Cybersecurity drills for small clinics

Practice the bad day before it happens.

A facilitated, 40-minute tabletop exercise your whole clinic runs around one screen — ransomware, phishing, a lost laptop — localized to your practice, your EHR, your town. No IT department required. Finish with a written after-action report you keep for compliance and insurance.

Built on HIPAA Security Rule and NIST CSF 2.0 framing · No real patient data, ever

Day 1 · 8:42 AMInject 2 of 9

Maria at the front desk calls you over. Every workstation shows the same message: “Your files have been encrypted.” The schedule won't open. The waiting room is filling up, and Dr. Patel's first patient is a diabetic follow-up who drove forty minutes to be here.

Your team, right now: what are the first three things you do — and who does each one?

Your team discusses, then answers together…
Facilitator note

Unplugging network cables is a defensible first move — powering machines off can destroy evidence your insurer and forensics team will need.

Why clinics run drills

The plan on the shelf is not the same as a team that has practiced.

Your insurer is already asking

Cyber insurance renewals increasingly ask whether you test your incident response. “No” affects premiums and coverage. A dated exercise record answers the question.

Consultant drills cost thousands

A facilitator-led tabletop is a genuinely useful exercise — priced for hospital systems. Small practices get quoted four figures for a single afternoon.

Untrained teams freeze

On the real bad day, the front desk is improvising and nobody knows who calls the EHR vendor, the insurer, or the patients. Forty minutes of practice changes that.

How it works

One screen. Whole team. Forty minutes.

1

Tell us about your clinic

Name, town, EHR, staff size, IT situation. The scenario is rewritten around your answers — your software goes down, a local reporter calls, the story happens to you.

2

Gather the team and play it out

Developments arrive one at a time on a simulated clock. Your team discusses out loud and answers as a group. A facilitator evaluates each answer and teaches before moving on — pressure from patients, staff, media, insurer, and regulators builds as you go.

3

Keep the report

Every run ends with a scored after-action report — what went well, gaps to fix, and the HIPAA and NIST CSF 2.0 citations behind each item — archived permanently with your attendance roster.

Scenario library

The bad days every clinic should rehearse.

Each scenario is a four-phase story with authored decision points, conditional branches based on your choices, and coach notes citing only official sources — HHS, CISA, NIST, and the FTC.

Ransomware

Locked Out: Ransomware at the Clinic

A ransomware attack encrypts the clinic’s systems on a busy weekday morning. The exercise walks the team from first detection through containment, patient and media communication, and recovery — including the breach-notification decision.

~40 min · 4 phases · 9 developments
Phishing / Wire Fraud

The Email That Wasn’t: Phishing and Wire Fraud

A staff member’s email password is stolen by a fake voicemail notification. Within a day, the attacker has wired money out of the clinic, tampered with payroll, phished patients from the clinic’s own address — and quietly copied a mailbox full of patient information. The exercise runs from the first “I think I did something bad” through fraud response, the breach-notification decision, and the fixes that would have prevented all of it.

~40 min · 4 phases · 8 developments
Lost Device

Gone From the Parking Lot: The Unencrypted Laptop

A staff member’s car is broken into over the weekend and the clinic’s billing laptop — unencrypted, with saved passwords and a patient spreadsheet on the desktop — is gone. The exercise runs from the Monday-morning phone call through scoping what was on a machine you no longer have, the “it’s password-protected” conversation, patient notification on the under-500 path, and the one-afternoon fix that would have made all of it unnecessary.

~40 min · 4 phases · 9 developments
Insider

Familiar Faces: An Employee in the Wrong Charts

A furious patient calls: someone at a cookout repeated details of her recent visit — details only the clinic would know. The audit logs point to one of your best-liked, longest-tenured staff members. The exercise runs from taking the complaint seriously through the audit trail, the interview, the “she works here, she’s allowed in the system” argument, a staff room choosing sides, and the access controls that catch the next case in weeks instead of months.

~40 min · 4 phases · 9 developments
Vendor Breach

Not Our Servers: The EHR Vendor Gets Ransomed

Monday morning, the EHR won’t load — the vendor’s status page says “emergency maintenance,” the trade press says ransomware, and your waiting room is filling up. The exercise runs from seeing patients safely with no charts, through the vendor’s lawyerly letters, to the moment the forensics land: thousands of YOUR patients’ records were taken from THEIR servers — and the notification duty lands on the clinic anyway.

