Business Continuity for EHR Downtime: A 72-Hour Plan
Continuity is not recovery. Recovery brings the system back; continuity is how the hospital keeps treating patients for three days while it is gone.
GuardsArm Team
Security Experts
Disaster recovery answers "how do we get the EHR back". Business continuity answers a different and more urgent question: how does this hospital treat patients for the next three days without it. Ransomware incidents in healthcare routinely run past 72 hours, and the plans that hold up are the ones written for days rather than hours.
The three phases, and what each needs
The declaration matters more than it sounds. Wards behave very differently when someone with authority states "we are in downtime procedures" than when they spend four hours wondering whether the system is about to come back. Name who can declare it, and let them do so early.
The read-only shadow record
The single most valuable continuity investment for a hospital is a read-only copy of the clinical record that survives the EHR being unavailable. Often called a downtime or business-continuity viewer.
It needs to be:
- Independent of the primary EHR infrastructure — separate compute, separate storage, ideally a separate network segment
- Refreshed frequently — hourly or better, so the data is clinically useful
- Accessible without the primary identity system, because the directory may be part of the outage
- Available at the point of care, not one terminal in IT
- Tested regularly, because a stale or unreachable viewer is worse than none
Knowing a patient's allergies, medications and recent results is the difference between safe care on paper and guesswork.
Paper workflows that actually function
Downtime forms are not a formality. What separates working paper process from chaos:
| Element | Requirement |
|---|---|
| Forms available | Pre-printed, stocked on every unit, checked quarterly — not a PDF on the intranet you cannot reach |
| Patient identification | A way to generate identifiers offline that will reconcile later |
| Order communication | Defined runner or phone process for labs, imaging, pharmacy |
| Result delivery | How a critical result reaches a clinician without the EHR |
| Medication administration | Paper MAR, with a reconciliation plan |
| Documentation standard | What must be captured for the record and for billing |
The two that fail most often are stocked forms — because the store ran down and nobody noticed — and critical result delivery, because the normal path is an EHR alert.
Staffing the manual process
Paper is slower. A ward running on downtime procedures needs more people, not the same people working harder. Plan for:
- Runners to move orders and results physically
- Scribes so clinicians are not transcribing
- A downtime coordinator per shift per area, owning the process
- Extended shifts or additional staff, which has a cost that should be in the plan
- Rest rotation, because a 72-hour event outlasts goodwill
Backfill: the phase nobody plans
When systems return, everything recorded on paper must enter the record. For a three-day outage in a mid-sized hospital this is thousands of documents, and it is the longest phase of the whole incident.
Decide in advance:
- What gets entered — everything, or a clinically defined subset
- Who enters it — clinical staff, or temporary data entry with clinical review
- In what order — active inpatients first, almost always
- How it is marked — retrospective entries must be identifiable as such in the audit trail
- Billing reconstruction, which has its own timeline and revenue consequence
Underestimating backfill is why hospitals are still recovering operationally weeks after the systems were technically restored.
Where to start
Find out whether your downtime viewer shares infrastructure with the EHR. That single question, answered honestly, tells you whether you have a continuity capability or a diagram.
For the technical side, see disaster recovery for hospitals, and for whether the backups will be there, backup testing.
GuardsArm builds and exercises clinical continuity plans, including downtime viewer dependency review and backfill planning. Book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on “Business Continuity for EHR Downtime: A 72-Hour Plan”
Talk to the GuardsArm team about how these services apply to your environment.


