It is 8:40 on a Tuesday morning. The waiting room has eleven people in it. The front desk cannot pull up the schedule, the medical assistants cannot open a chart, and the phone is ringing. Nobody knows yet whether this is the internet, the EHR vendor, or something worse.

What happens in the next twenty minutes is almost entirely determined by decisions made months earlier. Not by how good the IT is — by whether somebody printed the schedule, whether there is a binder, and whether the person at the front desk knows she is allowed to keep checking patients in.

Continuity planning for a clinic is not glamorous. It is forms, binders, and a phone tree. But it is the difference between a practice that loses ninety minutes and one that sends a day of patients home.

Availability Is a HIPAA Goal, Not Just an IT Preference

Most conversations about HIPAA are about confidentiality — keeping information from the wrong people. But the Security Rule protects the confidentiality, integrity, and availability of electronic protected health information. Availability means the information is there when a clinician needs it to treat a patient. An outage that puts a chart out of reach is a Security Rule concern, not merely an inconvenience.

That is why the rule includes a contingency plan standard. Three of its implementation specifications are required: a data backup plan, a disaster recovery plan, and an emergency mode operation plan — procedures that let you continue critical business processes and keep protecting ePHI while running in crisis mode. Two more are addressable, which does not mean optional. You implement them, or you document why they are not reasonable and appropriate for your practice and put an equivalent safeguard in place instead. Those two are testing and revision procedures, and an applications and data criticality analysis that ranks what has to come back first.

Two practical notes. Business associates carry the same Security Rule obligations as covered entities, so your EHR host, your billing company, and your IT provider each need their own plans — ask to see what they say about downtime and recovery. And the criticality analysis is the item practices skip and later wish they had: it is the document that answers “what do we bring back first” before anyone is under pressure. If you want the wider picture, our HIPAA IT compliance checklist puts contingency planning alongside the other safeguards.

Decide What “Down” Means Before It Happens

Three very different failures look identical from the front desk, and the response to each is different. Write down how to tell them apart:

That third one carries obligations the other two do not. Ransomware involving ePHI is presumed to be a breach unless a documented four-factor risk assessment demonstrates a low probability that the information was compromised, and the notification clock starts running. Affected individuals must be notified within 60 days. Every breach goes to OCR: those affecting 500 or more individuals within 60 days, smaller ones in an annual submission within 60 days of year end. Breaches affecting more than 500 residents of a single state also require media notice. We wrote separately about what healthcare organizations face after a breach.

The Downtime Packet

Paper fallback fails when it is invented on the day. It works when it is prepared, printed, and stored where the people who need it can reach it without a computer.

What belongs in the binder, one copy per station:

Two things make the binder actually usable. First, print tomorrow’s schedule at the end of every day — a single sheet with appointment times, patient names, date of birth, and visit reason. It costs nothing and it is the difference between a functioning morning and a guessing game. Second, keep a read-only copy of the day’s critical data if your EHR supports a downtime viewer or scheduled export: active problem lists, medications, and allergies for scheduled patients. Ask your vendor whether they offer one and how it is kept current.

Keeping Patients Moving

The instinct is to stop. Usually you should not. Assign the roles in advance so nobody waits to be told:

Remember the phones. If your phone system runs over the same internet connection as everything else, it goes down with it. Know in advance where calls forward — usually to a cell phone held by a named person — and make sure someone can actually make that change without the IT portal.

The Paper Itself Is Protected Health Information

The moment a clinician writes on a downtime form, that sheet is PHI. The Privacy Rule applies to it on paper exactly as it would on a screen, and this is where well-run practices slip.

Handle it like a chart, not like scratch paper. Forms are numbered and accounted for. They do not sit face-up on a counter or in an open bin at the nurses’ station. They go into a locked location at the end of each session. When they are handed to whoever is entering them, that hand-off is logged — sheet numbers, who took them, when. Anything discarded goes to shred, never to a wastebasket.

The problem practices actually run into is not that they used paper. It is that nobody counted it, so weeks later they cannot demonstrate where every sheet went. A numbered form and a two-column log solve that entirely.

