Privacy & Cybersecurity Incident Response Runbook
A clear, role-based, checklist-driven runbook that teams can copy, tailor, and rehearse to detect, contain, preserve evidence for, communicate about, and recover from privacy breaches and cybersecurity incidents that affect clinical systems.
Purpose and scope
This runbook gives clinical teams, IT/security, privacy, and leadership a practical, role-based sequence of actions to respond to suspected privacy breaches and cybersecurity incidents affecting clinical systems. Use this as a starting point—copy and adapt to your local systems, contracts, legal requirements, and clinical workflows. Consult legal counsel and your security vendor as required.
Core principles
- Protect patient safety and continuity of care first.
- Contain the technical spread while preserving evidence for clinical continuity and regulatory review.
- Communicate clearly, consistently, and through designated channels.
- Document every step, time-stamp actions, and maintain chain-of-custody for evidence.
- Exercise and update the runbook regularly.
Roles and responsibilities (default roster)
- Incident Commander (IC) — overall decision authority for the response, coordinates cross-functional actions, escalates to executive leadership.
- Clinical Lead — assesses and mitigates patient-safety impacts, manages temporary clinical workarounds.
- IT/Security Lead — triages technical containment, collects forensic artifacts, coordinates with external forensics/SIEM.
- Privacy Officer — evaluates PHI exposure, advises on notification obligations and documentation.
- Communications Lead — prepares internal staff messages and external communications (patients, partners, regulators) per legal guidance.
- Legal Counsel — advises on regulatory timelines, reporting, and legal risk management.
- Facilities / Biomed — assists with affected medical devices or physical isolation needs.
Incident severity triage (quick classification)
- Low — isolated, no PHI exposure, no clinical impact.
- Medium — limited PHI exposure or degraded non-critical clinical systems.
- High — confirmed PHI exposure affecting many records, or core clinical systems impacted.
- Critical — patient safety affected, major system outage, or confirmed data exfiltration with regulatory risk.
Immediate checklist — first 60 minutes
- Confirm and declare an incident. IC activates the runbook and notifies members of the roster.
- Protect patient care: clinical lead confirms alternative workflows (paper orders, manual monitoring) if systems are unavailable.
- Isolate affected systems from the network where possible (segmentation, VLAN isolation). Do not power-cycle devices unless directed by forensics — capture volatile data first when indicated.
- Start documentation log: record time, reported by, symptoms, systems affected, immediate actions, and names of responders.
- Preserve evidence: follow the Evidence Preservation Checklist below.
- Engage legal and privacy for preliminary assessment of regulatory obligations and notification triggers.
Evidence preservation checklist
Keep an evidence pack for each affected system or device. Maintain chain-of-custody records.
- Collect and save system and application logs (secure copy, hash if possible).
- Capture network traffic or relevant packet captures from the time window if SIEM or NAC is available.
- Take system images or snapshots where forensics team advises.
- Capture memory (RAM) only under forensic guidance; document who performed the capture and how.
- Export and preserve audit trails from EHR/clinical systems and access logs.
- Preserve user accounts, service accounts, and privileged activity logs.
- Record physical evidence (photos, device serials, location) for any medical device or endpoint taken offline.
- Store evidence in secure, access-controlled location. Record transfer events in chain-of-custody log.
Technical containment & remediation (IT/Security Lead)
- Identify scope: list affected hosts, accounts, services, and clinical modules.
- Block malicious IPs, domains, and quarantine compromised endpoints in the EDR/NAC console.
- Reset or disable compromised credentials and implement temporary multi-factor enforcement for affected accounts.
- Apply known good configurations or recovery images when available and validated by forensics.
- Coordinate with vendors for urgent patches, hotfixes, or device-level mitigations (e.g., medical device vendor advisories).
- Validate restoration in a controlled test environment before returning systems to production for clinical use.
Communications — short scripts and templates
Prefer simple, transparent language. Tailor wording with Legal/Privacy approval before external distribution.
Internal staff notification (example)
Subject: [Urgent] System Incident — Immediate Actions Required
We are responding to an IT/security incident affecting [system name]. Clinical teams: follow guidance from your clinical lead for temporary workflows. Do not attempt to access or troubleshoot affected systems unless instructed. If you observe patient-safety issues, escalate immediately to [Role/Contact]. Further updates will be provided at [time cadence].
Patient-facing message (example)
We are investigating a technical incident that may have impacted some patient information. We are taking steps to secure our systems and protect patient care. If you are affected, we will contact you directly with recommended next steps. For questions, call [help desk number].
Notification and regulatory considerations
Follow jurisdictional reporting requirements and consult your privacy officer and legal counsel for timing, content, and required recipients (patients, regulators, payors, partners). Keep a running log of decisions and approvals for reporting and audit purposes.
Post-incident review and remediation plan
Within the agreed review window (example: within 7–30 days depending on severity), convene a review to produce a written remediation plan.
Post-incident report template
- Summary: timeline of discovery to containment.
- Scope and impact: services, patient records, clinical effects.
- Root cause analysis: direct causes and contributing factors.
- Corrective actions taken and verification evidence.
- Remediation plan: actions, owners, due dates, verification criteria.
- Lessons learned and recommended updates to policies, training, or technical controls.
- Follow-up audit schedule and metrics to track progress.
Exercises and rehearsal guide
- Schedule regular tabletop exercises with cross-functional participants at least annually, and technical drills (declared incident recovery) more frequently for high-risk systems.
- Design scenarios that include clinical impacts (e.g., EHR outage during a shift change) to test patient-safety decisions under pressure.
- Use the runbook during exercises; capture timing, decision points, communication clarity, and gaps.
- Update the runbook after each exercise and assign owners to remediation actions.
Quick reference checklists (printable)
Initial 10-point checklist (one-page)
- Declare incident and notify roster
- Protect patient care (Clinical Lead confirmation)
- Isolate affected systems
- Start documentation log
- Preserve evidence
- Block malicious access and quarantine endpoints
- Engage Legal/Privacy
- Prepare internal staff notice
- Plan temporary clinical workflows
- Schedule post-incident review
Where to store and how to maintain this runbook
Keep a copy versioned in your secure knowledge base, make a printable one-page quick checklist available in work areas, and ensure the roster/contact list is maintained and tested quarterly. After any incident or exercise, update the runbook and record the change log.
Notes and cautions
- Do not give forensic tools or evidence to unauthorized personnel.
- Avoid promises to patients about outcomes or compensation without legal counsel.
- This runbook is a practical guide. Legal, regulatory, clinical, or vendor-specific advice should be sought where required.
Discussion
Comments and conversation will live here.