Media and Family Questions During a Cyber Incident

When a cyber incident hits a nursing home or assisted living community, the phones start ringing quickly. Families want to know whether their loved one is safe and whether their information was stolen. Staff are asking whether they will be paid. A local reporter may call before your leadership team has finished its first meeting. If nobody has decided who speaks and what they say, people fill the silence with rumors.

The fix is simple and cheap: decide your approach now, write it down, and keep it with your incident response plan.

Start with roles

Communication goes wrong most often when too many people talk, or when nobody does. Name these roles in advance, with a backup for each.

Incident lead: coordinates the response and decides when facts are confirmed enough to share.

Spokesperson: the only person who speaks to the media. Usually the administrator or an executive.

Family liaison: handles resident and family communication, often the administrator, social services director or a designated nurse leader.

Staff communicator: updates employees through approved channels.

Legal and compliance contact: reviews statements, especially anything touching breach notification under HIPAA.

Everyone else gets a short rule: refer all outside inquiries to the spokesperson. Put that rule on a card at the front desk and in the nurses' station.

Write holding statements in advance

A holding statement is a short, honest message you can issue within the first hours, before you know everything. It should say what you know, what you are doing, and when people will hear more. It should not guess.

A basic template might read:

"We recently identified a technology issue affecting some of our systems. We have taken steps to protect our residents and information, and we are working with outside specialists to investigate. Resident care continues without interruption. We will share more information as it becomes available."

Only claim what is true. If care is disrupted, say so plainly, and do not promise that no information was affected until investigators confirm it. Statements that later turn out wrong damage trust far more than an honest "we do not know yet."

What to avoid

Speculating about who attacked you or why.

Blaming a vendor or an employee.

Giving technical details that could help attackers.

Promising timelines you cannot control.

Using the word "secure" or "safe" for systems you have not verified.

Preparing for family questions

Families care most about three things: is my loved one being cared for, is my family's information safe, and what should I do? Prepare a short question-and-answer sheet for staff who answer calls. Include:

Whether care and medications continue as normal, and how.

Whether you know yet if resident information was involved.

How and when families will be notified if it was.

A phone number or email for questions.

Reminders to watch for suspicious calls or emails that reference the incident, since scammers often exploit news of a breach.

If personal information is confirmed to be affected, HIPAA's Breach Notification Rule sets requirements and deadlines for notifying individuals, HHS and sometimes the media. Your attorney should guide the timing and wording of formal notices. A casual remark by a staff member can become a legal problem, which is another reason to keep the speaking list short.

Media inquiries

Reporters are doing their job, and treating them courteously helps. Train your front desk to take the reporter's name, outlet and deadline, then pass it to the spokesperson. The spokesperson can respond with the holding statement, offer to follow up, and avoid off-the-record comments. Keep a log of every inquiry and response.

Staff communication

Employees are often the first people families ask. Give staff a brief script, remind them not to post on social media, and update them regularly, even when the update is "no change." If systems are down, tell them what workarounds to use, such as downtime paper forms.

Practice before you need it

Add a communication scenario to your next tabletop exercise. Read a mock reporter's call out loud, and see whether the front desk knows what to do. Update contact lists twice a year, and store the plan somewhere you can reach when email and shared drives are unavailable.

UnityCare IT helps senior-living and healthcare providers build incident response plans, including communication roles and templates, and run tabletop exercises with leadership teams. If your plan has a gap here, we can help you fill it before an incident does.

Related service

Security monitoring, HIPAA safeguards, backups and staff training for healthcare and small businesses.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172