Cybersecurity drills for small clinics
A facilitated, 40-minute tabletop exercise your whole clinic runs around one screen — ransomware, phishing, a lost laptop — localized to your practice, your EHR, your town. No IT department required. Finish with a written after-action report you keep for compliance and insurance.
Built on HIPAA Security Rule and NIST CSF 2.0 framing · No real patient data, ever
Maria at the front desk calls you over. Every workstation shows the same message: “Your files have been encrypted.” The schedule won't open. The waiting room is filling up, and Dr. Patel's first patient is a diabetic follow-up who drove forty minutes to be here.
Your team, right now: what are the first three things you do — and who does each one?
Unplugging network cables is a defensible first move — powering machines off can destroy evidence your insurer and forensics team will need.
Why clinics run drills
Cyber insurance renewals increasingly ask whether you test your incident response. “No” affects premiums and coverage. A dated exercise record answers the question.
A facilitator-led tabletop is a genuinely useful exercise — priced for hospital systems. Small practices get quoted four figures for a single afternoon.
On the real bad day, the front desk is improvising and nobody knows who calls the EHR vendor, the insurer, or the patients. Forty minutes of practice changes that.
How it works
Name, town, EHR, staff size, IT situation. The scenario is rewritten around your answers — your software goes down, a local reporter calls, the story happens to you.
Developments arrive one at a time on a simulated clock. Your team discusses out loud and answers as a group. A facilitator evaluates each answer and teaches before moving on — pressure from patients, staff, media, insurer, and regulators builds as you go.
Every run ends with a scored after-action report — what went well, gaps to fix, and the HIPAA and NIST CSF 2.0 citations behind each item — archived permanently with your attendance roster.
Scenario library
Each scenario is a four-phase story with authored decision points, conditional branches based on your choices, and coach notes citing only official sources — HHS, CISA, NIST, and the FTC.
A ransomware attack encrypts the clinic’s systems on a busy weekday morning. The exercise walks the team from first detection through containment, patient and media communication, and recovery — including the breach-notification decision.
~40 min · 4 phases · 9 developmentsA staff member’s email password is stolen by a fake voicemail notification. Within a day, the attacker has wired money out of the clinic, tampered with payroll, phished patients from the clinic’s own address — and quietly copied a mailbox full of patient information. The exercise runs from the first “I think I did something bad” through fraud response, the breach-notification decision, and the fixes that would have prevented all of it.
~40 min · 4 phases · 8 developmentsA staff member’s car is broken into over the weekend and the clinic’s billing laptop — unencrypted, with saved passwords and a patient spreadsheet on the desktop — is gone. The exercise runs from the Monday-morning phone call through scoping what was on a machine you no longer have, the “it’s password-protected” conversation, patient notification on the under-500 path, and the one-afternoon fix that would have made all of it unnecessary.
~40 min · 4 phases · 9 developmentsA furious patient calls: someone at a cookout repeated details of her recent visit — details only the clinic would know. The audit logs point to one of your best-liked, longest-tenured staff members. The exercise runs from taking the complaint seriously through the audit trail, the interview, the “she works here, she’s allowed in the system” argument, a staff room choosing sides, and the access controls that catch the next case in weeks instead of months.
~40 min · 4 phases · 9 developmentsMonday morning, the EHR won’t load — the vendor’s status page says “emergency maintenance,” the trade press says ransomware, and your waiting room is filling up. The exercise runs from seeing patients safely with no charts, through the vendor’s lawyerly letters, to the moment the forensics land: thousands of YOUR patients’ records were taken from THEIR servers — and the notification duty lands on the clinic anyway.
~40 min · 4 phases · 9 developmentsA friendly, competent-sounding caller claiming to be your EHR vendor’s support line says there’s an urgent security patch — and talks the front desk into installing a remote-access tool. The exercise runs from the moment of the call through cutting the intruder off, figuring out what he saw and did on a machine signed into the EHR, the bank-account scare, the breach analysis, handling the employee who was fooled without punishing the honesty that surfaced it, and the callback rule that makes the next call bounce off.
~40 min · 4 phases · 9 developmentsYour billing specialist leaves on decent terms for a competing practice across town. Three weeks later, patients start calling: the other practice is “welcoming” them by name. The audit log tells the rest — her account was never disabled, she signed in after her last day, and she exported the patient list. The exercise runs from the first strange phone call through the audit-log gut punch, the lawyer and the letter to the other practice, the over-500 notification path with its media notice, the staff room full of rumors about someone they liked, and the offboarding checklist that makes the whole scenario impossible to repeat.
~40 min · 4 phases · 9 developmentsOn payday, a medical assistant’s direct deposit doesn’t arrive — and the bookkeeper insists the practice manager emailed the bank change herself, from her real address. She didn’t. Someone has been inside her mailbox for six weeks: hidden rules deleting the replies that would have given it away, a forwarding rule copying everything out, and a patient-facing “new payment portal” email sent in her name. The exercise runs from the payday gut-punch through evicting the intruder, chasing the money, treating a clinic mailbox as the PHI trove it quietly becomes, the under-500 notification path, and the two fixes — MFA and voice-verified payment changes — that would have made the whole story impossible.
~40 min · 4 phases · 9 developmentsNew scenarios are added to the library and included with every plan.
The after-action report
Every exercise ends with a written after-action report: a preparedness score rolled up by NIST CSF 2.0 function, every question and answer with the criteria it was scored against, gaps to fix with plain-language recommendations, and the roster of who was in the room. Print it, save the PDF, or keep it at its permanent link — it's your evidence for the security risk assessment, the auditor, and the insurance questionnaire.
Pricing
Common questions
No. Everything is written in plain language for the people who actually run a clinic — office managers, front desk, billing, clinicians. If a question would stump a normal clinic team, we rewrote it.
About 40 minutes. The pacing is built in: every scenario moves through four phases and ends with a short team debrief. It fits in a lunch hour or a slow Friday afternoon.
Whoever would actually be there on the bad day: the office or practice manager, someone from the front desk, billing, and a clinician if you can get one. One screen, one group, answering together. Everyone you list is recorded on the report as your attendance record.
No. Exercises are simulations. We ask for your clinic name, town, EHR name, and staff roles so the story feels like it is happening to you — never patient information, and the scenario never asks your team to enter any.
No single product can honestly claim that. What an exercise gives you is a documented, dated record that your team practiced its incident response — the kind of evidence security risk assessments, auditors, and cyber insurance questionnaires ask about. Every after-action report cites the HIPAA and NIST CSF 2.0 items each question maps to.
Yes. Monthly plans cancel anytime and annual plans do not auto-trap you — manage everything yourself from the billing portal. Your archived reports remain yours.
Different question? Ask us directly — a real person replies, usually the same day.
Sign in with your email, tell us about your clinic, and gather the team around one screen.