Healthcare Ransomware Tabletop Playbook: Test Decisions, Not Scripts

A facilitator-ready exercise structure for clinics and practices that need to test ransomware decision paths.

Updated

A ransomware tabletop is a discussion-based exercise, not a penetration test and not a dramatic reading of the incident response plan. Its purpose is to reveal whether clinic leaders can make and communicate the decisions needed to protect patients, contain harm, preserve evidence, sustain essential work, assess obligations, and recover safely when normal systems are unavailable.

This playbook helps healthcare clinics and practices run that exercise. It does not determine whether a particular event is a reportable breach, prescribe legal conclusions, or replace advice from privacy, legal, clinical, insurance, law-enforcement, or incident-response professionals. Apply requirements based on the organization's actual status, contracts, jurisdictions, and facts.

Define a narrow exercise objective

Choose one or two decisions to test rather than trying to simulate an entire crisis. Useful objectives include authorizing network containment without creating an unsafe care delay, shifting to approved downtime procedures, deciding when restoration is safe, escalating evidence to the privacy and legal process, or communicating when the EHR and normal contact lists are unavailable.

NIST's June 2026 Ransomware Risk Management Profile maps ransomware readiness across Govern, Identify, Protect, Detect, Respond, and Recover. Use that whole-life-cycle view to select the exercise objective. The tabletop itself should focus on decisions and handoffs, while technical control testing and restoration testing remain separate, controlled activities.

Put the right roles in the room

Invite roles that would actually make or execute decisions: executive incident lead, clinical operations, IT or managed IT, security or incident-response provider, privacy officer, legal counsel, communications, facilities, human resources, records or data owner, and key application or business-associate contacts. Include primary and backup decision makers. A facilitator delivers injects; a separate recorder captures decisions, assumptions, missing information, owners, and due dates.

For entities subject to the HIPAA Security Rule, HHS guidance says security incident procedures and contingency planning should address response, reporting, backup, disaster recovery, emergency operations, application and data criticality, and periodic testing. The HHS Ransomware and HIPAA fact sheet explains those points and the fact-specific breach assessment process. Use privacy or legal leadership to interpret how the guidance applies to the scenario; do not let the exercise facilitator improvise a legal determination.

Prepare evidence before the session

  • Current incident, downtime, emergency-operations, communications, and recovery plans.
  • Critical workflow list showing clinical and operational owners, manual alternatives, and dependencies.
  • Network, identity, vendor, backup, and data-flow summaries suitable for the participants.
  • Primary and out-of-band contact lists for leadership, vendors, responders, and advisers.
  • Response authority matrix for isolating systems, disabling accounts, engaging specialists, and switching workflows.
  • Sanitized backup and restoration evidence, including the last controlled test and unresolved findings.

Do not include live credentials, actual patient records, sensitive forensic artifacts, or instructions that could disrupt production. State that the scenario is fictional and identify how participants should report a real incident discovered during the exercise.

Use exercise rules that reward honest gaps

Tell participants that the goal is to test the plan, not the people. Let them consult the same documents and advisers they would use during a real event. When the group makes an assumption, the recorder labels it. When the answer is unknown, record the information owner and how the team would obtain it. Do not silently grant perfect backups, complete logs, immediate vendor response, or a clean network.

CISA's #StopRansomware Guide recommends maintaining and exercising incident response and communications plans. CISA also provides Tabletop Exercise Packages with facilitator and scenario materials. Adapt those voluntary resources to the clinic's size, workflow, and authority structure rather than treating them as a certification checklist.

Ransomware tabletop inject and decision worksheet

Copy the table into the facilitator guide. Reveal one row at a time. The facilitator may add facts only from the approved scenario; participants should state which evidence they need before deciding.

