You're 45 minutes into a ransomware event. Your EHR is locked. Clinical staff are asking whether to activate downtime procedures. Your MSP is on the phone. Your CFO wants to know if you should pay. And nobody's sure who gets to decide.
This is the moment your incident response plan either works or becomes a binder on a shelf.
The decision you're facing isn't technical; it's structural. When ransomware disrupts clinical workflows, you need a decision-making architecture that's faster than the chaos. That means knowing, before the incident, who owns which calls and when they make them.
The Decision You Are Facing
Your real choice isn't "respond or don't respond." It's whether you'll assign decision rights and practice the handoffs now, or improvise them under pressure later.
If you wait, you'll face these questions mid-crisis:
- Who declares severity and sets the update cadence?
- Who decides which systems get isolated first?
- Who approves the restore order when clinical and revenue-cycle priorities conflict?
- Who holds final authority on ransom payment, and who screens for OFAC sanctions?
Every minute spent debating ownership is a minute lost to containment.
Key Factors That Affect Your Choice
Operational Complexity
A single-facility practice can often centralize decisions with the practice administrator and IT lead. A multi-site health system needs clearer delineation: an incident commander who sets rhythm, a security lead who directs containment, separate clinical and IT operations leads who manage their domains, and executive sponsorship to resolve priority conflicts.
Third-party Dependencies
If your EHR, cloud infrastructure, or managed security services come from external vendors, you need pre-mapped escalation paths. Who contacts the EHR vendor? Who engages your cyber insurance broker? Who activates outside breach counsel? These aren't questions you want to answer while systems are offline.
Regulatory Exposure
HHS guidance presumes a breach when ransomware affects systems containing PHI unless a 4-factor risk assessment shows low probability of compromise. That means your compliance and legal teams need to be part of the decision loop from hour one, not brought in after containment.
Care-continuity Thresholds
Define what "care continuity" means for your organization before you're in downtime. What's your tolerance for EHR outage? Which ancillary systems (lab, radiology, pharmacy) are critical? What's the trigger for activating paper procedures? Your clinical operations lead should own this definition, not discover it mid-incident.
Path A: Centralized Command (Small to Mid-Size Covered Entities)
When to Choose This
You operate a single facility or small network. Decision-making can be fast because the leadership team is small and tightly coordinated.
Structure
Designate one incident commander (often your IT director or HIPAA Security Officer) who runs the response and makes containment calls. Assign a clinical liaison (practice manager, nursing director) who translates operational impact and sets downtime triggers. Bring in outside breach counsel and your cyber insurance broker within the first hour.
What You Need Ready
- A vendor contact tree with escalation paths for your EHR, MSP, and key SaaS platforms
- A restore-order list ranked by clinical impact (patient registration, scheduling, EHR core, lab/radiology interfaces, billing)
- A decision log template that captures what was decided, by whom, and when
- Confirmation that at least one backup copy is immutable or offline and validated through recent restore testing
First-hour Actions
Your incident commander declares severity, isolates affected segments using your containment playbook, and sets a 2-hour update rhythm. Your clinical liaison confirms whether downtime procedures need activation. Legal counsel is notified to preserve attorney-client privilege over forensic evidence.
Path B: Distributed Command (Health Systems and Complex Covered Entities)
When to Choose This
You operate multiple sites, have layered IT infrastructure, or support high-acuity clinical services where operational continuity is life-critical.
Structure
You need role separation. The incident commander sets cadence and removes blockers but doesn't make every technical call. Your CISO (or security lead) directs containment and coordinates forensics. IT operations handles infrastructure stabilization and restore execution. Clinical operations owns patient-safety decisions and workflow impact. Legal counsel directs privilege and regulatory strategy. Compliance tracks breach-notification timelines.
This isn't a committee; it's a command structure. Each role has clear decision rights, and the incident commander adjudicates conflicts.
What You Need Ready
- A roles-and-responsibilities matrix that maps each decision type to a named owner
- Pre-approved containment playbooks so your security lead doesn't need executive sign-off to isolate a compromised segment
- A tabletop exercise schedule (annually at minimum) that tests handoffs between roles
- Documented restore order aligned to both clinical priorities and business dependencies
- A ransom-payment decision path that includes OFAC sanctions screening, law enforcement notification, and a named executive with final authority
First-hour Actions
The incident commander activates the team and sets a 90-minute update cycle. The security lead begins containment and evidence capture. IT ops validates backup viability. Clinical ops assesses workflow impact and confirms downtime thresholds. Legal counsel engages outside breach counsel and cyber insurance. Compliance starts the breach-notification clock unless the 4-factor assessment can rebut the presumption.
Path C: Hybrid Command with External Coordination
When to Choose This
You rely heavily on a managed service provider (MSP) or managed security service provider (MSSP) for day-to-day IT operations, or your infrastructure is predominantly cloud-based with multiple SaaS vendors.
Structure
Your internal incident commander still owns decision rhythm and priority-setting, but technical containment and forensics are coordinated through your MSP/MSSP. You need a clear interface: who on your team approves containment actions, and who on the vendor side executes them?
What You Need Ready
- A service-level agreement (SLA) or statement of work that defines incident-response escalation paths and decision rights
- Contact details for your MSP's security operations center and their incident-response lead
- Confirmation that your cyber insurance policy covers your MSP's panel vendors for forensics and breach response
- A communication protocol so your MSP updates your incident commander, not just your IT staff
First-hour Actions
Your incident commander contacts the MSP's incident-response lead and confirms containment authority. Your MSP begins isolation and evidence capture under your direction. You engage your cyber insurance broker to confirm coverage and approve panel vendors. Legal counsel is brought in to preserve privilege over forensic findings.
Summary Matrix
| Factor | Path A: Centralized | Path B: Distributed | Path C: Hybrid/External |
|---|---|---|---|
| Org size/complexity | Single facility, small network | Multi-site, layered IT, high-acuity services | Heavy MSP/MSSP reliance, cloud-first |
| Incident commander | IT director or Security Officer | Named IC (often CISO or COO) | Internal IC + MSP coordination lead |
| Decision speed | Fast (small team) | Structured (role-based) | Coordinated (vendor + internal) |
| Key dependency | Vendor contact tree | Role clarity + tabletop practice | SLA-defined escalation paths |
| Restore-order owner | IT director + clinical liaison | IT ops + clinical ops (adjudicated by IC) | MSP executes; internal IC prioritizes |
| Legal/compliance trigger | First-hour counsel engagement | Compliance tracks breach clock; counsel directs privilege | Counsel + insurance broker coordinate forensics approval |
The goal isn't to build the perfect org chart. It's to eliminate decision paralysis when you're 45 minutes into an event and the EHR is still locked. Assign the roles. Practice the handoffs. Know who decides what. Then, when ransomware hits, you'll have a plan that works instead of a plan that looked good in the binder.



