The One-Page Incident Response Plan Every Facility Needs

Most organizations know they should have an incident response plan. Fewer have one that staff can actually use when something goes wrong. A thirty-page document written to satisfy a checklist tends to sit on a shelf. When a real event begins, such as a suspicious email that was opened, a lost laptop or ransomware on a server, people need a short, clear guide that tells them who to call and what to do first.

You can build that guide on a single page. It does not replace a fuller plan, but it makes sure the most important steps happen quickly.

Section 1: What counts as an incident

Start with a plain definition and a few examples, so staff know when to use the page.

Suspected malware, ransomware or an unexpected pop-up message

A clicked link or entered password on a suspicious site

A lost or stolen laptop, phone or storage device

Resident or employee information sent to the wrong recipient

An unauthorized person in a restricted area or using a workstation

A vendor or partner reporting a breach

Unusual system behavior, such as files that will not open or accounts locked out

Tell staff that when in doubt, report. A false alarm costs minutes. A late report can cost much more.

Section 2: Who to call, in order

List names and phone numbers, including after-hours numbers, for:

The incident lead, usually the administrator or a designee, and a backup

Your IT provider's emergency line

The privacy and security officer

The director of nursing, for care continuity decisions

Your cyber insurance hotline, if you have a policy

Legal counsel

Your EHR vendor's support line

Print it. Do not rely on a contact list that lives in the system that might be down.

Section 3: First actions for any employee

A short list that anyone can follow:

Stop what you are doing with the affected device or account

Do not turn the computer off unless told to, but disconnect it from the network if you can do so safely

Do not delete anything, and do not try to fix it yourself

Write down what you saw, the time and what you clicked or typed

Call the number above, rather than only sending an email

Tell your supervisor

Section 4: First actions for the response team

The incident lead and technical lead should work through these steps.

Confirm what is happening and which systems and accounts are involved

Contain it by isolating devices, disabling compromised accounts and blocking malicious connections

Preserve evidence, including logs, affected machines and ransom notes

Start a written log of times, actions and decisions

Decide whether to activate downtime procedures for clinical operations

Notify the insurer and counsel as required by the policy and your attorney's advice

Reset passwords and review access for affected accounts

Section 5: Decision rules

Write a few simple rules so that people are not improvising under stress.

If resident safety is at risk, the director of nursing takes charge of care decisions, and IT supports

If there is any chance protected health information was exposed, the privacy officer begins a HIPAA breach risk assessment immediately and the notification clock is tracked

No one speaks to media, families or outside parties about the incident except the designated communications contact

No ransom discussions or payments without leadership, counsel and the insurer

Do not restore systems from backup until the cause is understood and the attacker is contained

Section 6: After the incident

Schedule a review within a couple of weeks. Document what happened, what worked, what did not and what will change. Update the plan, share lessons with staff, and add any needed training. Keep records, since they support HIPAA documentation and insurance claims.

Make it real

A plan is only useful if people know it exists. Post the one-page version in the supervisor's office and at nurse stations. Review contacts every quarter and whenever personnel change. Run a tabletop exercise at least once a year, where the team talks through a realistic scenario using the page. You will quickly see what is missing, such as a phone number nobody has or a decision that no one is authorized to make.

For reference, NIST's Cybersecurity Framework 2.0, published in February 2024, treats responding and recovering as core functions, and CISA publishes incident response guidance that is free to use.

UnityCare IT helps healthcare organizations draft, test and maintain incident response plans, and can facilitate a tabletop exercise for your leadership team.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172