~40 min · 4 phases · 9 developments
Phone Scam

The Helpful Caller: Fake Support on Line Two

A friendly, competent-sounding caller claiming to be your EHR vendor’s support line says there’s an urgent security patch — and talks the front desk into installing a remote-access tool. The exercise runs from the moment of the call through cutting the intruder off, figuring out what he saw and did on a machine signed into the EHR, the bank-account scare, the breach analysis, handling the employee who was fooled without punishing the honesty that surfaced it, and the callback rule that makes the next call bounce off.

~40 min · 4 phases · 9 developments
Departing Staff

Two Weeks’ Notice: The Account Nobody Closed

Your billing specialist leaves on decent terms for a competing practice across town. Three weeks later, patients start calling: the other practice is “welcoming” them by name. The audit log tells the rest — her account was never disabled, she signed in after her last day, and she exported the patient list. The exercise runs from the first strange phone call through the audit-log gut punch, the lawyer and the letter to the other practice, the over-500 notification path with its media notice, the staff room full of rumors about someone they liked, and the offboarding checklist that makes the whole scenario impossible to repeat.

~40 min · 4 phases · 9 developments
Email Takeover

The Missing Paycheck: Six Weeks Inside Your Email

On payday, a medical assistant’s direct deposit doesn’t arrive — and the bookkeeper insists the practice manager emailed the bank change herself, from her real address. She didn’t. Someone has been inside her mailbox for six weeks: hidden rules deleting the replies that would have given it away, a forwarding rule copying everything out, and a patient-facing “new payment portal” email sent in her name. The exercise runs from the payday gut-punch through evicting the intruder, chasing the money, treating a clinic mailbox as the PHI trove it quietly becomes, the under-500 notification path, and the two fixes — MFA and voice-verified payment changes — that would have made the whole story impossible.

~40 min · 4 phases · 9 developments

New scenarios are added to the library and included with every plan.

The after-action report

The drill is the practice. The report is the proof.

Every exercise ends with a written after-action report: a preparedness score rolled up by NIST CSF 2.0 function, every question and answer with the criteria it was scored against, gaps to fix with plain-language recommendations, and the roster of who was in the room. Print it, save the PDF, or keep it at its permanent link — it's your evidence for the security risk assessment, the auditor, and the insurance questionnaire.

Scored by NIST CSF 2.0 functionHIPAA citations on every criterionAttendance roster includedArchived at a permanent linkImprovement trend across repeat runs

Pricing

One flat price for your whole organization. Everyone in the room is covered.

Monthly$99/monthCancel anytime

Common questions

Asked by every office manager. Answered plainly.

Do we need IT or security knowledge?

No. Everything is written in plain language for the people who actually run a clinic — office managers, front desk, billing, clinicians. If a question would stump a normal clinic team, we rewrote it.

How long does an exercise take?

About 40 minutes. The pacing is built in: every scenario moves through four phases and ends with a short team debrief. It fits in a lunch hour or a slow Friday afternoon.

Who should be in the room?

Whoever would actually be there on the bad day: the office or practice manager, someone from the front desk, billing, and a clinician if you can get one. One screen, one group, answering together. Everyone you list is recorded on the report as your attendance record.

Is any of our patient data involved?

No. Exercises are simulations. We ask for your clinic name, town, EHR name, and staff roles so the story feels like it is happening to you — never patient information, and the scenario never asks your team to enter any.

Does this make us HIPAA compliant?

No single product can honestly claim that. What an exercise gives you is a documented, dated record that your team practiced its incident response — the kind of evidence security risk assessments, auditors, and cyber insurance questionnaires ask about. Every after-action report cites the HIPAA and NIST CSF 2.0 items each question maps to.

Can we cancel anytime?

Yes. Monthly plans cancel anytime and annual plans do not auto-trap you — manage everything yourself from the billing portal. Your archived reports remain yours.

Different question? Ask us directly — a real person replies, usually the same day.

Your team's first drill could be this Friday.

Sign in with your email, tell us about your clinic, and gather the team around one screen.