Most organizations discover the gaps in their incident response plan during an actual incident, which is the worst possible time. A tabletop exercise is a low-cost way to find those gaps in advance. Leaders gather around a table, walk through a realistic scenario and talk through who would do what. No systems are touched, and nobody is graded.
For a nursing home or senior living operator, a 90-minute session once or twice a year can reveal missing phone numbers, unclear authority and overlooked dependencies, while the stakes are still low.
Administrator or executive director
Director of nursing or clinical lead
Business office or finance lead
Compliance or privacy officer
IT lead or your IT provider
Human resources
Someone responsible for communications, if different
Corporate or regional leaders, for multi-site operators
Assign a facilitator, ideally someone not directly responsible for the plan, and a note-taker.
Explain that the goal is learning, not blame. Review the current incident response plan briefly and confirm that everyone has a copy.
Present the scenario in stages, called injects. After each, pause and ask what the team would do.
List what went well, what was unclear and what was missing.
Capture specific improvements, owners and dates.
This is a hypothetical scenario you can adapt.
Inject 1, Saturday 5:40 a.m. The night nurse reports that several computers display a message saying files are encrypted, and the EHR will not open.
Questions: Who does she call first? Is the number posted? What is her authority to switch to downtime procedures? Who notifies the administrator?
Inject 2, 7:00 a.m. IT confirms the file server and several workstations are affected. Backups may also be impacted. The attacker's note demands payment and claims data was copied.
Questions: Who is the incident lead? Do we contact our cyber insurer, and what does the policy require? Who contacts legal counsel? Do we disconnect more systems? Who decides?
Inject 3, 10:00 a.m. Day shift is struggling with paper medication records. A family member calls asking why they cannot reach a loved one through the usual phone system, which is also down.
Questions: What do we tell families? Who speaks for the organization? How do we handle physician orders and pharmacy communication?
Inject 4, Monday. A local reporter calls, having seen a post by the attacker. Staff paychecks are due on Friday.
Questions: What is our public statement? Is payroll affected? What are our obligations under HIPAA and state law if resident data was taken? What law enforcement contacts are appropriate?
Do we know where the plan and contact list are if the network is down?
Who has authority to make major decisions, such as shutting down systems?
Which systems must be restored first, and who agreed to that order?
How would we run for several days without electronic records?
Who handles regulators, residents, families and staff communications?
Which vendors do we call, and do we have their emergency numbers?
Write a short summary of findings, with a list of corrective actions. Typical results include updating contact lists, adding after-hours numbers, clarifying decision authority, creating pre-approved communication templates and scheduling a downtime drill. Follow up in 30 and 90 days to confirm completion, and keep the documentation as evidence of preparedness.
Try other scenarios in later sessions, such as a lost laptop, a vendor breach, a business email compromise that redirects a payment, a prolonged internet outage or an insider snooping on records.
UnityCare IT can help design and facilitate tabletop exercises tailored to your facility, and can help update your plan based on what the team learns. If you have never run one, it is an approachable first step.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172