All scenarios
Healthcare
Hospital network ransomware
Patient data exposed while care continues. Weigh patient safety, medical-device security and notification obligations against public-health communication under intense scrutiny.
Free to use for your own tabletop, no email gate.
Scenario brief

The threat
Ransomware encrypts clinical systems during a busy shift. The EHR is unavailable, some connected devices are behaving oddly, and leadership must protect patients first while meeting breach-notification duties.
Key injects
- 01The EHR goes read-only; clinicians revert to paper.
- 02A connected infusion device shows an unexpected reboot.
- 03A regulator asks for scope of exposed patient records.
- 04Local press reports ambulances being diverted.
What's assessed
- Patient-safety prioritisation vs. containment
- Clinical continuity and downtime procedures
- Breach-scope determination and notification
- Calm, accurate public messaging
Exercise objectives
- Activate downtime procedures on every affected ward within 45 minutes; care continues before containment is perfect.
- Triage connected medical devices for isolation without interrupting ongoing treatment.
- Scope the breach well enough to meet GDPR Art. 33 (72 hours to the supervisory authority) and take a defensible Art. 34 decision on informing patients.
- Keep public messaging calm and accurate while ambulances are being diverted.
Roles at the table
- ●Crisis team lead · Runs the cadence between medicine, IT and administration; patient safety stays the first agenda item.
- ●IT / SOC · Containment and EHR recovery options; tells medicine honestly what is down and for how long.
- ●Clinical operations lead · Medical director on duty: ward-by-ward downtime, diversion decisions, staffing under paper operations.
- ●Communications · Patients, relatives, staff and local press: calm wording that never outruns confirmed facts.
- ●Data protection / legal · GDPR Art. 33/34 assessment, regulator contact, ransom and evidence questions.
- ●Hospital management · Accepts residual risk, approves diversion and paper operations, faces the board and the public.
Discussion prompts
- 01The EHR is read-only and the emergency department is full. Which patients do you divert first, and is that a call for IT or for medicine?
- 02An infusion device rebooted without explanation. Do you pull every networked device from the wards on suspicion?
- 03You cannot yet say which records were exposed. What do you tell the supervisory authority at hour 70, and the patients?
- 04Staff are working on paper at double the workload. When does the cyber crisis become a patient-safety incident in its own right?
- 05Local press reports diverted ambulances. Does your statement say 'ransomware' before it is confirmed?
- 06Would you restore from backups while the intrusion path is unknown, if the alternative is days more on paper?
Suggested timeline
- 00:00–00:25EHR goes read-only: downtime procedures, ward-by-ward triage
- 00:25–01:10Device decisions: isolate, monitor or keep clinical systems running
- 01:10–02:00Breach scoping: which records, which patients, Art. 33/34 assessment
- 02:00–02:40Notification drafted; press statement and patient-information plan
- 02:40–03:00Hot wash: care impact, notification quality, recovery priorities