This section captures critical identification data for all affected medical devices. Complete with maximum precision to enable rapid response and asset tracking. Time is critical - provide information as accurately as possible under emergency conditions.
Is this incident affecting a single device or multiple devices?
How many devices are affected?
Affected Device Inventory & Network Identifiers
Device Manufacturer | Device Model | Serial Number | Hospital Asset ID | Primary IP Address | MAC Address | Hostname | Clinical Ward/Department | Room Number/Location | Device Criticality | Active on Patient? | ||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
A | B | C | D | E | F | G | H | I | J | K | ||
1 | Standard Care | |||||||||||
2 | ||||||||||||
3 | ||||||||||||
4 | ||||||||||||
5 | ||||||||||||
6 | ||||||||||||
7 | ||||||||||||
8 | ||||||||||||
9 | ||||||||||||
10 |
Device primary network connection type
Wired Ethernet
WiFi/Wireless
Both Wired & Wireless
Bluetooth
Proprietary RF
Unknown
Network topology description - how is this device connected? (e.g., direct VLAN, wireless, via middleware server)
If device is active on patient(s), provide anonymized patient identifier(s) and clinical context
When was the malware infection first detected on this device?
Who initially detected the malware infection?
Device primary clinical function
Comprehensive threat assessment is crucial for determining patient safety exposure and regulatory reporting obligations. Provide detailed analysis of the malware characteristics and potential clinical impact.
Malware detection method
Endpoint Detection & Response (EDR) Alert
Network Intrusion Detection System
Antivirus Software
Manual Discovery by Staff
Vendor Notification
Patient Safety Event Triggered Investigation
Other
Describe the specific malware identified (name, hash, behavior observed)
Has the malware demonstrated capability to affect device clinical functionality?
Select all clinical impacts observed or suspected:
Device Unresponsive/Shutdown
Incorrect Data Display
Alarm Suppression
Therapy Delivery Interruption
Data Corruption
Network Communication Failure
Delayed Diagnostic Results
Other Critical Impact
Is there evidence of data exfiltration or unauthorized access to patient health information (PHI)?
Describe the scope of potential PHI exposure (data types, volume, affected patients)
Patient Safety Risk Assessment Matrix - Rate each dimension based on current understanding
Minimal | Low | Moderate | High | Critical | |
|---|---|---|---|---|---|
Direct Patient Harm Potential | |||||
Indirect Clinical Decision Impact | |||||
Data Integrity Risk | |||||
Device Availability Impact | |||||
Propagation Risk to Other Devices |
Does this incident meet criteria for regulatory notification (e.g., FDA, HIPAA, CE Marking authorities)?
Specify which regulatory bodies must be notified and the timeline requirement
Describe the suspected initial infection vector and propagation path within the network
Overall Incident Severity Rating (1=Minor, 5=Catastrophic)
Is there any threat actor attribution or indication of targeted attack?
Threat intelligence sources consulted and key findings
Document all network isolation actions taken to prevent malware propagation. This section serves as evidence of proper containment procedures and supports forensic investigation.
Has the affected device been physically disconnected from the network?
When was physical disconnection completed?
Explain why physical disconnection was not performed and what alternative containment was implemented
Network isolation methods implemented (select all applicable)
Physical Cable Disconnection
Switch Port Shutdown
VLAN Segregation
Firewall Rule Blocking
Access Control List (ACL) Implementation
Wireless SSID Disconnection
Network Access Control (NAC) Quarantine
Other
Provide specific technical details of VLAN containment and firewall rules implemented
Has network traffic capture been initiated for forensic analysis?
Specify capture location and file storage path
Have neighboring devices on the same network segment been scanned for infection indicators?
Summarize scan results and any additional devices quarantined
Containment Action Log - Document each step with timestamp and responsible personnel
Action Timestamp | Action Taken | Performed By | Verification Method | Action Verified? | ||
|---|---|---|---|---|---|---|
A | B | C | D | E | ||
1 | 1/20/2025, 2:30 PM | Physical network cable disconnected from device | J.Smith, Biomed Eng | Visual inspection and switch log review | Yes | |
2 | 1/20/2025, 2:35 PM | Device moved to quarantine VLAN 999 | T.Jones, IT Security | Switch configuration verification | Yes | |
3 | ||||||
4 | ||||||
5 | ||||||
6 | ||||||
7 | ||||||
8 | ||||||
9 | ||||||
10 |
Is the device completely isolated from all production networks including wireless?
Describe any remaining network connectivity and justification
Has a forensic image of the device storage been created before remediation?
Forensic image hash (MD5/SHA256) and storage location
Have all containment actions been tested and verified effective?
Describe verification failures and corrective actions
Ensure uninterrupted patient care through proper backup equipment deployment and clinical workflow adjustments. Document all measures taken to maintain clinical service levels.
Are there patients currently dependent on the affected device for life-support or critical care?
Immediate patient safety measures implemented
Backup Equipment Deployment Log
Original Device Asset ID | Backup Device Asset ID | Backup Device Location | Deployment Time | Deployed By | Clinical Validation Completed? | ||
|---|---|---|---|---|---|---|---|
A | B | C | D | E | F | ||
1 | |||||||
2 | |||||||
3 | |||||||
4 | |||||||
5 | |||||||
6 | |||||||
7 | |||||||
8 | |||||||
9 | |||||||
10 |
Has the clinical engineering team verified backup device calibration and safety before deployment?
Explain calibration status and any risks of using backup equipment
Impact on clinical service delivery
No Impact - Backup Available Immediately
Minor Delay (<15 minutes)
Moderate Delay (15-60 minutes)
Significant Delay (1-4 hours)
Service Interruption (>4 hours)
Complete Service Outage
Have clinical staff been notified of device unavailability and alternative procedures?
Describe communication method and confirmation of receipt
Is manual backup procedure required due to lack of available backup devices?
Detail manual procedure and additional monitoring requirements
Describe any temporary workflow modifications implemented to maintain patient care standards
Has patient notification been required due to potential data breach or care disruption?
Document patient notification process and timeline
Are there supply chain implications affecting backup equipment availability?
Describe supply chain issues and contingency plans
Has additional staff training been required for backup equipment or manual procedures?
Document training provided and competency verification
Final verification and authorization section. Both Biomedical Engineering and IT Security leadership must review all incident details, containment actions, and patient safety measures before sign-off. This form serves as official incident record.
Executive Summary of Incident (for leadership review)
Has all evidence been preserved for forensic analysis in accordance with incident response policy?
Explain any deviations from evidence preservation standard
Are there any objections to the containment actions taken from clinical leadership?
Document objections and resolution
Has the device manufacturer been notified of the security incident?
Provide manufacturer case number and response summary
Is there a formal risk acceptance for maintaining the device in quarantine state?
Explain rationale for not obtaining formal risk acceptance
Proposed device reconnection date/time (if applicable)
Reconnection prerequisites and security hardening requirements
Head of Biomedical Engineering - Incident Review & Approval
Biomedical Engineering Sign-off Timestamp
Hospital Chief Information Security Officer (CISO) - Security Review & Approval
CISO Sign-off Timestamp
Does this incident require escalation to hospital executive leadership or board notification?
Document escalation details and executive response
Has cyber insurance carrier been notified of the incident?
Provide insurance claim number and adjuster contact
Are there media or public relations considerations requiring communications department involvement?
Document PR strategy and messaging approval
Lessons Learned & Process Improvement Recommendations
Has this incident been entered into the official hospital risk management system?
Explain why not and provide alternative documentation method
To configure an element, select it on the form.