The Joint Commission revised its Emergency Management standards in January 2024 to explicitly categorize cybersecurity incidents as emergencies requiring the same planning, testing, and documentation rigor as natural disasters or mass casualty events. For chief operating officers, compliance officers, and risk management leadership at accredited organizations, this creates immediate obligations without necessarily providing clear internal ownership or a method to measure adequacy.
The practical effect: if your organization has not formally integrated cybersecurity incident response into your Emergency Operations Plan with documented accountabilities, defined testing cycles, and executive oversight, you now have a compliance gap that affects accreditation standing.
Why This Matters to Hospital and Health System Leadership
Emergency management standards carry direct accreditation consequences. Unlike advisory guidance, these are surveyable requirements. Joint Commission reviewers will examine whether cybersecurity incidents are incorporated into your Emergency Operations Plan, whether you have conducted required exercises, and whether leadership roles are documented and understood.
The business exposure is organizational continuity. A cybersecurity incident that halts electronic health record access, disrupts diagnostic imaging, or forces diversion of ambulances has the same operational impact as a power failure or building evacuation. The updated standards recognize this equivalence and require equivalent preparation.
Many organizations already have elements of cybersecurity incident response in place—IT teams with runbooks, vendor support agreements, notification protocols. The regulatory shift is that these activities must now be elevated to the same governance structure, executive accountability, and testing discipline that applies to all emergency management functions.
What the January 2024 Revisions Require
The revised standards do not prescribe specific technologies or vendor selections. They establish obligations around planning, coordination, and documented capability:
- Cybersecurity incidents must be addressed in the organization's Emergency Operations Plan with the same formality as other hazard categories.
- The plan must identify leadership roles and decision authorities during a cybersecurity incident, including who has authority to make operational continuity decisions when systems are unavailable.
- The organization must conduct exercises that test cybersecurity incident response at intervals consistent with other emergency types, typically including at least one exercise annually.
- Documentation must demonstrate that relevant staff understand their roles, that communication pathways are defined, and that alternative procedures for clinical and administrative operations are established.
- The plan must address coordination with external entities, which may include law enforcement, regulators, business associates, and incident response resources.
The standards do not replace existing cybersecurity programs or contradict obligations under HIPAA, state breach notification laws, or other regulatory frameworks. They add an emergency management lens that requires integration, not duplication.
The Ownership Problem Most Organizations Face
Emergency management typically reports through operations or facilities leadership. Cybersecurity typically reports through information technology or information security. Compliance oversight often sits with legal or a dedicated compliance officer. The Joint Commission standards require these functions to converge around a unified incident response capability with clear executive accountability.
The question is not whether someone is responsible for cybersecurity, but whether anyone is responsible for translating technical response into executive decisions under emergency conditions. When ransomware halts patient registration, who decides whether to divert ambulances? When a business associate breach compromises scheduling systems, who owns the communication to patients, staff, and regulators?
Many organizations discover during tabletop exercises that roles are ambiguous, that escalation pathways are informal, and that no single leader can answer whether the organization is compliant with the standard's requirements. This is the accountability gap the revisions expose.
How This Relates to Incident Readiness and Response Planning
Incident readiness means having documented, tested processes that allow the organization to recognize, escalate, and manage a cybersecurity event without improvisation. Response planning translates technical containment activities into operational decisions that protect patients and preserve accreditation standing.
Under the revised Joint Commission standards, readiness includes:
- Written protocols that specify who is notified, in what sequence, when a potential cybersecurity incident is detected.
- Pre-defined criteria for escalating an incident to the Emergency Operations Center or activating the Incident Command System.
- Documented alternative procedures for clinical operations when electronic systems are unavailable, including paper-based workflows, manual order entry, and pharmaceutical dispensing.
- Communication templates for internal staff, patients, business associates, and regulators that can be executed under time pressure.
- Recovery priorities that reflect clinical risk rather than only technical complexity, ensuring that patient-facing systems are restored in an order that minimizes safety exposure.
Response planning is not an IT function. It is a governance function that requires translating technical events into business decisions, regulatory positions, and continuity trade-offs. That translation is a leadership capability, not a technical one.
What Adequate Ownership Looks Like
Adequate ownership means a single executive who can answer whether the organization is prepared for a cybersecurity emergency, who knows the current state of incident response capability, and who can demonstrate compliance with the Joint Commission standards to surveyors.
In organizations with a Chief Information Security Officer, that role may provide this ownership if it has sufficient authority and integration with emergency management. In organizations without dedicated security leadership, or where the CISO role is narrowly scoped to technical controls, the gap persists.
A [virtual CISO](/vciso/) engagement establishes this ownership by providing executive-level cybersecurity leadership that integrates with existing emergency management structures. The vCISO acts as the accountable leader for cybersecurity incident readiness, coordinates across IT, operations, and compliance, and delivers the documentation and testing evidence that Joint Commission surveyors will examine.
This is not a project. It is an ongoing governance function that requires someone who can make risk decisions, interpret regulatory obligations, and speak credibly to both technical staff and the board.
What Leadership Should Do Next
Start with three concrete actions:
First, confirm whether your current Emergency Operations Plan explicitly addresses cybersecurity incidents as a hazard category with the same documentation standard as other emergency types. If it does not, or if the documentation is vague, you have a surveyable gap.
Second, identify who in your organization can currently answer these questions without consultation: What is our process for escalating a cybersecurity incident to the Incident Command System? What are our documented alternative clinical workflows when the EHR is unavailable? Who has decision authority to activate those workflows? If no single person can answer all three, you lack adequate ownership.
Third, determine whether your most recent emergency management exercise included a cybersecurity scenario with documented participation from IT, clinical operations, legal, and executive leadership. If not, schedule one. The exercise will reveal gaps more precisely than any assessment.
These actions clarify where ownership exists and where it does not. Most compliance gaps are not technical. They are governance gaps—responsibilities that cross organizational boundaries without a clear owner who can make decisions and demonstrate preparedness to external reviewers.
When to Seek External Leadership
If your organization does not currently have a single executive who can demonstrate compliance with the Joint Commission's cybersecurity emergency management requirements, or if the responsibility is distributed across roles without clear accountability, that is the condition a vCISO engagement addresses.
Heights Consulting Group provides virtual CISO leadership for organizations that need executive accountability without building permanent headcount. The engagement establishes governance structure, integrates cybersecurity with emergency management, produces the documentation that accreditation requires, and gives the board and executive leadership a clear answer to the question: who owns this?
If you are uncertain whether your current structure meets the January 2024 requirements, or if recent exercises have revealed accountability gaps, a confidential consultation will clarify whether external leadership is the appropriate step. Reach out through the contact information on this site to schedule a conversation.
Sources
- Cybersecurity Framework | NIST , www.nist.gov
- Privacy and Security | Federal Trade Commission , www.ftc.gov
- Privacy Framework | NIST , www.nist.gov
Related service: Incident Readiness and Response Planning
A response plan that names decision makers, defines escalation and notification paths, and has been tested with the executives who would have to use it.