Back to Blog
Business Continuity
10 min read

Business Continuity for EHR Downtime: A 72-Hour Plan

Continuity is not recovery. Recovery brings the system back; continuity is how the hospital keeps treating patients for three days while it is gone.

GuardsArm Team

Security Experts

December 21, 2025

EHR downtime continuity

Disaster recovery answers "how do we get the EHR back". Business continuity answers a different and more urgent question: how does this hospital treat patients for the next three days without it. Ransomware incidents in healthcare routinely run past 72 hours, and the plans that hold up are the ones written for days rather than hours.

Days, not hours
Healthcare ransomware outages are frequently measured in weeks
Care continues
Patients arrive regardless of system state — continuity is not optional
Backfill is the tail
Everything done on paper must eventually enter the record

The three phases, and what each needs

The four phases of an extended EHR outageThe four phases of an extended EHR outage1Hours 0-4: Recognise and declareImmediateConfirm scope, declare downtime, activate procedures. The declaration itself is the control.2Hours 4-24: Stabilise on paperDay 1Downtime forms in use, read-only record accessed, orders flowing manually.3Hours 24-72: SustainDays 2-3Staffing for manual process, supply of forms, results reconciliation, external comms.4Post-restore: BackfillWeeksPaper into the record, orders reconciled, billing rebuilt. Longest phase by far.
Most plans cover the first phase in detail and the last one not at all.

The declaration matters more than it sounds. Wards behave very differently when someone with authority states "we are in downtime procedures" than when they spend four hours wondering whether the system is about to come back. Name who can declare it, and let them do so early.


The read-only shadow record

The single most valuable continuity investment for a hospital is a read-only copy of the clinical record that survives the EHR being unavailable. Often called a downtime or business-continuity viewer.

It needs to be:

  • Independent of the primary EHR infrastructure — separate compute, separate storage, ideally a separate network segment
  • Refreshed frequently — hourly or better, so the data is clinically useful
  • Accessible without the primary identity system, because the directory may be part of the outage
  • Available at the point of care, not one terminal in IT
  • Tested regularly, because a stale or unreachable viewer is worse than none

Knowing a patient's allergies, medications and recent results is the difference between safe care on paper and guesswork.

Test the viewer during the drill, not after
The recurring finding is a downtime viewer that depends on the same domain controllers, the same storage array or the same VMware cluster as the EHR. It works perfectly in a test and is unavailable in the one scenario it exists for.

Paper workflows that actually function

Downtime forms are not a formality. What separates working paper process from chaos:

ElementRequirement
Forms availablePre-printed, stocked on every unit, checked quarterly — not a PDF on the intranet you cannot reach
Patient identificationA way to generate identifiers offline that will reconcile later
Order communicationDefined runner or phone process for labs, imaging, pharmacy
Result deliveryHow a critical result reaches a clinician without the EHR
Medication administrationPaper MAR, with a reconciliation plan
Documentation standardWhat must be captured for the record and for billing

The two that fail most often are stocked forms — because the store ran down and nobody noticed — and critical result delivery, because the normal path is an EHR alert.


Staffing the manual process

Paper is slower. A ward running on downtime procedures needs more people, not the same people working harder. Plan for:

  • Runners to move orders and results physically
  • Scribes so clinicians are not transcribing
  • A downtime coordinator per shift per area, owning the process
  • Extended shifts or additional staff, which has a cost that should be in the plan
  • Rest rotation, because a 72-hour event outlasts goodwill

Backfill: the phase nobody plans

When systems return, everything recorded on paper must enter the record. For a three-day outage in a mid-sized hospital this is thousands of documents, and it is the longest phase of the whole incident.

Decide in advance:

  • What gets entered — everything, or a clinically defined subset
  • Who enters it — clinical staff, or temporary data entry with clinical review
  • In what order — active inpatients first, almost always
  • How it is marked — retrospective entries must be identifiable as such in the audit trail
  • Billing reconstruction, which has its own timeline and revenue consequence

Underestimating backfill is why hospitals are still recovering operationally weeks after the systems were technically restored.


Where to start

Find out whether your downtime viewer shares infrastructure with the EHR. That single question, answered honestly, tells you whether you have a continuity capability or a diagram.

For the technical side, see disaster recovery for hospitals, and for whether the backups will be there, backup testing.

GuardsArm builds and exercises clinical continuity plans, including downtime viewer dependency review and backfill planning. Book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on “Business Continuity for EHR Downtime: A 72-Hour Plan”

Talk to the GuardsArm team about how these services apply to your environment.