Emergency Response: Networked Medical Device Malware Containment & Isolation Protocol

1. Affected Medical Device, IP & Clinical Ward Identifiers

This section captures critical identification data for all affected medical devices. Complete with maximum precision to enable rapid response and asset tracking. Time is critical - provide information as accurately as possible under emergency conditions.

 

Is this incident affecting a single device or multiple devices?

 

How many devices are affected?

Affected Device Inventory & Network Identifiers

Device Manufacturer

Device Model

Serial Number

Hospital Asset ID

Primary IP Address

MAC Address

Hostname

Clinical Ward/Department

Room Number/Location

Device Criticality

Active on Patient?

A
B
C
D
E
F
G
H
I
J
K
1
 
 
 
 
 
 
 
 
 
Standard Care
 
2
 
 
 
 
 
 
 
 
 
 
 
3
 
 
 
 
 
 
 
 
 
 
 
4
 
 
 
 
 
 
 
 
 
 
 
5
 
 
 
 
 
 
 
 
 
 
 
6
 
 
 
 
 
 
 
 
 
 
 
7
 
 
 
 
 
 
 
 
 
 
 
8
 
 
 
 
 
 
 
 
 
 
 
9
 
 
 
 
 
 
 
 
 
 
 
10
 
 
 
 
 
 
 
 
 
 
 

Device primary network connection type

Network topology description - how is this device connected? (e.g., direct VLAN, wireless, via middleware server)

If device is active on patient(s), provide anonymized patient identifier(s) and clinical context

When was the malware infection first detected on this device?

Who initially detected the malware infection?

Device primary clinical function

2. Malware Threat Vector & Patient Safety Exposure Assessment

Comprehensive threat assessment is crucial for determining patient safety exposure and regulatory reporting obligations. Provide detailed analysis of the malware characteristics and potential clinical impact.

 

Malware detection method

Describe the specific malware identified (name, hash, behavior observed)

Has the malware demonstrated capability to affect device clinical functionality?

 

Select all clinical impacts observed or suspected:

Is there evidence of data exfiltration or unauthorized access to patient health information (PHI)?

 

Describe the scope of potential PHI exposure (data types, volume, affected patients)

Patient Safety Risk Assessment Matrix - Rate each dimension based on current understanding

Minimal

Low

Moderate

High

Critical

Direct Patient Harm Potential

Indirect Clinical Decision Impact

Data Integrity Risk

Device Availability Impact

Propagation Risk to Other Devices

Does this incident meet criteria for regulatory notification (e.g., FDA, HIPAA, CE Marking authorities)?

 

Specify which regulatory bodies must be notified and the timeline requirement

Describe the suspected initial infection vector and propagation path within the network

Overall Incident Severity Rating (1=Minor, 5=Catastrophic)

Is there any threat actor attribution or indication of targeted attack?

Threat intelligence sources consulted and key findings

3. Network Disconnection, VLAN Containment & Quarantine Verification

Document all network isolation actions taken to prevent malware propagation. This section serves as evidence of proper containment procedures and supports forensic investigation.

 

Has the affected device been physically disconnected from the network?

 

When was physical disconnection completed?

 

Explain why physical disconnection was not performed and what alternative containment was implemented

Network isolation methods implemented (select all applicable)

Provide specific technical details of VLAN containment and firewall rules implemented

Has network traffic capture been initiated for forensic analysis?

 

Specify capture location and file storage path

Have neighboring devices on the same network segment been scanned for infection indicators?

 

Summarize scan results and any additional devices quarantined

Containment Action Log - Document each step with timestamp and responsible personnel

Action Timestamp

Action Taken

Performed By

Verification Method

Action Verified?

A
B
C
D
E
1
1/20/2025, 2:30 PM
Physical network cable disconnected from device
J.Smith, Biomed Eng
Visual inspection and switch log review
Yes
2
1/20/2025, 2:35 PM
Device moved to quarantine VLAN 999
T.Jones, IT Security
Switch configuration verification
Yes
3
 
 
 
 
 
4
 
 
 
 
 
5
 
 
 
 
 
6
 
 
 
 
 
7
 
 
 
 
 
8
 
 
 
 
 
9
 
 
 
 
 
10
 
 
 
 
 

Is the device completely isolated from all production networks including wireless?

 

Describe any remaining network connectivity and justification

Has a forensic image of the device storage been created before remediation?

 

Forensic image hash (MD5/SHA256) and storage location

Have all containment actions been tested and verified effective?

 

Describe verification failures and corrective actions

4. Patient Care Continuity & Backup Medical Equipment Protocol

Ensure uninterrupted patient care through proper backup equipment deployment and clinical workflow adjustments. Document all measures taken to maintain clinical service levels.

 

Are there patients currently dependent on the affected device for life-support or critical care?

 

Immediate patient safety measures implemented

Backup Equipment Deployment Log

Original Device Asset ID

Backup Device Asset ID

Backup Device Location

Deployment Time

Deployed By

Clinical Validation Completed?

A
B
C
D
E
F
1
 
 
 
 
 
 
2
 
 
 
 
 
 
3
 
 
 
 
 
 
4
 
 
 
 
 
 
5
 
 
 
 
 
 
6
 
 
 
 
 
 
7
 
 
 
 
 
 
8
 
 
 
 
 
 
9
 
 
 
 
 
 
10
 
 
 
 
 
 

Has the clinical engineering team verified backup device calibration and safety before deployment?

 

Explain calibration status and any risks of using backup equipment

Impact on clinical service delivery

Have clinical staff been notified of device unavailability and alternative procedures?

 

Describe communication method and confirmation of receipt

Is manual backup procedure required due to lack of available backup devices?

 

Detail manual procedure and additional monitoring requirements

Describe any temporary workflow modifications implemented to maintain patient care standards

Has patient notification been required due to potential data breach or care disruption?

 

Document patient notification process and timeline

Are there supply chain implications affecting backup equipment availability?

 

Describe supply chain issues and contingency plans

Has additional staff training been required for backup equipment or manual procedures?

 

Document training provided and competency verification

5. Head of Biomedical Engineering & Hospital CISO Sign-Off

Final verification and authorization section. Both Biomedical Engineering and IT Security leadership must review all incident details, containment actions, and patient safety measures before sign-off. This form serves as official incident record.

 

Executive Summary of Incident (for leadership review)

Has all evidence been preserved for forensic analysis in accordance with incident response policy?

 

Explain any deviations from evidence preservation standard

Are there any objections to the containment actions taken from clinical leadership?

 

Document objections and resolution

Has the device manufacturer been notified of the security incident?

 

Provide manufacturer case number and response summary

Is there a formal risk acceptance for maintaining the device in quarantine state?

 

Explain rationale for not obtaining formal risk acceptance

Proposed device reconnection date/time (if applicable)

Reconnection prerequisites and security hardening requirements

Head of Biomedical Engineering - Incident Review & Approval

Biomedical Engineering Sign-off Timestamp

Hospital Chief Information Security Officer (CISO) - Security Review & Approval

CISO Sign-off Timestamp

Does this incident require escalation to hospital executive leadership or board notification?

 

Document escalation details and executive response

Has cyber insurance carrier been notified of the incident?

 

Provide insurance claim number and adjuster contact

Are there media or public relations considerations requiring communications department involvement?

 

Document PR strategy and messaging approval

Lessons Learned & Process Improvement Recommendations

Has this incident been entered into the official hospital risk management system?

 

Explain why not and provide alternative documentation method

To configure an element, select it on the form.

To add a new question or element, click the Question & Element button in the vertical toolbar on the left.