Built from the post-mortems of three attacks that cost lives, billions of dollars, and weeks of clinical downtime. Six scenarios, an out-of-band facilitation script, and a HIPAA / NIST CSF 2.0 crosswalk your auditor can use.
Why generic ransomware playbooks miss healthcare
The Change Healthcare attack shut down prescription processing nationwide. Ascension moved to paper records for 30+ days. NHS/Synnovis confirmed the first patient death linked to ransomware. The disruption is the leverage. Your tabletop has to address clinical continuity, not just data recovery.
Change Healthcare's Citrix portal had no MFA when it was breached. UnitedHealth CEO testified to Congress. The same misconfiguration is in hospital systems and group practices today.
NHS/Synnovis proved that one pathology vendor going offline can stop blood testing nationally and cancel 800+ surgeries. Vendor access and failover must be in the tabletop.
Ransomware encryption of EHR systems triggers immediate patient-safety incidents. The 60-day HIPAA notification clock starts on discovery — not on confirmation. Tabletop must rehearse both timelines.
What's inside (6 scenarios)
Each scenario is built from a real post-mortem and includes a timeline, decision points, escalation triggers, and a moderator script. Run the scenarios in 30, 60, or 90 minutes.
How to run it
Every scenario comes with a moderator script, role roster, scribe template, and a comms matrix for clinical leadership. No prep required from your clinical teams — you can run it on a Tuesday afternoon.
IR team + IT lead + on-call security. One scenario, one decision. Good for quarterly refreshes and team retention.
Add clinical leadership and compliance. Two scenarios, scribe captures decisions, comms template triggers one patient-safety communication.
Full leadership: CMO, CIO, CISO, compliance, board observer. Three scenarios, board-call script drilled, regulatory clock walked through with CFO.
After the tabletop
Every tabletop closes with a written after-action and an action list mapped to the NIST Cybersecurity Framework 2.0 functions. You hand the same list to the auditor as the record of your contingency planning and risk management exercises.
Risk decisions documented in tabletop minutes. Board-level understanding of clinical-safety exposure to ransomware.
Configuration management of remote access, MFA, and EHR backup tested — not assumed. Vendor access controls revised where flagged.
Containment decision tree practiced, communications matrix tested, regulator notification clock walked through with compliance.
PDF. Download instantly. Built for hospital systems, group practices, and health-tech vendors.
The Healthcare Ransomware Tabletop Playbook is on its way. If you don't see it in 2 minutes, check your spam folder.
Download directly →
Who is this playbook for?
Hospital systems, medical groups, group practices, health-tech vendors, and any organization where IT security shares an incident response with clinical stakeholders. The script is written so a clinical informatics lead or IT director can facilitate — no prior tabletop experience required.
What ransomware attacks does it cover?
Six attack scenarios built directly from the Change Healthcare ($22M ransom, 190M records, 9-day dwell — ALPHV/BlackCat, Feb 2024), Ascension (140 hospitals, EHR offline 30+ days, May 2024), and NHS/Synnovis (Qilin ransomware, 10,152 appointments canceled, 1 confirmed patient death in June 2025) post-mortems. Plus three additional scenarios: help desk reset, third-party vendor breach, and the day-1 isolation decision.
How do I use it with my leadership team?
The playbook includes a moderator script, role roster (CISO, CIO, CMO, compliance, on-call security), a designated scribe template, time-boxes for each decision, and a comms matrix for clinical leadership. Pick the 30-min, 60-min, or 90-min run format and assign roles in advance. After-action template maps directly to NIST CSF 2.0 GV.OC, PR.IP, and RS.MI for your audit record.
A SecurEveryone Executive Session puts one of our healthcare-specialized facilitators in the room — live, over Zoom, scoped to your hospital system or group practice. We use your own EHR, vendor list, and incident response structure in the scenarios.
Book a 90-min Healthcare Ransomware Tabletop →A single 60-minute training session can change that. Book today — sessions from $150.
Book a Session →Personal · Executive · Business tiers · Satisfaction guaranteed