This section captures critical identification data for all affected medical devices. Complete with maximum precision to enable rapid response and asset tracking. Time is critical - provide information as accurately as possible under emergency conditions.
Is this incident affecting a single device or multiple devices?
Affected Device Inventory & Network Identifiers
Device Manufacturer | Device Model | Serial Number | Hospital Asset ID | Primary IP Address | MAC Address | Hostname | Clinical Ward/Department | Room Number/Location | Device Criticality | Active on Patient? | |
|---|---|---|---|---|---|---|---|---|---|---|---|
Standard Care | |||||||||||
Device primary network connection type
Wired Ethernet
WiFi/Wireless
Both Wired & Wireless
Bluetooth
Proprietary RF
Unknown
Network topology description - how is this device connected? (e.g., direct VLAN, wireless, via middleware server)
If device is active on patient(s), provide anonymized patient identifier(s) and clinical context
When was the malware infection first detected on this device?
Who initially detected the malware infection?
Device primary clinical function
Comprehensive threat assessment is crucial for determining patient safety exposure and regulatory reporting obligations. Provide detailed analysis of the malware characteristics and potential clinical impact.
Malware detection method
Endpoint Detection & Response (EDR) Alert
Network Intrusion Detection System
Antivirus Software
Manual Discovery by Staff
Vendor Notification
Patient Safety Event Triggered Investigation
Other
Describe the specific malware identified (name, hash, behavior observed)
Has the malware demonstrated capability to affect device clinical functionality?
Is there evidence of data exfiltration or unauthorized access to patient health information (PHI)?
Patient Safety Risk Assessment Matrix - Rate each dimension based on current understanding
Minimal | Low | Moderate | High | Critical | |
|---|---|---|---|---|---|
Direct Patient Harm Potential | |||||
Indirect Clinical Decision Impact | |||||
Data Integrity Risk | |||||
Device Availability Impact | |||||
Propagation Risk to Other Devices |
Does this incident meet criteria for regulatory notification (e.g., FDA, HIPAA, CE Marking authorities)?
Describe the suspected initial infection vector and propagation path within the network
Overall Incident Severity Rating (1=Minor, 5=Catastrophic)
Is there any threat actor attribution or indication of targeted attack?
Threat intelligence sources consulted and key findings
Document all network isolation actions taken to prevent malware propagation. This section serves as evidence of proper containment procedures and supports forensic investigation.
Has the affected device been physically disconnected from the network?
Network isolation methods implemented (select all applicable)
Physical Cable Disconnection
Switch Port Shutdown
VLAN Segregation
Firewall Rule Blocking
Access Control List (ACL) Implementation
Wireless SSID Disconnection
Network Access Control (NAC) Quarantine
Other
Provide specific technical details of VLAN containment and firewall rules implemented
Has network traffic capture been initiated for forensic analysis?
Have neighboring devices on the same network segment been scanned for infection indicators?
Containment Action Log - Document each step with timestamp and responsible personnel
Action Timestamp | Action Taken | Performed By | Verification Method | Action Verified? | |
|---|---|---|---|---|---|
1/20/2025, 2:30 PM | Physical network cable disconnected from device | J.Smith, Biomed Eng | Visual inspection and switch log review | Yes | |
1/20/2025, 2:35 PM | Device moved to quarantine VLAN 999 | T.Jones, IT Security | Switch configuration verification | Yes | |
Is the device completely isolated from all production networks including wireless?
Has a forensic image of the device storage been created before remediation?
Have all containment actions been tested and verified effective?
Ensure uninterrupted patient care through proper backup equipment deployment and clinical workflow adjustments. Document all measures taken to maintain clinical service levels.
Are there patients currently dependent on the affected device for life-support or critical care?
Backup Equipment Deployment Log
Original Device Asset ID | Backup Device Asset ID | Backup Device Location | Deployment Time | Deployed By | Clinical Validation Completed? | |
|---|---|---|---|---|---|---|
Has the clinical engineering team verified backup device calibration and safety before deployment?
Impact on clinical service delivery
No Impact - Backup Available Immediately
Minor Delay (<15 minutes)
Moderate Delay (15-60 minutes)
Significant Delay (1-4 hours)
Service Interruption (>4 hours)
Complete Service Outage
Have clinical staff been notified of device unavailability and alternative procedures?
Is manual backup procedure required due to lack of available backup devices?
Describe any temporary workflow modifications implemented to maintain patient care standards
Has patient notification been required due to potential data breach or care disruption?
Are there supply chain implications affecting backup equipment availability?
Has additional staff training been required for backup equipment or manual procedures?
Final verification and authorization section. Both Biomedical Engineering and IT Security leadership must review all incident details, containment actions, and patient safety measures before sign-off. This form serves as official incident record.
Executive Summary of Incident (for leadership review)
Has all evidence been preserved for forensic analysis in accordance with incident response policy?
Are there any objections to the containment actions taken from clinical leadership?
Has the device manufacturer been notified of the security incident?
Is there a formal risk acceptance for maintaining the device in quarantine state?
Proposed device reconnection date/time (if applicable)
Reconnection prerequisites and security hardening requirements
Head of Biomedical Engineering - Incident Review & Approval
Biomedical Engineering Sign-off Timestamp
Hospital Chief Information Security Officer (CISO) - Security Review & Approval
CISO Sign-off Timestamp
Does this incident require escalation to hospital executive leadership or board notification?
Has cyber insurance carrier been notified of the incident?
Are there media or public relations considerations requiring communications department involvement?
Lessons Learned & Process Improvement Recommendations
Has this incident been entered into the official hospital risk management system?