Back to Blog
Incident Response
9 min read

Incident Communications Plan: Keeping Patient Care First

During a hospital cyber incident the technical work is rarely the bottleneck — coordination is. Who decides, who tells the wards, and how any of it happens when email is down.

GuardsArm Team

Security Experts

December 13, 2025

Incident communications

In most hospital cyber incidents the containment work is understood within hours. What extends the damage is coordination: wards not knowing whether to divert, clinicians unable to reach anyone, executives learning about it from a journalist, and an incident team trying to organise itself over the email system the attacker controls.

Email may be hostile
If the attacker is in the mail system, planning over email briefs them too
Clinicians first
The people delivering care need to know before the press does
Clocks are running
Regulatory notification deadlines start early and do not pause

Out-of-band, decided in advance

The first requirement is a way to communicate that does not depend on the systems under attack. This must be chosen, provisioned and tested beforehand — setting it up during an incident is both slow and a security risk.

What it needs:

  • Independent of corporate identity — if the directory is compromised, single sign-on to the chat tool is not a safe channel
  • Reachable on personal devices, since laptops may be isolated
  • A pre-populated roster, because nobody will find phone numbers at 3am
  • Printed contact sheets held by on-call leadership — the low-technology fallback that always works
  • Tested quarterly, with a call tree exercise
Assume the attacker reads your email
If the mail system is in scope, the incident channel must not be in it. Teams have discussed containment timing over compromised email and had the adversary act first. Move to the out-of-band channel on declaration, before you know the scope.

Audiences, in order

Different groups need different information at different times. Sequence deliberately.

AudienceWhenThey need
Incident teamImmediatelyTechnical facts, tasks, channel
Executive on callWithin 30 minScope, clinical impact, decisions needed
Clinical leadershipWithin 1 hourWhat is unavailable, which procedures to activate
All clinical staffWithin 2 hoursPlain instructions: what works, what to do instead
Legal and privacyWithin hoursScope for notification assessment
Cyber insurerPer policy, often 24-72hPolicy terms frequently require early notice
RegulatorsPer statutory deadlineJurisdiction-specific and non-negotiable
PatientsAfter scope is establishedAccurate facts; premature detail gets corrected publicly
MediaWhen a statement is readyA holding statement beats silence

Clinical staff are the audience most often served last and needing it most. They do not need incident detail. They need to know that the EHR is unavailable, that downtime procedures are active, and where the forms are.


Holding statements, written now

Under pressure, organisations either say nothing or say too much. Both are avoidable with pre-drafted templates covering: a suspected incident with unknown scope, confirmed disruption to clinical services, confirmed data involvement, and resolution. Each needs legal and clinical review before an incident, when there is time to get the wording right.

A holding statement should confirm that you are aware, that patient care is the priority, that you are investigating, and when you will next update. It should not speculate on cause, attribution, scope or data.


The regulatory clock

Deadlines start early and vary by jurisdiction. In the United States the HIPAA Breach Notification Rule sets the framework for PHI; other regimes are faster. Two practical points:

  • Determination is not the same as discovery. The clock generally starts at discovery, not when the investigation concludes, so "we are still investigating" is not an extension.
  • Know which regimes apply before the day. A hospital may have federal, state and contractual obligations with different timelines running simultaneously, plus payer and business-associate notification terms.

Get these written down with your legal team as a one-page reference for the incident binder. Researching them live wastes hours you will not have.


Structure that holds up

Incident communications sequenceDeclaration by a named authority, immediate move to an out-of-band channel, clinical briefing, scope assessment, then notification per obligation.Declarenamed authorityMove channelout-of-bandBrief clinicalwithin the hourAssess scopelegal + privacyNotifyper obligation
One named role owns communications so the incident lead can run the response.

Separate the roles. An incident lead running technical response cannot also handle executive briefings, clinical notification and press enquiries. Name a communications lead in the plan.


Where to start

Run a call-tree exercise this quarter, on the out-of-band channel, assuming email and the corporate directory are unavailable. It takes an hour and reliably finds that the roster is stale, the tool needs corporate SSO, or the on-call list names someone who left.

For the operational side of an outage, see the 72-hour continuity plan.

GuardsArm builds and exercises healthcare incident communications plans, including out-of-band channel design and tabletop facilitation. Book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on “Incident Communications Plan: Keeping Patient Care First”

Talk to the GuardsArm team about how these services apply to your environment.