Reconciling Back Into the EHR

Systems coming back is the midpoint, not the end. The backlog is real work and it competes with a schedule that is already behind.

Set a target and staff it — for example, every downtime encounter entered within 72 hours of restoration — and assign named people rather than assuming it will happen in gaps between patients. Track each numbered form until it is entered and verified, and have a second person spot-check a sample against the paper. Enter with the correct date and time of service rather than the date of entry, and follow your EHR’s late-entry convention so the record is honest about when the note was written; that convention matters for billing and for anyone reading the chart later.

Then work outward. Orders written on paper need to be entered so results come back to the right place, and someone should confirm nothing was dropped at the lab. Prescriptions written by hand need to be reconciled against the medication list. Charges captured on paper need to reach billing, because the most common financial casualty of a downtime day is revenue that was never coded. Once everything is in, retain the paper according to your record retention policy rather than shredding it the moment entry is done — the original is your evidence if a question arises about what was recorded.

Test It Before You Need It

A plan nobody has walked through is a document, not a capability. Twice a year, take ninety minutes and run the downtime drill — this is separate from the annual incident-response tabletop, and it exercises different people. Tell the staff the EHR is unavailable, hand out the binders, and have them work a simulated half hour on paper. You will find the same three things almost everyone finds — the printed schedule was not printed, nobody knows the vendor account number, and the forms are three revisions out of date. Fix those, note the date you tested, and keep that documentation. Testing and revision is exactly what the contingency plan standard contemplates, and it is also the thing that makes the real event boring.

Continuity for a clinic is unglamorous and it is cheap. A binder, a printed schedule, a numbered form, and a phone number on paper will carry you through most of what actually happens. The rest — recovery times, backup design, what comes back first — is worth a harder look, and our list of what most disaster recovery plans are missing is a reasonable place to start.

Related Questions

Does HIPAA require a downtime plan?

The Security Rule protects the confidentiality, integrity, and availability of electronic protected health information, and availability is the goal most people forget. Its contingency plan standard requires a data backup plan, a disaster recovery plan, and an emergency mode operation plan that lets you keep protecting ePHI while operating in crisis mode. Testing and revision procedures and a criticality analysis of your applications and data are addressable, which does not mean optional. You implement them, or you document why they are not reasonable and appropriate for your practice and put an equivalent safeguard in place instead. Business associates carry the same obligations as covered entities, so ask your EHR host and your IT provider what their plans say.

What happens to patient information written on paper during an outage?

It is protected health information the moment it is written, and the Privacy Rule applies to it in paper form exactly as it would on a screen. That means downtime forms are not left face-up on a counter, they are numbered and tracked, they are stored in a locked location until they are entered, and they are logged out to the person entering them. Practices get into trouble not because they used paper but because the paper was never counted, so nobody could prove afterwards where every sheet ended up.

Should we keep seeing patients if the EHR is unavailable?

That is a clinical decision, not an IT one, and it should be made in advance by the physicians rather than in the hallway on the day. Most practices can safely continue routine visits on paper for a limited period, and most decide to defer anything that depends on information they cannot see, such as a first visit with no chart, a medication change without a current list, or a procedure that requires prior imaging. Write the criteria down, name who makes the call, and set a time of day by which the decision to reschedule the afternoon gets made.

How long should reconciling paper charts back into the EHR take?

Plan for it to take longer than the outage did, and staff it accordingly. A half day of paper visits in a busy clinic is hours of data entry on top of a normal schedule, and it competes directly with the backlog the outage created. Set a target, such as everything entered within 72 hours of systems returning, assign named people to it rather than expecting it to happen in gaps, and track each downtime form by its number until it is entered and verified.

Build a Downtime Plan Your Staff Can Actually Follow

We support hospices, clinics, and medical practices across the Central Valley and Sacramento region, and we help them write and rehearse the unglamorous parts — the binder, the criticality analysis, the phone failover, and the restore test behind it all. If your current plan is a document nobody has opened, let’s walk through it together.

Talk to Us About Healthcare IT (888) 735-7701