Inject Decision to test Evidence or question Record during exercise
1. Staff report a ransom note and cannot open scheduling or charting from several workstations. Who declares an incident, and what can be isolated immediately? Which sites, identities, systems, and patient-care functions appear affected? Incident lead, containment authority, time, and protected workflows
2. The EHR is unavailable, the network's status is uncertain, and patients are arriving. Which downtime procedures activate, and who can change clinical operations? Are approved forms, medication information, referral methods, and later reconciliation steps accessible? Clinical owner, service changes, safety escalation, and staff message
3. A privileged account shows suspicious use and the normal email channel may be exposed. Which accounts or sessions are disabled, and how will the team communicate? Is emergency access available, monitored, and separate from suspected credentials? Identity actions, approver, fallback channel, and rollback method
4. A backup console is reachable, but the team cannot yet establish whether it is trustworthy. Who authorizes restoration, to what isolated target, and after which checks? What restore evidence, clean credentials, recovery order, and validation are required? Recovery decision, dependencies, validation owner, and stop condition
5. The actor claims to have copied patient data, but the available evidence is incomplete. Who starts the factual and legal assessment, preserves evidence, and contacts advisers? What data, systems, access, acquisition, viewing, and mitigation facts are known? Facts versus assumptions, evidence custodian, advisers, and next review time
6. Patients, staff, a vendor, and a reporter request updates while facts are changing. Who approves each message and prevents speculation? Which audiences need operational instructions now, and which notifications require fact-specific review? Audience, channel, approver, message owner, and update cadence
7. Core systems appear recoverable, but integrations and endpoint trust are unresolved. What is the phased return-to-service order? Which security, data-integrity, clinical, and business checks define safe restoration? Service owner acceptance, monitoring, residual risk, and rollback trigger

Keep containment, continuity, and recovery separate

Containment limits further harm. Continuity keeps essential work operating through approved alternate methods. Recovery returns systems and data to a trustworthy state. One action can affect all three: isolating a network segment may limit spread but also interrupt phones, imaging, pharmacy, building access, or another dependent service. The exercise should require clinical and technical owners to describe those consequences before action when time and safety allow.

NIST SP 800-61 Revision 3 places preparation, detection, response, recovery, and improvement within ongoing risk management. HHS's Security Incident Procedures newsletter discusses incident documentation, mitigation, backup integrity, test restorations, and contingency planning for regulated entities. A tabletop can validate decision paths, but it cannot prove that a backup restores or a containment control works. Schedule technical tests separately.

Handle data-exposure claims as an evidence problem

Modern ransomware scenarios may include encryption, theft, extortion, or a false claim. The exercise should route facts to qualified privacy and legal review without having technical staff announce a conclusion. HHS's Breach Notification Rule guidance explains the HIPAA framework for breaches of unsecured PHI and the factors in the low-probability-of-compromise assessment. Whether and how that framework applies depends on the organization and incident facts.

Capture where evidence comes from, who preserves it, which systems and data may be involved, what is known about access or acquisition, and which mitigation occurred. Also identify contractual, state, insurance, law-enforcement, patient-safety, and other processes that the organization's advisers say apply. The exercise tests routing and authority, not a predetermined notification outcome.

Turn the after-action review into owned improvements

End the scenario before energy drops and hold a short hotwash. Ask what worked, what created delay, which authority was unclear, which contact or document failed, what evidence was missing, and which assumption was unsafe. Within an internally defined review period, issue an after-action record with each finding, risk, corrective action, owner, due date, and validation method.

Prioritize findings that affect patient safety, containment authority, trusted communications, evidence preservation, critical workflow continuity, or restoration confidence. Update the plan only after the responsible owners approve the change. Re-exercise the failed decision path after remediation; closing a ticket is not the same as showing that the new handoff works.

Connect the exercise to the rest of the program

Clarify the monitoring provider's escalation and containment role with the MDR evaluation guide. Test restoration assumptions against the distinction between cloud backup and disaster recovery. Use the clinic network data-governance model to identify owners and sensitive data flows before writing the exfiltration inject.

Primary sources

Suggested next step

Talk with Cloud Core MSP if your clinic needs a facilitated ransomware tabletop tied to its actual systems, decision makers, and downtime workflows.

Want help applying this to your environment?

Start with a short discovery call and we will help you sort the practical next step without overcomplicating it.