Tabletop Exercises: Rehearse a Cyberattack Before It Happens

Most care organizations have a plan for fires, severe weather and infectious disease outbreaks, and they practice it. Fewer have rehearsed what they would do if every computer in the building suddenly displayed a ransom note. When an incident happens for the first time during a real crisis, even capable leaders can freeze, duplicate effort or make decisions without key information.

A tabletop exercise is a simple, discussion-based way to practice. No systems are touched and nobody is in danger. A facilitator presents a realistic scenario, and participants talk through what they would do. CMS emergency preparedness rules for long-term care facilities already expect testing and training, and a cyber scenario can fit naturally into that rhythm.

What a Tabletop Exercise Achieves

Reveals gaps in your incident response plan before a real event does

Clarifies who makes which decisions

Tests communication paths, including after hours

Builds familiarity between clinical, administrative and IT leaders

Shows whether downtime procedures are actually usable

Produces documentation useful for compliance reviews and cyber insurance applications

Who Should Participate

Include people who would be involved in a real incident:

Administrator or executive director

Director of nursing and clinical leaders

Business office manager

Human resources and compliance officer

Maintenance or facilities lead

IT representative and your managed service provider

Corporate or ownership representative, where applicable

Optionally, legal counsel or your insurance broker

Select a facilitator who is not in the middle of the scenario, which could be your IT partner or an outside professional.

Designing a Scenario

Make it realistic and relevant to your operations. Some examples:

Ransomware encrypts your file server and the EHR is unavailable on a Friday evening

A staff member reports clicking a link, and the email system begins sending suspicious messages

A vendor notifies you that their system was breached and your resident data may be involved

A lost laptop containing unencrypted resident information is reported missing

A business office employee wired payment to a fraudulent account after an email request

A prolonged internet and phone outage coincides with severe weather

Choose one scenario per session and keep it to about 60 to 90 minutes.

Structure of the Session

Break the scenario into phases, revealing new information as time passes:

Detection: what do staff notice, and who is told?

Initial response: who is in charge, what gets disconnected and when do you call IT, the insurer and counsel?

Care continuity: how will medications be administered and documented, and how do you handle admissions and discharges?

Communication: what do you tell staff, residents, families, physicians and regulators?

Investigation and recovery: what is restored first, and how do you confirm it is safe?

Legal and compliance: how do you evaluate whether this is a reportable breach under HIPAA and state law?

Prepare questions for each phase, and adding twists, such as the discovery that backups are also encrypted, keeps the discussion honest.

Ground Rules

Treat it as a learning exercise, not a test of individuals

Encourage honesty about what the team does not know

Have someone record decisions, questions and gaps

Refer to actual documents, such as your contact lists and procedures, during the exercise

After the Exercise

The value comes from follow-up. Within a week or two:

Summarize findings, strengths and gaps

Assign action items with owners and due dates

Update the incident response plan, contact lists and downtime procedures

Share key lessons with staff

Schedule the next exercise, with a different scenario

File the summary with your compliance records. It is evidence that you test your plans.

Common Gaps Exercises Reveal

Nobody knows who is authorized to make major decisions

Contact numbers are outdated or stored only on affected systems

Downtime forms are missing or unfamiliar

No one has contacted the cyber insurer in advance to understand the process

Communication to families has not been thought through

Practice Pays Off

A tabletop exercise is inexpensive compared with a poorly handled incident. UnityCare IT can design a scenario that fits your facility, facilitate the discussion and help you turn what you learn into an updated plan.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172