Back to Columns
Healthcare Security14 min read

Incident Response Planning for Healthcare Providers: Who Decides What, and How Care Continues

September 14, 2026

Incident Response Planning for Healthcare Providers: Who Decides What, and How Care Continues
Share this article

When the electronic health record will not open one morning, who decides to take the system offline? Who calls the public health centre and the regional referral hospital, who decides to stop outpatient reception, and who answers the phone when a reporter calls? A surprising number of providers, of every size, cannot answer these questions immediately.

Security discussions gravitate toward the perimeter — how to keep attackers out. But if you have not decided how the organisation moves once the perimeter fails, the disruption caused by confusion outlasts the incident itself. What published cases have in common is that the gap in decision-making and the breakdown of communication stretch the timeline far more than the technical recovery does.

With Japan's FY2026 fee revision, this moved from good practice to a billing requirement. The newly created coordinated electronic clinical information add-on states, at its higher tier, that a business continuity plan for cyberattacks must be developed and drilled.

This article is the blueprint for building an incident response plan from scratch, or rebuilding one that has become a shelf document.

Disclaimer: This article is general information. The authoritative sources are the Ministry of Health, Labour and Welfare's notices and Q&A on reimbursement requirements, and the text of the Guidelines for the Safe Management of Medical Information Systems. Base actual decisions on those.

Why a Plan Is Now Required

The FY2026 revision abolished and merged two earlier add-ons into a new coordinated electronic clinical information add-on, folding cybersecurity evaluation into it.

TierPointsRequirements
Tier 1160The common requirements below, plus backups by multiple methods (some held offline) and a cyberattack BCP that has been developed and drilled
Tier 280Conformance with the Guidelines for the Safe Management of Medical Information Systems, and a dedicated medical information system safety manager

The point is not the difference in reimbursement but the fact that the system now evaluates planning and drills. The question is no longer what you bought but whether the organisation can move. See Key Points of the FY2026 Fee Revision and The Medical Information Safety Manager Role. For the guideline background, see The Three-Ministry Guidelines.

What the Plan Must Contain

A plan is not judged by thickness. The test is whether a night-shift lead can open it at 2am and act. At minimum, six things must be written down.

ItemWhat to writeCommon omission
Scope and activation criteriaWhat counts as an incident, and who declares activation"In serious cases" with no criteria
Roles and authorityWho can decide what, and the order of deputiesNo deputy order; everything stalls without the director
CommunicationInternal and external contacts, and the order to use themThe contact list exists only inside the affected system
First responseWhat to do in the first hour, and what not to do"Respond promptly" and nothing more
Clinical continuityPaper fallback and clinical prioritiesNo printed forms exist
Records and reportingWhat to record, and where and when to reportNo list of reporting destinations

First response is covered in First Response to Ransomware, continuity in A BCP for Cyberattacks, and reporting duties in Reporting a Personal Data Breach.

Write activation criteria as observable events. "The same file extension change observed on multiple endpoints" or "no staff member can log in to the core system" is the granularity a duty officer can act on without hesitation.

Who Decides What

Response is delayed less often by a lack of technical skill than by nobody knowing who decides. For each decision, name a first-line decision-maker and a final approver.

DecisionFirst lineFinal approverTarget timing
Declaring an incidentDuty lead / IT staffMedical information safety managerWithin 30 min of detection
Disconnecting from the networkIT staffSafety manager (design for after-the-fact reporting)Within 1 hour of detection
Restricting admissions and outpatient intakeDepartment headHospital directorWithin 2 hours of activation
Requesting outside help (specialist firms, authorities)Safety managerHospital directorSame day
Public disclosure and press handlingCommunications leadDirector / board chairAfter facts are confirmed
Reporting to the Personal Information Protection CommissionData protection leadHospital directorWithin the statutory window

Delegating the disconnection decision downward matters most in practice. Waiting for approval lets damage spread; disconnecting wrongly stops clinical care. Pre-authorising staff to disconnect under stated conditions, with reporting afterwards, is the workable design.

How to assign these roles and constitute a committee is covered in Building a Security Governance Structure.

Build Communication on the Assumption It Fails

A recurring failure in published cases is that the contact list lived only inside the system that was encrypted. Intranet portals, shared folders, notes in the EHR — all lost at once.

Design communication in three layers.

