It is a Tuesday afternoon. The administrator's phone rings, and it is a representative from a company that provides software or services to your organization. They are calling to say they have discovered unauthorized access to their systems, and they believe some of your data may be involved. They cannot yet say how much. What happens next?
This tabletop exercise lets your leadership team practice that moment in about an hour, with no technology required. The goal is not to find the right answer, but to find the gaps in your plan while the stakes are low.
Invite the administrator or executive director, the director of nursing or clinical lead, the business office manager, the person who manages IT (internal or from your managed provider), the compliance or privacy officer, and someone from human resources. In a multi-site organization, include a corporate representative.
Appoint a facilitator who reads the scenario aloud and keeps time. Appoint a note-taker who records decisions and open questions. Remind everyone that this is a safe place to say "we don't know," because those answers become your action items. Have your incident response plan, vendor contact list and business associate agreements on hand.
Your organization uses a third-party vendor for a function that matters, such as billing, scheduling, document storage or a clinical application. The vendor holds resident and employee information. The facilitator reads each stage aloud and gives the group time to discuss.
A vendor contact tells you that they detected suspicious activity several days ago, that an investigation is underway, and that your data may have been accessed. They say a written notice will follow.
Discussion questions:
Who takes the call, and who needs to be told immediately?
What do we ask the vendor right now? Consider what data, what time period, whether it is contained and when we will receive updates.
How do we document the call?
Do we know where our business associate agreement is, and what it says about notification?
Should we contact our cyber insurance carrier or legal counsel now?
The next day the vendor says that names, dates of birth, insurance information and some clinical details for current and former residents may have been accessed. They say they do not yet know whether the data was copied. They advise you to change any shared passwords.
Discussion questions:
Which of our accounts connect to this vendor? Who can reset them, and how fast?
What does our process say about determining whether this is a reportable breach under HIPAA? Who makes that decision?
Which residents and former residents might be affected, and can we produce a list?
How do we keep working if the vendor's service is offline?
What do we tell staff, and what do we say if residents or families ask?
A local reporter calls asking whether your organization has been affected by the vendor's incident. A family member also emails asking about their mother's information. The vendor's updates are slow and contradictory.
Discussion questions:
Who speaks to the media, and what do we say?
How do we respond to families with accurate information and without speculation?
What do we do if the vendor's timeline for notifying us conflicts with our own obligations?
Who is tracking the legal deadlines for notifying individuals and regulators?
What records should we be keeping?
Two weeks later, the vendor confirms the incident is contained. Leadership must decide whether to continue the relationship.
Discussion questions:
What would we want from the vendor before continuing, such as an investigation report, security improvements or contract changes?
Do we have an alternative provider or a fallback process?
What did we learn about our own dependencies?
Spend the last ten minutes reviewing the notes. For each gap, assign an owner and a due date. Typical findings include outdated contact lists, no clear authority to make decisions, unclear communication responsibilities, and no list of which systems share credentials with vendors.
Update your incident response plan and vendor inventory within thirty days. Schedule the next tabletop within a year, using a different scenario.
UnityCare IT can facilitate tabletop exercises for healthcare and senior-living teams, adapt the scenario to your actual vendors and systems, and help turn the findings into updated plans. Contact us if you would like a facilitator for your next session.
Security monitoring, HIPAA safeguards, backups and staff training for healthcare and small businesses.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172