Every practice will lose access to its EHR at some point. The question is whether the front desk knows what to do in the first ten minutes or finds out by improvising. A written downtime plan is the difference. HIPAA expects you to have one, cyber insurers ask about it on the application, and it becomes the most useful document in the building when a Tuesday morning goes wrong. Here is what a workable plan actually includes, followed by a template outline you can fill in.
Why the plan needs to be written down
Downtime comes in more forms than most practices plan for:
- Planned downtime. Vendor upgrades, server maintenance, migrations. You know the window in advance and can staff for it.
- Unplanned local outage. Your server, your switch, your workstation image, your building's power. The EHR may be fine somewhere else, but not for you.
- Vendor or cloud outage. The hosted EHR itself is down. Nothing you do locally fixes it. You wait, and you need to keep seeing patients while you wait.
- Internet outage. Cloud EHR is up, but your circuit is not. This is the most common one for practices with a single ISP.
- Security incident. Ransomware or a compromised account. Here downtime is deliberate: systems are taken offline on purpose, and the outage may last days.
Each has a different cause and recovery, but the clinical and front-desk response is nearly identical. That is the value of a single written procedure. Staff do not need to know why the EHR is gone. They need to know what to pick up and who to call. And the person who "knows how we handled it last time" eventually leaves. The plan does not.
The HIPAA connection
The HIPAA Security Rule requires a contingency plan with several named components: a data backup plan, a disaster recovery plan, an emergency mode operation plan, and procedures for testing and revising those plans. The emergency mode operation plan is the part that says how you continue to protect and access ePHI while operating in a degraded state. Your EHR downtime procedure is that plan, or the core of it.
This matters in two practical ways. If you have done a HIPAA security risk assessment, the downtime plan is one of the controls it expects to find, and a missing plan is a documented gap. And HHS OCR enforcement data shows resolution agreements routinely citing missing or untested contingency plans. Whether your specific plan satisfies your specific obligations is a question for your compliance officer or counsel.
Roles: who does what when the screen goes dark
A plan without names is a wish list. Assign these roles, with a primary and a backup for each:
Downtime coordinator. Usually the practice administrator. Declares downtime, calls IT, keeps the downtime log, decides when to reschedule or divert, and declares recovery. One person. Not a committee.
Front desk lead. Pulls the printed schedule and paper registration forms, checks patients in on paper, collects copays manually, and keeps a running list of every patient seen during downtime.
Clinical lead. A nurse, MA lead, or physician. Distributes paper encounter forms and med lists, makes sure orders are written on paper order forms, and confirms that any result received by phone or fax during downtime is documented.
Billing lead. Holds the superbills, ensures every downtime encounter gets a paper superbill, and owns the back-entry queue after recovery.
IT contact. Your MSP or internal IT. Diagnoses the cause, gives restoration estimates, and tells the coordinator when it is safe to resume.
Print this roster with phone numbers, put it in the kit, and update it every time someone leaves.
The downtime kit
The kit is a physical box at the front desk and one in each clinical pod, inventoried quarterly, because forms walk away.
Paper forms:
- Patient registration and demographics sheet
- Encounter form or superbill, specialty-specific, with your common CPT and ICD-10 codes preprinted
- Medication list and allergy sheet
- Vital signs and progress note template
- Lab, imaging, and referral order forms
- Prescription pads (secured, logged) for non-controlled medications if that is your fallback
- Consent forms and HIPAA acknowledgment
- A downtime log: outage start, who declared it, what was affected, who was called, when it ended
- A patient tracking sheet: every patient seen, in order, with time and provider
Downtime workstation. A designated PC or laptop that either holds a read-only copy of the schedule and recent charts (many EHRs offer a downtime export that refreshes on a schedule) or can reach the EHR through a separate path such as a cellular hotspot. Someone should know where the export lands.
Printed schedule. Printed each morning, or the next day's schedule printed the night before. It is the cheapest and most valuable item in the kit.
Phone tree. IT provider, EHR vendor support line and your account number, e-prescribing vendor, internet provider and circuit ID, phone vendor, cyber insurance hotline, and the practice's leadership. Written on paper, not saved in a system that may be down.
Decision points
Write the thresholds down before you need them.
When to declare downtime. Pick a rule: 15 minutes of confirmed unavailability, or any outage where IT cannot give an estimate. At the threshold, the coordinator declares and everyone opens the kit. The rule prevents the slow drift where each room quietly improvises differently.
When to reschedule. Decide in advance which visit types can proceed on paper (follow-ups, simple acute visits, most procedures where the consent is on paper) and which cannot (visits that require imaging review, infusion where dosing is EHR-verified, anything requiring an electronic prior authorization). If the estimate exceeds a set number of hours, the front desk begins calling tomorrow's patients from the printed schedule.
When to divert. Rare for outpatient practices, but relevant for procedure suites, labs, and urgent care. If a patient's safety depends on data you cannot reach, the plan says who decides to send them elsewhere and how that is documented.
Communication
Staff. The coordinator announces the declaration in person and by text to a pre-built group: what is down, that the kit is open, who is coordinating. Then updates at set intervals even if the update is "no change."
Patients. Front desk gets a short script: the practice is experiencing a system outage, visits are continuing on paper, there may be delays. No speculation about cause. If the outage is a security incident, patient communication becomes a legal and insurance question, and questions go to the administrator.
