When something goes wrong with technology, people rarely reach for a thick binder. They look for a phone number and a clear instruction. Long incident response plans have their place as references, but the plan that actually helps at 3 a.m. is short, visible and written in plain language.
Here is how to build a one-page plan for a care facility, and what to put behind it.
In a stressful moment, people forget details and freeze. A single page reduces the number of decisions. It answers three questions: what do I do right now, who do I call, and who is in charge.
List examples in plain terms so staff recognize them:
Computers showing a ransom message or files that will not open
A lost or stolen laptop, phone or tablet
A message sent to the wrong person containing resident information
Someone entering a password on a suspicious website
Unexpected account activity or sign-in alerts
The EHR, phones or network unavailable without explanation
Add a simple instruction: if you are not sure, report it anyway.
Keep these few and easy.
Stay calm and stop using the affected device
If it shows a ransom message or acts strangely, disconnect it from the network by unplugging the cable or turning off Wi-Fi, but do not turn it off unless instructed
Do not delete anything or try to fix it yourself
Call the incident number below
Switch to downtime procedures if the system is unavailable
Print this list in large type, with every number verified.
Primary contact: helpdesk or IT provider emergency line
Facility decision-maker: administrator and the backup if they are unavailable
Cyber insurance hotline with policy number
Law enforcement contact information, such as the local FBI field office, for criminal incidents
Store a copy offline and at the nurse station, since a network incident can make digital copies unreachable.
Assign four basic roles, with named backups:
Incident lead: makes decisions and coordinates, typically the administrator or designee
Technical lead: directs containment and recovery, usually the IT provider
Communications lead: handles messages to staff, families and the media, and ensures only one voice speaks externally
Documentation lead: keeps a log of times, decisions and actions
Decide in advance who may authorize actions such as taking systems offline, notifying insurers or engaging outside experts. Predefining authority speeds action when leaders are unavailable.
The one-pager points to supporting material you maintain separately.
A network and systems inventory
Downtime procedures and paper forms
Backup and recovery procedures
HIPAA breach assessment template using the four-factor test
State breach notification requirements
Communication templates for staff and families
A contact list for vendors and regulators
A tabletop exercise takes an hour. Gather leadership, nursing, IT and administrative staff, and walk through a scenario such as ransomware on a weekend night. Ask who would call whom, what systems would be affected and how care would continue. Record what was confusing and revise the plan. Include night shift representatives, because they will be the first responders in a real event.
Check phone numbers every quarter, since outdated contacts are the most common failure. Review the plan after any real incident, personnel changes or system changes.
The Security Rule requires security incident procedures, including identifying and responding to suspected incidents, mitigating harm and documenting outcomes. A practiced one-page plan with a log goes a long way toward meeting that requirement.
UnityCare IT can help you draft the one-page plan, build the supporting documents and facilitate your first tabletop exercise.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172