Provide precise device identification and network configuration details. All fields marked mandatory must be completed for incident traceability.
Device Manufacturer
Device Model Name & Number
Serial Number
Device Category
Imaging System
Patient Monitor
Therapeutic Device
Laboratory Analyzer
IT Infrastructure
Other
FDA Device Class
Class I
Class II
Class III
Unknown
Current Firmware Version
Last Known Authorized Firmware Version
Has firmware integrity been verified via digital signature or hash?
Provide hash value or signature verification result
Explain why firmware integrity verification was not possible
Primary Network IP Address
MAC Address
Network Segment/VLAN ID
IP Assignment Method
DHCP
Static IP
Unknown
Subnet Mask
Default Gateway
DNS Servers
Device Hostname
Primary Connection Type
Wired Ethernet
Wi-Fi
Bluetooth
Cellular
Hybrid/Multiple
Wi-Fi SSID (if applicable)
Active Network Ports/Services
Last Successful Patch/Update Date
Last Security Scan Date
Device Criticality Level (1=Low, 5=Critical)
Facility/Location
Department/Unit
Room Number
Primary Device Operator/Owner
Document the threat discovery details, vulnerability characteristics, and potential impact on patient safety and data security.
Vulnerability Discovery Timestamp
Discovery Method
Routine Vulnerability Scan
Anomaly Detection System
User/Staff Report
Vendor Security Advisory
Incident Response Team
Internal Audit
Third-Party Assessment
Other
Primary Vulnerability Type
Unauthorized Firmware Modification
Malware Infection
Configuration Weakness
Default/Weak Credentials
Unpatched Known CVE
Ransomware
Data Exfiltration
Denial of Service
Other
Probable Threat Vector
Network-Based Intrusion
Insider Threat
Supply Chain Compromise
Physical Device Access
USB/Removable Media
Wireless Exploitation
Web Interface Attack
Social Engineering
Unknown
Other
CVSS v3.1 Score (0.0 to 10.0)
Potential Patient Safety Impact
Does this vulnerability expose clinical patient data?
Describe type and volume of exposed data
Does this involve PHI/PII data breach implications?
Select applicable data types
Patient Names
Medical Record Numbers
Diagnostic Images
Treatment Data
Insurance Information
Social Security Numbers
Other Identifiers
Detailed Description of Potential Patient Harm
Harm Severity Classification
Negligible (No clinical impact)
Minor (Temporary inconvenience)
Moderate (Temporary clinical impact)
Major (Permanent clinical impact)
Catastrophic (Patient death or severe harm)
Attack Sophistication Level
Automated/Opportunistic
Targeted with Low Skill
Targeted with High Skill
Advanced Persistent Threat (APT)
Unknown
Has forensic evidence been preserved?
Describe evidence preservation method and storage location
Explain why evidence could not be preserved
Estimated Number of Similar Devices Potentially Affected
Has the device exhibited anomalous behavior?
Describe observed anomalies (performance issues, unexpected reboots, unusual network traffic)
Were network traffic anomalies observed?
Describe suspicious traffic patterns, destinations, or volumes
Are device log files available for analysis?
Specify log file locations and retention period
Explain log unavailability (overwritten, disabled, corrupted)
Document immediate containment actions, patient safety measures, and operational continuity plans.
Current Device Operational Status
Fully Operational
Isolated but Operational
Quarantined/Offline
Emergency Shutdown
Unknown
Isolation Methods Implemented
Network Cable Physically Disconnected
VLAN Segregation
Firewall Rules Applied
Air-Gapped
Port Security Disabled
Wireless Radio Disabled
Access Control List (ACL)
Other
Isolation/Containment Timestamp
Is a patient currently dependent on this device?
Describe patient dependency and transition plan
Is an alternative device available for immediate use?
Alternative device model and location
Explain contingency plan for patient care continuity
Estimated Clinical Impact Level
No Impact
Minor Delay (0-30 min)
Moderate Disruption (30 min-4 hours)
Critical Replacement Needed (4-24 hours)
Life-Threatening (Immediate action required)
Clinical Workflow Disruption Level (1=Minimal, 5=Severe)
Has a backup device been deployed?
Backup device serial number
Can device operate safely in offline/air-gapped mode?
Describe offline operational capabilities and limitations
Explain why offline operation is not feasible
Critical Safety Checks Completed Before Isolation
Was formal isolation approval obtained from clinical leadership?
Approving clinical leader name and role
Explain urgency that precluded formal approval
Network Access Restoration Plan
Record all vendor interactions, patch verification activities, diagnostic procedures, and remediation actions performed.
Has the device manufacturer/vendor been officially notified?
Vendor notification timestamp
Justify delayed vendor notification
Has vendor provided an initial response?
Vendor case/ticket number
Describe follow-up plan with vendor
Is an official security patch or firmware update available?
Patch version number
Describe vendor's recommended mitigation or workaround
Has the patch been tested in a lab environment?
Summarize test results and any issues identified
Explain testing plan or justification for direct deployment
Estimated Patch Deployment Timeline
Less than 24 hours
24-72 hours
3-7 days
1-2 weeks
More than 2 weeks
Unknown/Indeterminate
Diagnostic Actions Taken
Remediation Actions Performed
Was firmware integrity verification performed after remediation?
Post-remediation firmware hash/signature
Is firmware rollback to previous version possible if needed?
Rollback firmware version number
Explain rollback limitations
Vendor Support Quality Rating (1=Poor, 5=Excellent)
Additional Security Controls Implemented
Enhanced Network Segmentation
Intrusion Detection System
Multi-Factor Authentication
Encryption of Data at Rest/Transit
Physical Security Controls
Application Whitelisting
Endpoint Detection & Response
Other
Has remediation validation testing been completed?
Describe validation tests and success criteria
Explain pending validation steps
Has the device been returned to full clinical service?
Return to service timestamp
Explain why device remains out of service
Final authorization and risk acceptance documentation requiring sign-off from both Information Security and Biomedical Engineering leadership.
Executive Summary of Incident & Resolution
Has formal root cause analysis been completed?
Summarize root cause findings
Explain timeline for RCA completion
Risk Acceptance Decision
Accept Risk (Device returned to service)
Mitigate Risk (Additional controls required)
Transfer Risk (Vendor/managed service)
Avoid Risk (Device remains offline/decommissioned)
CISO Review and Approval Completed
Chief Information Security Officer Name
Explain pending CISO review items
CISO Digital Signature
CISO Sign-Off Timestamp
Head of Biomedical Engineering Review and Approval Completed
Head of Biomedical Engineering Name
Explain pending Biomedical Engineering review items
Head of Biomedical Engineering Digital Signature
Biomedical Engineering Sign-Off Timestamp
Is executive escalation to C-Suite required?
Executive Name and Title notified
Is regulatory reporting to external bodies required?
Select regulatory bodies to be notified
FDA (Medical Device Reporting)
HHS Office for Civil Rights
State Health Department
Device Manufacturer
Information Sharing Organization
Other
Have lessons learned been formally documented?
Summarize key lessons and process improvements
Plan for lessons learned documentation
All Documentation Complete and Verified
Follow-up security audit scheduled?
Follow-up audit date
To configure an element, select it on the form.