EMStool LLC — Cadence EMS Scheduler

Incident Response Runbook

Document #: IRP-2026-01 Version: 1.0 Effective: June 29, 2026 Owner: Jacob Russell, Security Officer
This runbook establishes the procedures EMStool LLC will follow to detect, contain, investigate, eradicate, recover from, and learn from security incidents affecting Cadence and related systems.

1. Purpose and Scope

This runbook applies to all systems operated by EMStool LLC including Cadence customer tenants, the emstool.com web properties, and supporting infrastructure. A security incident is any event that compromises or threatens the confidentiality, integrity, or availability of Cadence systems or the PHI and PII they contain.

2. Severity Classification

SeverityDefinitionResponse TimeNotification
CriticalActive breach of PHI; ransomware; full system compromiseImmediate (within 1 hour)All customers + HHS within 60 days
HighAttempted breach; privilege escalation; data exfiltration suspectedWithin 4 hoursAffected customers within 72 hours
MediumUnauthorized access attempt; service degradation; malware detectedWithin 24 hoursInternal log + assess notification need
LowPolicy violation; suspicious activity; failed auth spikeWithin 72 hoursInternal documentation

3. Incident Response Phases

Phase 1: Identification

Phase 2: Containment

Phase 3: Eradication

Phase 4: Recovery

Phase 5: Post-Incident Review

4. Communication Plan

AudienceTriggerTimelineChannel
Internal teamAny incidentImmediatelyDirect communication
Affected customersHigh or Critical incidentWithin 72 hoursEmail to account admins
HHS (HIPAA breach)PHI breach >500 individualsWithin 60 daysHHS breach portal
Affected individualsPHI breach confirmedWithout unreasonable delay, no later than 60 daysWritten notice per HIPAA

5. Key Contacts and Resources

6. Evidence Preservation Checklist

Security Officer Signature
Jacob Russell — Security Officer, EMStool LLC
Date Reviewed
June 29, 2026