Meridian Health Network
INCIDENT COMMAND SIMULATION
Ransom Deadline
72:00:00
Ransomware Negotiation Room
You are the Incident Commander.
Meridian Health Network is a regional hospital system serving roughly 40,000 patients across six clinics. Three hours ago, the Security Operations Center flagged unusual encryption activity across the scheduling and billing servers. IT has now confirmed it: this is a ransomware attack, and it's live.
Your role: You lead the incident response. Legal, Finance, IT, and your cyber insurance carrier are waiting on your call.
What's at stake: Every decision you make moves two things you'll track live on the right side of your screen —
Financial Damage — ransom costs, downtime, recovery, regulatory fines
Reputational Damage — patient trust, media exposure, regulatory scrutiny
Structure: You'll move through two major decision points as the incident unfolds in real time, then receive a full incident debrief on how your choices played out.
00:00 — Detection
The note has surfaced on every screen in the billing department.
SYSTEM MESSAGE — READ_ME.txt
SOC Status
CONFIRMED 14 of 60 servers encrypted, including scheduling and billing
CONFIRMED 3 on-site backup snapshots also encrypted or deleted
UNCONFIRMED Off-site immutable backup from 6 hours ago — integrity check in progress
Decision Point 1 — Initial Response Strategy
Legal, Finance, and your insurance carrier are on the call. What's your call?
Choose the strategy that sets the tone for the next 72 hours.
6 Hours Later
Decision Point 2 — Disclosure
The exfiltration claim just became real.
The attacker has posted a sample of 200 real patient records — names, dates of birth, diagnosis codes — to a public leak site as proof of the larger theft. Legal counsel needs a decision on public disclosure before the story breaks somewhere you don't control.
72 Hours Later — Incident Debrief
Here's how command decisions shaped the outcome.
Decision Log
Incident Command Takeaways
Backups are only as good as their immutability. If an attacker can reach and encrypt your backups, they aren't a recovery plan — they're another target.
Paying a ransom carries legal exposure beyond the payment itself. U.S. organizations must screen for OFAC sanctions risk before transacting with a threat actor, even under pressure.
Breach notification timelines are not optional. HIPAA generally requires notification within 60 days of discovery — "waiting for certainty" has a legal clock attached to it.
The negotiation itself is a data point for the attacker. A willingness to talk, even to stall, can be read as a willingness to pay.
Reputational damage is driven less by the breach than by how it's handled. Speed and transparency of disclosure consistently move the outcome more than the incident's technical severity.