Provide precise device identification and network configuration details. All fields marked mandatory must be completed for incident traceability.
Device Manufacturer
Device Model Name & Number
Serial Number
Device Category
Imaging System
Patient Monitor
Therapeutic Device
Laboratory Analyzer
IT Infrastructure
Other
FDA Device Class
Class I
Class II
Class III
Unknown
Current Firmware Version
Last Known Authorized Firmware Version
Has firmware integrity been verified via digital signature or hash?
Primary Network IP Address
MAC Address
Network Segment/VLAN ID
IP Assignment Method
DHCP
Static IP
Unknown
Subnet Mask
Default Gateway
DNS Servers
Device Hostname
Primary Connection Type
Wired Ethernet
Wi-Fi
Bluetooth
Cellular
Hybrid/Multiple
Wi-Fi SSID (if applicable)
Active Network Ports/Services
Last Successful Patch/Update Date
Last Security Scan Date
Device Criticality Level (1=Low, 5=Critical)
Facility/Location
Department/Unit
Room Number
Primary Device Operator/Owner
Document the threat discovery details, vulnerability characteristics, and potential impact on patient safety and data security.
Vulnerability Discovery Timestamp
Discovery Method
Routine Vulnerability Scan
Anomaly Detection System
User/Staff Report
Vendor Security Advisory
Incident Response Team
Internal Audit
Third-Party Assessment
Other
Primary Vulnerability Type
Unauthorized Firmware Modification
Malware Infection
Configuration Weakness
Default/Weak Credentials
Unpatched Known CVE
Ransomware
Data Exfiltration
Denial of Service
Other
Probable Threat Vector
Network-Based Intrusion
Insider Threat
Supply Chain Compromise
Physical Device Access
USB/Removable Media
Wireless Exploitation
Web Interface Attack
Social Engineering
Unknown
Other
CVSS v3.1 Score (0.0 to 10.0)
Potential Patient Safety Impact
Does this vulnerability expose clinical patient data?
Does this involve PHI/PII data breach implications?
Detailed Description of Potential Patient Harm
Harm Severity Classification
Negligible (No clinical impact)
Minor (Temporary inconvenience)
Moderate (Temporary clinical impact)
Major (Permanent clinical impact)
Catastrophic (Patient death or severe harm)
Attack Sophistication Level
Automated/Opportunistic
Targeted with Low Skill
Targeted with High Skill
Advanced Persistent Threat (APT)
Unknown
Has forensic evidence been preserved?
Estimated Number of Similar Devices Potentially Affected
Has the device exhibited anomalous behavior?
Were network traffic anomalies observed?
Are device log files available for analysis?
Document immediate containment actions, patient safety measures, and operational continuity plans.
Current Device Operational Status
Fully Operational
Isolated but Operational
Quarantined/Offline
Emergency Shutdown
Unknown
Isolation Methods Implemented
Network Cable Physically Disconnected
VLAN Segregation
Firewall Rules Applied
Air-Gapped
Port Security Disabled
Wireless Radio Disabled
Access Control List (ACL)
Other
Isolation/Containment Timestamp
Is a patient currently dependent on this device?
Is an alternative device available for immediate use?
Estimated Clinical Impact Level
No Impact
Minor Delay (0-30 min)
Moderate Disruption (30 min-4 hours)
Critical Replacement Needed (4-24 hours)
Life-Threatening (Immediate action required)
Clinical Workflow Disruption Level (1=Minimal, 5=Severe)
Has a backup device been deployed?
Can device operate safely in offline/air-gapped mode?
Critical Safety Checks Completed Before Isolation
Was formal isolation approval obtained from clinical leadership?
Network Access Restoration Plan
Record all vendor interactions, patch verification activities, diagnostic procedures, and remediation actions performed.
Has the device manufacturer/vendor been officially notified?
Has vendor provided an initial response?
Is an official security patch or firmware update available?
Has the patch been tested in a lab environment?
Estimated Patch Deployment Timeline
Less than 24 hours
24-72 hours
3-7 days
1-2 weeks
More than 2 weeks
Unknown/Indeterminate
Diagnostic Actions Taken
Remediation Actions Performed
Was firmware integrity verification performed after remediation?
Is firmware rollback to previous version possible if needed?
Vendor Support Quality Rating (1=Poor, 5=Excellent)
Additional Security Controls Implemented
Enhanced Network Segmentation
Intrusion Detection System
Multi-Factor Authentication
Encryption of Data at Rest/Transit
Physical Security Controls
Application Whitelisting
Endpoint Detection & Response
Other
Has remediation validation testing been completed?
Has the device been returned to full clinical service?
Final authorization and risk acceptance documentation requiring sign-off from both Information Security and Biomedical Engineering leadership.
Executive Summary of Incident & Resolution
Has formal root cause analysis been completed?
Risk Acceptance Decision
Accept Risk (Device returned to service)
Mitigate Risk (Additional controls required)
Transfer Risk (Vendor/managed service)
Avoid Risk (Device remains offline/decommissioned)
CISO Review and Approval Completed
CISO Digital Signature
CISO Sign-Off Timestamp
Head of Biomedical Engineering Review and Approval Completed
Head of Biomedical Engineering Digital Signature
Biomedical Engineering Sign-Off Timestamp
Is executive escalation to C-Suite required?
Is regulatory reporting to external bodies required?
Have lessons learned been formally documented?
All Documentation Complete and Verified
Follow-up security audit scheduled?