CRISISTABLETOP
Clinician using technology in a healthcare setting
← Exercise library

CISA.GOV CTEP · SECTOR RESILIENCE

CISA Healthcare & Public Health

A phishing campaign and vendor activity precede radiology delays, orphaned accounts, corrupted records, unsafe medical-device behavior, ransomware, direct patient extortion, legal claims, and loss of public confidence.

3 HRSuggested duration12Participant roles12Scenario stages
Stock photography via Unsplash

EXERCISE PURPOSE

Examine cyber resilience during a healthcare incident that disrupts network-connected medical devices, clinical data, and patient care.

Phishing-enabled compromise affecting medical devices, patient records, PHI, clinical operations, and safety

DECISION PRESSURE

Questions the team must answer together

The facilitator releases facts in stages. Participants should identify the decision owner, the authority being used, the information still needed, the immediate action, and the next escalation point.

01

Who has authority when cyber containment conflicts with immediate patient care?

02

Which clinical services can continue safely on downtime procedures?

03

How are suspect records or device outputs identified and communicated?

04

When is ransomware activity presumed to involve PHI?

05

What clinical, technical, and legal evidence is required before systems return to care?

INSIDE THE EXERCISE

A scenario that changes as the response develops

The template is already populated with public injects, facilitator-only context, discussion prompts, private role messages, and a final hotwash.

  1. Day 1
    Module 1

    Joint healthcare cyber alert

    CISA, the FBI, and HHS HC3 warn of increased attacks on healthcare organizations using phishing, ransomware, remote hacking, DDoS, and data exfiltration.

  2. Day 9
    Module 1

    MSP-themed phishing campaign

    Employees receive a message appearing to come from the MSP about a new HR system. The link requests portal credentials and returns a 404 page. Some employees also enable macros in an attached document.

  3. Day 10
    Module 1

    Patient-monitor updates installed

    Manufacturer updates for patient monitors are downloaded from the manufacturer’s website and installed without reported issues.

  4. Day 13
    Module 1

    Unannounced EMR vendor requests access

    A third-party EMR vendor arrives without notice and says it must patch a new vulnerability affecting workstations, imaging, radiology, bedside monitors, and other clinical devices.

  5. Day 15
    Module 1

    MRI workflow degrades

    Radiology reports that an MRI workstation locks up, patient data loads slowly, and retrieving images now takes extraordinary time. Appointments are more than two hours behind.

  6. Day 20
    Module 2

    Former IT accounts remain active

    A system administrator discovers and disables active accounts belonging to IT employees who left during the prior 12 months.

  7. Day 23 · Morning
    Module 2

    Patient records display incorrect data

    Nurses report incorrect medication, diagnosis, and personal information in patient records.

PARTICIPANTS

Bring the decision-makers who would own the real event

Assign people to functions, not titles alone. If one person owns several functions, keep the roles distinct during discussion so conflicts and handoffs remain visible.

Incident CommanderChief Information Security OfficerIT Operations LeadClinical Operations LeadBiomedical or OT Security LeadChief Medical or Patient Safety OfficerPrivacy or HIPAA OfficerGeneral CounselEmergency Management or Continuity LeadCommunications LeadVendor Management LeadHospital Administrator

REAL-WORLD INCIDENTS

Ground the exercise in events teams can recognize

Use these cases during planning or the prebrief. They are factual anchors, not scripts. Adapt the scenario to the organization’s technology, industry, geography, contracts, regulators, and risk profile.

LEGAL, REGULATORY & STANDARDS LENS

Authorities worth testing against the scenario

Applicability depends on the organization and facts. Use counsel and subject-matter owners to tailor deadlines, thresholds, privileges, preservation, reporting, and communications.

PRACTITIONER PERSPECTIVES

Law-firm and security-professional guidance

External perspectives help the design team challenge internal assumptions. They do not replace organization-specific legal or technical advice.

EXPECTED OUTPUT

Finish with an improvement plan, not a score.

  • Integrated clinical and cyber incident command
  • Validated downtime and diversion decisions
  • PHI, patient, regulator, and media workstreams
  • Medical-device and vendor coordination
  • Safety-based restoration criteria
Start with this exerciseRead the facilitator guide