All scenarios
Healthcare

Hospital network ransomware

Patient data exposed while care continues. Weigh patient safety, medical-device security and notification obligations against public-health communication under intense scrutiny.

Free to use for your own tabletop, no email gate.

Scenario brief

Hospital network ransomware, Healthcare

The threat

Ransomware encrypts clinical systems during a busy shift. The EHR is unavailable, some connected devices are behaving oddly, and leadership must protect patients first while meeting breach-notification duties.

Key injects

  • 01The EHR goes read-only; clinicians revert to paper.
  • 02A connected infusion device shows an unexpected reboot.
  • 03A regulator asks for scope of exposed patient records.
  • 04Local press reports ambulances being diverted.

What's assessed

  • Patient-safety prioritisation vs. containment
  • Clinical continuity and downtime procedures
  • Breach-scope determination and notification
  • Calm, accurate public messaging

Exercise objectives

  • Activate downtime procedures on every affected ward within 45 minutes; care continues before containment is perfect.
  • Triage connected medical devices for isolation without interrupting ongoing treatment.
  • Scope the breach well enough to meet GDPR Art. 33 (72 hours to the supervisory authority) and take a defensible Art. 34 decision on informing patients.
  • Keep public messaging calm and accurate while ambulances are being diverted.

Roles at the table

  • Crisis team lead · Runs the cadence between medicine, IT and administration; patient safety stays the first agenda item.
  • IT / SOC · Containment and EHR recovery options; tells medicine honestly what is down and for how long.
  • Clinical operations lead · Medical director on duty: ward-by-ward downtime, diversion decisions, staffing under paper operations.
  • Communications · Patients, relatives, staff and local press: calm wording that never outruns confirmed facts.
  • Data protection / legal · GDPR Art. 33/34 assessment, regulator contact, ransom and evidence questions.
  • Hospital management · Accepts residual risk, approves diversion and paper operations, faces the board and the public.

Discussion prompts

  • 01The EHR is read-only and the emergency department is full. Which patients do you divert first, and is that a call for IT or for medicine?
  • 02An infusion device rebooted without explanation. Do you pull every networked device from the wards on suspicion?
  • 03You cannot yet say which records were exposed. What do you tell the supervisory authority at hour 70, and the patients?
  • 04Staff are working on paper at double the workload. When does the cyber crisis become a patient-safety incident in its own right?
  • 05Local press reports diverted ambulances. Does your statement say 'ransomware' before it is confirmed?
  • 06Would you restore from backups while the intrusion path is unknown, if the alternative is days more on paper?

Suggested timeline

  • 00:00–00:25EHR goes read-only: downtime procedures, ward-by-ward triage
  • 00:25–01:10Device decisions: isolate, monitor or keep clinical systems running
  • 01:10–02:00Breach scoping: which records, which patients, Art. 33/34 assessment
  • 02:00–02:40Notification drafted; press statement and patient-information plan
  • 02:40–03:00Hot wash: care impact, notification quality, recovery priorities

Run this scenario with your team.