An EHR is only useful if you can reach it when you need it. Hardware failures, ransomware, internet outages, and natural disasters can all interrupt access to patient records. Backup and business continuity planning are about making sure a disruption is an inconvenience, not a catastrophe.
What HIPAA expects
The HIPAA Security Rule requires covered entities and business associates to have a contingency plan for responding to emergencies or other occurrences that damage systems containing electronic protected health information (ePHI). The contingency plan standard includes implementation specifications for a data backup plan, a disaster recovery plan, and an emergency mode operation plan. These are baseline expectations, not optional extras.
Cloud does not mean automatic safety
If your EHR is cloud-based, the vendor typically handles infrastructure backups — but you remain responsible for understanding what is backed up, how quickly you can recover, and what happens during an internet or vendor outage. Read the business associate agreement and service-level commitments, and ask direct questions about recovery time and recovery point objectives.
Building a practical plan
- Know your data: Identify where ePHI lives — EHR, billing system, imaging, scanned documents, email.
- Back up reliably: Maintain backups that are tested, recent, and stored separately from production, including an offline or otherwise isolated copy to resist ransomware.
- Test restores: A backup you have never restored is a guess. Periodically verify that you can actually recover data.
- Plan for downtime: Have paper forms and procedures so the practice can keep seeing patients safely when the EHR is unavailable.
- Document and train: Write the plan down, assign responsibilities, and rehearse it.
Downtime procedures
Decide in advance how you will register patients, document encounters, and order medications when the system is down, and how you will reconcile that information once systems return. Clear downtime procedures reduce errors and protect patient safety during the most stressful moments. A simple downtime kit — printed schedules generated at the start of each day, paper encounter forms, and a contact list — can keep a practice functioning through a multi-hour outage.
Ransomware: a modern reality
Ransomware attacks, which encrypt systems and demand payment, have become a serious threat to health care organizations of all sizes. They make the case for backups especially clearly: an attacker who encrypts your production data cannot extort you as easily if you hold clean, isolated backups you can restore. This is why security guidance emphasizes maintaining backups that are offline or otherwise segmented from the network, so they cannot be encrypted along with everything else.
Recovery objectives
Two questions shape any continuity plan. The recovery time objective (RTO) asks how quickly you must be back online. The recovery point objective (RPO) asks how much recent data you can afford to lose — minutes, hours, or a day. For a cloud EHR, ask the vendor about their RTO and RPO commitments; for on-premise systems, design your backup frequency and recovery procedures to meet the objectives your practice can tolerate.
Bottom line
Backup and continuity planning are both a compliance requirement and basic operational hygiene. Build the plan, test it, and revisit it regularly — especially after any change to your systems or vendors. Knowing your RTO and RPO, holding isolated backups, and rehearsing downtime procedures turn a potential disaster into a manageable interruption.