  1. A paper call tree — staff, key vendors, the public health centre, police, partner hospitals. Held under lock in more than one location
  2. Channels that do not depend on the hospital network — mobile phones or a separate messaging route, tested in peacetime
  3. A single point of contact — enquiries, press, and patient questions routed to one place so accounts do not diverge

For external contacts, record the contractual number and the number that actually answers separately. A maintenance contract's main line frequently goes unanswered at night. List out-of-hours procedures and contractual response times alongside. See Writing SLAs and Demarcating Responsibility.

Keeping Care Going

The purpose of the plan is not to fix the system but to keep treating patients. This is where it resembles a disaster BCP — and where it differs, because after a cyberattack the time to recovery cannot be estimated.

Include:

  • Clinical priorities — emergency, surgery, dialysis, obstetrics: identify what cannot stop
  • Paper forms — prescriptions, orders, test requests, consent. Printed and stored. Files alone are useless
  • The minimum information you must still be able to read — inpatient list, allergies and contraindications, the day's surgical and test schedule
  • Reconciliation after recovery — how paper records get back into the EHR. Skipping this creates a second wave of disruption

Knowing how many days you can run on paper is what separates a real plan from a document. Three days and two weeks imply very different stockpiles and very different investment decisions. See A BCP for Cyberattacks and Backup Design: the 3-2-1 Rule.

Keeping the Plan Usable

Plans decay from the day they are written: staff rotate, systems are replaced. Three maintenance activities are the minimum.

ActivityHow to set frequencyRecords to keep
Updating the call treeTie it to staff rotation datesUpdate date, distribution list
Tabletop walkthroughOn revision and on structural changeScenario, participants, issues raised
Live drill of degraded operationBuilt into the annual planRecord, elapsed times, improvements
Plan reviewAfter drills and after real incidentsRevision history

The value of a drill is discovering what you could not do. A drill that runs smoothly was probably too easy. Add constraints — the approver is unreachable, the call tree is unavailable — and the gaps appear.

See Designing Staff Training and Drills and Phishing Simulations. For reconciling your plan against the checklist MHLW published on 14 May 2025, see How to Use the MHLW Security Checklist.

Conclusion

  1. The FY2026 coordinated electronic clinical information add-on makes a drilled cyberattack BCP a tier-1 requirement. Planning is now a billing condition
  2. The plan's skeleton is six items: scope and activation, roles and authority, communication, first response, clinical continuity, records and reporting
  3. Separate first-line decision-makers from final approvers for each decision, and pre-authorise disconnection
  4. Keep contact lists outside the affected systems — on paper, in more than one place
  5. Continuity planning is only real once you know how many days you can run on paper
  6. Drills exist to surface what you could not do; a smooth drill was under-loaded

Building the skeleton is usually within reach in-house; writing decision criteria at a usable granularity and designing drill scenarios is where teams stall without prior experience. Pottech works on the design and operation of medical information systems and advises on governance and guideline compliance. If going it alone is difficult, contact us. For the supplier side of the equation, What Is an ISMS (ISO/IEC 27001)? is a useful companion.

References and Sources

Note: reimbursement requirements are given concrete form by notices and Q&A and are subject to revision. Confirm the current text with MHLW publications.

Share this article

Related Articles

Healthcare Security

Access Control and Privileged ID Management: What Is Realistic in a Hospital

Role-based permissions, least privilege, offboarding and transfer reviews, vendor maintenance accounts, and what to do where shared IDs genuinely cannot be eliminated. Access design that actually limits blast radius within the constraints of clinical work.

September 14, 2026
Healthcare Security

Antivirus and EDR: What a Hospital Should Decide Before Buying

How EDR differs from conventional antivirus, why it is not a product that protects you simply by being installed, how to choose an operating model for the alerts it produces, what to do about devices it cannot be installed on, and what to settle before you buy.

September 14, 2026
Healthcare Security

Logging and Audit Trails: Getting Past 'We Collect It but Nobody Looks'

What to log, how long to retain it, and the real problem — logs collected but never read. Which logs actually matter during an incident, and how to make review a sustainable routine in a hospital with limited staff.

September 14, 2026
Healthcare Security

Backup Design for Hospitals: The 3-2-1 Rule and the Tier 1 Requirement

Japan's FY2026 revision makes multi-method backup with part of it held offline a tier 1 requirement. We cover the three methods accepted as meeting it — external media, automated transfer to a permanently detached NAS, and a logically separated area within a cloud service — plus generation management and why an untested backup does not count.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.