Incident Communications Plan: Keeping Patient Care First
During a hospital cyber incident the technical work is rarely the bottleneck — coordination is. Who decides, who tells the wards, and how any of it happens when email is down.
GuardsArm Team
Security Experts
In most hospital cyber incidents the containment work is understood within hours. What extends the damage is coordination: wards not knowing whether to divert, clinicians unable to reach anyone, executives learning about it from a journalist, and an incident team trying to organise itself over the email system the attacker controls.
Out-of-band, decided in advance
The first requirement is a way to communicate that does not depend on the systems under attack. This must be chosen, provisioned and tested beforehand — setting it up during an incident is both slow and a security risk.
What it needs:
- Independent of corporate identity — if the directory is compromised, single sign-on to the chat tool is not a safe channel
- Reachable on personal devices, since laptops may be isolated
- A pre-populated roster, because nobody will find phone numbers at 3am
- Printed contact sheets held by on-call leadership — the low-technology fallback that always works
- Tested quarterly, with a call tree exercise
Audiences, in order
Different groups need different information at different times. Sequence deliberately.
| Audience | When | They need |
|---|---|---|
| Incident team | Immediately | Technical facts, tasks, channel |
| Executive on call | Within 30 min | Scope, clinical impact, decisions needed |
| Clinical leadership | Within 1 hour | What is unavailable, which procedures to activate |
| All clinical staff | Within 2 hours | Plain instructions: what works, what to do instead |
| Legal and privacy | Within hours | Scope for notification assessment |
| Cyber insurer | Per policy, often 24-72h | Policy terms frequently require early notice |
| Regulators | Per statutory deadline | Jurisdiction-specific and non-negotiable |
| Patients | After scope is established | Accurate facts; premature detail gets corrected publicly |
| Media | When a statement is ready | A holding statement beats silence |
Clinical staff are the audience most often served last and needing it most. They do not need incident detail. They need to know that the EHR is unavailable, that downtime procedures are active, and where the forms are.
Holding statements, written now
Under pressure, organisations either say nothing or say too much. Both are avoidable with pre-drafted templates covering: a suspected incident with unknown scope, confirmed disruption to clinical services, confirmed data involvement, and resolution. Each needs legal and clinical review before an incident, when there is time to get the wording right.
A holding statement should confirm that you are aware, that patient care is the priority, that you are investigating, and when you will next update. It should not speculate on cause, attribution, scope or data.
The regulatory clock
Deadlines start early and vary by jurisdiction. In the United States the HIPAA Breach Notification Rule sets the framework for PHI; other regimes are faster. Two practical points:
- Determination is not the same as discovery. The clock generally starts at discovery, not when the investigation concludes, so "we are still investigating" is not an extension.
- Know which regimes apply before the day. A hospital may have federal, state and contractual obligations with different timelines running simultaneously, plus payer and business-associate notification terms.
Get these written down with your legal team as a one-page reference for the incident binder. Researching them live wastes hours you will not have.
Structure that holds up
Separate the roles. An incident lead running technical response cannot also handle executive briefings, clinical notification and press enquiries. Name a communications lead in the plan.
Where to start
Run a call-tree exercise this quarter, on the out-of-band channel, assuming email and the corporate directory are unavailable. It takes an hour and reliably finds that the roster is stale, the tool needs corporate SSO, or the on-call list names someone who left.
For the operational side of an outage, see the 72-hour continuity plan.
GuardsArm builds and exercises healthcare incident communications plans, including out-of-band channel design and tabletop facilitation. Book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on “Incident Communications Plan: Keeping Patient Care First”
Talk to the GuardsArm team about how these services apply to your environment.


