Skip to main content
🏥 Healthcare Ransomware Playbook · Free PDF

Run Your Own Healthcare Ransomware Tabletop — Without Waiting for a Real Incident

Built from the post-mortems of three attacks that cost lives, billions of dollars, and weeks of clinical downtime. Six scenarios, an out-of-band facilitation script, and a HIPAA / NIST CSF 2.0 crosswalk your auditor can use.

Send Me the Playbook — Free →

Built from 12+ real healthcare incident post-mortems — including HHS HC3 advisories, UnitedHealth SEC filings, and NHS England after-action reports. Used by clinical informatics, IT, and compliance teams across hospital systems, group practices, and health-tech vendors.

Why generic ransomware playbooks miss healthcare

Patient safety — not just data — is the leverage attackers use against you

The Change Healthcare attack shut down prescription processing nationwide. Ascension moved to paper records for 30+ days. NHS/Synnovis confirmed the first patient death linked to ransomware. The disruption is the leverage. Your tabletop has to address clinical continuity, not just data recovery.

Threat 1

Vulnerable remote access points

Change Healthcare's Citrix portal had no MFA when it was breached. UnitedHealth CEO testified to Congress. The same misconfiguration is in hospital systems and group practices today.

Threat 2

Vendor / pathology / lab dependencies

NHS/Synnovis proved that one pathology vendor going offline can stop blood testing nationally and cancel 800+ surgeries. Vendor access and failover must be in the tabletop.

Threat 3

EHR continuity vs. data recovery

Ransomware encryption of EHR systems triggers immediate patient-safety incidents. The 60-day HIPAA notification clock starts on discovery — not on confirmation. Tabletop must rehearse both timelines.

What's inside (6 scenarios)

What this playbook covers

Each scenario is built from a real post-mortem and includes a timeline, decision points, escalation triggers, and a moderator script. Run the scenarios in 30, 60, or 90 minutes.

Scenario 1 · 9 days
ALPHV/BlackCat Remote-Access Intrusion
(Change Healthcare pattern)
A single Citrix-class remote portal without MFA. Decision point: do you have an inventory of every remote access point, and have you changed the test that proves MFA is on? Worst case: $22M ransom, 190M records, $2.457B total cost.
Scenario 2 · 30+ days EHR down
Health System Ransomware — EHR Offline
(Ascension pattern)
An affiliate-domain ransomware attack knocks EHR, scheduling, and patient portal offline at a multi-hospital system. Decision point: manual clinical workarounds, patient communication script, and the moment you tell the board.
Scenario 3 · Patient death
Pathology Vendor Held Hostage
(NHS/Synnovis pattern)
A pathology or lab vendor is hit by ransomware. Blood testing drops from 10,000/day to 400/day. Surgery backlog starts at hour 6. Decision point: failover or paid expedite? Do you have a clinical-continuity runbook?
Scenario 4 · Insider pivot
Help Desk Reset Attack
A clinical informatics help-desk call walks through MFA reset verification using public LinkedIn data (name, employee ID, department). Domain admin reached in 11 minutes (MGM pattern, adapted to hospital operations).
Scenario 5 · Codecov-style
Third-Party Diagnostic Vendor Breach
A diagnostic imaging vendor or PACS provider reports a breach. Decision point: is the vendor in your BAA inventory? Is PHI provably exposed? Are there contract terms that limit their liability, and what is your notification obligation?
Scenario 6 · Containment call
Day 1 Detection — Isolate or Continue?
EDR fires on a workstation at 2:14 AM. Lateral movement signs detected at 2:48 AM. Decision point: do you isolate the segment (preserve forensics, save EHR) or shut down the machine (lose evidence, slower recovery)? Walk through the actual decision tree under time pressure.

How to run it

Three run formats, scripted for out-of-band facilitation

Every scenario comes with a moderator script, role roster, scribe template, and a comms matrix for clinical leadership. No prep required from your clinical teams — you can run it on a Tuesday afternoon.

30 minutes

Tactical Drill

IR team + IT lead + on-call security. One scenario, one decision. Good for quarterly refreshes and team retention.

60 minutes

Operational Tabletop

Add clinical leadership and compliance. Two scenarios, scribe captures decisions, comms template triggers one patient-safety communication.

90 minutes

Executive Tabletop

Full leadership: CMO, CIO, CISO, compliance, board observer. Three scenarios, board-call script drilled, regulatory clock walked through with CFO.

After the tabletop

NIST CSF 2.0 action items the auditor can trace back

Every tabletop closes with a written after-action and an action list mapped to the NIST Cybersecurity Framework 2.0 functions. You hand the same list to the auditor as the record of your contingency planning and risk management exercises.

GV.OC · Govern

Organizational Context

Risk decisions documented in tabletop minutes. Board-level understanding of clinical-safety exposure to ransomware.

PR.IP · Protect

Protective Processes

Configuration management of remote access, MFA, and EHR backup tested — not assumed. Vendor access controls revised where flagged.

RS.MI · Respond

Incident Management

Containment decision tree practiced, communications matrix tested, regulator notification clock walked through with compliance.

Get the Free Healthcare Ransomware Tabletop Playbook

PDF. Download instantly. Built for hospital systems, group practices, and health-tech vendors.

We'll email you the PDF instantly. No spam. Unsubscribe anytime.

✓ Check Your Inbox

The Healthcare Ransomware Tabletop Playbook is on its way. If you don't see it in 2 minutes, check your spam folder.

Download directly →

Frequently Asked Questions

Who is this playbook for?

Hospital systems, medical groups, group practices, health-tech vendors, and any organization where IT security shares an incident response with clinical stakeholders. The script is written so a clinical informatics lead or IT director can facilitate — no prior tabletop experience required.

What ransomware attacks does it cover?

Six attack scenarios built directly from the Change Healthcare ($22M ransom, 190M records, 9-day dwell — ALPHV/BlackCat, Feb 2024), Ascension (140 hospitals, EHR offline 30+ days, May 2024), and NHS/Synnovis (Qilin ransomware, 10,152 appointments canceled, 1 confirmed patient death in June 2025) post-mortems. Plus three additional scenarios: help desk reset, third-party vendor breach, and the day-1 isolation decision.

How do I use it with my leadership team?

The playbook includes a moderator script, role roster (CISO, CIO, CMO, compliance, on-call security), a designated scribe template, time-boxes for each decision, and a comms matrix for clinical leadership. Pick the 30-min, 60-min, or 90-min run format and assign roles in advance. After-action template maps directly to NIST CSF 2.0 GV.OC, PR.IP, and RS.MI for your audit record.

Want a live facilitator for your first run?

A SecurEveryone Executive Session puts one of our healthcare-specialized facilitators in the room — live, over Zoom, scoped to your hospital system or group practice. We use your own EHR, vendor list, and incident response structure in the scenarios.

Book a 90-min Healthcare Ransomware Tabletop →

Your team is one phishing email away from a breach.

A single 60-minute training session can change that. Book today — sessions from $150.

Book a Session →

Personal · Executive · Business tiers · Satisfaction guaranteed