Vendors and MSP. The coordinator makes one call to IT and lets IT handle vendor calls unless the plan says otherwise. Two people calling the same vendor slows everything down.
Documentation during downtime
Every encounter gets a paper encounter form, a superbill, and an entry on the tracking sheet. Orders go on paper order forms with a copy retained. Any result received by phone gets a result slip with the caller's name and time. Paper prescriptions are logged. The habit to enforce: if it is not on a form in the kit, it will not survive to back-entry.
E-prescribing and EPCS during downtime
This section is where most plans are thin. Decide, in advance and in writing:
- Whether your e-prescribing vendor offers a standalone web portal reachable from the downtime workstation or a phone, and who has credentials.
- Whether non-controlled prescriptions fall back to paper pads, and where those pads live.
- What happens with controlled substances. EPCS requires two-factor authentication through a certified workflow, and Texas requires electronic prescribing of controlled substances with limited exceptions, some of which cover temporary technological failure. The documentation requirements around those exceptions are specific, so this is a regulatory question to settle with counsel before the outage. Practices that prescribe controlled substances daily should read about EPCS and the Texas PDMP and build the fallback accordingly.
Recovery and back-entry
Recovery is not "the EHR is back." Recovery is when the record is whole again.
- IT declares the system available. Not staff noticing that it loaded. IT confirms the database is consistent and, after a security incident, that it is safe.
- Coordinator declares recovery and records the end time in the log.
- Back-entry assignments. Front desk enters registrations and check-ins, clinical staff enter vitals and notes (or scan the paper form and enter a summary), providers sign, billing enters superbills. Deadline: typically 24 to 48 hours.
- Reconciliation. Someone compares the paper tracking sheet against the EHR schedule to confirm every downtime patient has a visit and a charge in the record.
- Orders and results. Verify every paper order was transmitted or entered, that faxed labs were received, and that phoned results made it into the chart.
- Prescriptions. Log paper prescriptions in the EHR so the medication list and PDMP picture are complete.
Back-entry is where practices lose revenue after an outage. Understanding what an hour of downtime actually costs usually pushes administrators to tighten this section first.
Testing the plan
A plan that has never been rehearsed fails on the details. Run a tabletop exercise twice a year: gather the role holders, pick a scenario (internet down at 8:40 a.m. on a full clinic day; ransomware discovered at lunch), and walk through the plan out loud. Write down every "wait, who does that?" and fix the document.
Once a year, run a light live drill: paper forms for one provider for one hour with the EHR still up. Revise the plan after every real outage, every EHR change, and every roster change. Keep a revision date on the cover.
Template outline
Fill in these headings and you have a defensible, usable plan.
- Purpose and scope. Systems covered (EHR, PM, e-prescribing, lab interface, phones).
- Definitions and triggers. What counts as downtime, the declaration threshold, planned versus unplanned.
- Roles and contacts. Coordinator, front desk lead, clinical lead, billing lead, IT contact, backups. Phone numbers.
- Notification and communication. Staff alert method, patient script, vendor and MSP call order, update cadence.
- Downtime kit inventory and locations. Forms list, downtime workstation, printed schedule procedure, phone tree.
- Downtime workflows. Check-in, rooming, provider documentation, orders, results, prescriptions (including EPCS path), checkout and payment.
- Decision criteria. Reschedule rules by visit type, divert rules, time thresholds.
- Security incident addendum. What changes when the outage is deliberate: preserve evidence, do not reconnect, who calls the insurer.
- Recovery. Who declares, back-entry assignments and deadlines, reconciliation checklist, order and result verification.
- Testing and maintenance. Tabletop schedule, drill schedule, revision log, next review date.
- Appendices. Blank forms, downtime log, tracking sheet, contact roster.
The HIPAA Security Rule requires a contingency plan that includes an emergency mode operation plan, a data backup plan, and a disaster recovery plan. A written EHR downtime procedure is how most practices satisfy the emergency mode operation requirement. Auditors and cyber insurers ask to see it.
Set the threshold in advance so nobody has to decide under pressure. Many practices use 15 to 30 minutes of confirmed unavailability, or any outage with no restoration estimate. The point is that a named person makes the call using a written rule, not a hallway consensus.
At minimum: patient registration and demographics, an encounter form or superbill per specialty, a medication list and allergy sheet, lab and imaging order forms, consent and HIPAA acknowledgment forms, a paper schedule for the day, and a downtime log for tracking what happened and when.
Usually not through the EHR itself. Your plan should state whether the practice will use the e-prescribing vendor's standalone web portal, fall back to paper for non-controlled medications, or defer refills. Controlled substances under EPCS have narrower fallback options, so decide that path with counsel and your prescribers ahead of time.
Run a tabletop exercise at least twice a year and after any major EHR, network, or staffing change. A tabletop takes about an hour: walk through a scenario, follow the plan step by step, and note every place where the plan is vague, out of date, or missing a name.
A downtime plan depends on IT that can actually tell you what is wrong and when it will be fixed. Our EMR support and backup and disaster recovery services are built around that: monitored backups, tested restores, a downtime report that runs on schedule, and a 15-minute response window when the call comes in. If your plan has gaps in the IT sections, that is usually where a HIPAA security risk assessment finds them too.
Ready for a straight answer about your IT? Call (972) 776-6366 or visit our contact page.