the severity tends to stay.

Allow anyone to escalate if they are uncomfortable with the assigned level.

Review the scale after every real incident and at least annually.

Practice it

Run a short tabletop exercise with a few scenarios and ask the team to assign levels and say who would be called. You will quickly find gaps, such as missing phone numbers or unclear responsibility for notifying insurance.

Getting help

UnityCare IT works with healthcare organizations to create practical incident procedures and respond when something goes wrong. If you do not yet have a written scale, a one-page version like this is a strong first step, and we are glad to help you tailor it.

Related service

An outsourced IT department with proactive maintenance and one number to call.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172