Run a One-Hour Cyber Incident Tabletop Exercise

Most care organizations have never rehearsed a cyber incident. They have fire drills and severe weather drills, but when ransomware hits, leaders are figuring out who to call while staff are asking whether they can still give medications. A tabletop exercise changes that. It is a discussion-based drill, with no technology touched and no one's job on the line, where the team walks through a realistic scenario and finds gaps in its plan.

You can run a useful one in about an hour. Here is how.

Why tabletop exercises work

They reveal confusion about roles, missing phone numbers, unclear decision authority and untested assumptions, all in a low-stakes setting. They also support HIPAA's expectation that contingency and incident response procedures are tested and revised, and align with the testing element of CMS emergency preparedness requirements.

Who should attend

Keep the group small but cross-functional:

Administrator or executive director.

Director of nursing or clinical lead.

Privacy or compliance officer.

IT lead or managed service provider representative.

Business office manager.

Human resources or communications lead.

Assign one person as facilitator and another as note-taker.

The one-hour agenda

5 minutes: Explain the ground rules and objectives. This is about learning, not blame.

10 minutes: Present the scenario and first prompts.

30 minutes: Walk through three or four stages of the scenario with discussion.

10 minutes: Debrief and list gaps.

5 minutes: Assign action items with owners and dates.

A sample scenario

It is a Friday afternoon. Several nurses report that they cannot open resident records. A message on a shared computer says files have been encrypted and demands payment. The phone system is also acting strangely.

Stage one: Discovery

Discussion prompts:

Who needs to be notified first, and how?

Who decides to disconnect systems from the network?

What do nurses do right now to continue medication administration?

Do we have a printed list of key phone numbers?

Stage two: Containment and operations

It becomes clear that the file server and the EHR connection are affected, and backups are in question.

Who confirms the status of backups, and how fast can they tell us?

Where are downtime forms kept, and who distributes them?

How do we communicate with staff on other shifts?

Do we call our insurance carrier, and who has the policy details?

Stage three: Outside pressure

A local reporter calls, and a family member posts on social media that the facility is not answering phones.

Who speaks for the organization?

What do we tell families, and through what channel?

Do we need to notify regulators, law enforcement or CISA?

Has anyone consulted legal counsel?

Stage four: Recovery and compliance

Two days later, forensic review suggests that some resident data may have been accessed.

How do we determine whether this is a reportable HIPAA breach?

What is our deadline to notify affected individuals?

Who documents the timeline?

How do we restore systems safely, and in what order?

Facilitation tips

Ask open questions: what would we do, who would do it, how would we know?

Do not let technical staff answer every question. The goal is for leaders to make decisions.

Capture disagreements and unknowns as action items.

Keep to time, and avoid solving every problem in the room.

Debrief questions

What went well?

Where were we confused about roles or authority?

What information did we wish we had?

Which phone numbers or documents were missing?

What would have made recovery faster?

Turn findings into action

Write a short list, no more than five to ten items, with owners and due dates. Typical results include updating the contact list, printing downtime forms, testing a backup restore, clarifying who can authorize system shutdowns and drafting notification templates. Follow up in thirty and ninety days.

Repeat it

Run an exercise at least annually, and vary the scenario: a lost laptop, a compromised email account, a vendor outage or a misdirected fax.

How UnityCare IT can help

UnityCare IT can facilitate tabletop exercises for healthcare and senior-living organizations and help translate the findings into an updated incident response plan. If you would like to schedule one, we are glad to talk it through.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034