Office Technology

Backups and Business Continuity Basics

A medical practice runs on data and systems. When they go down — a server failure, a ransomware attack, a flood, or a prolonged outage — the office can grind to a halt and patient care can be disrupted. Backups and a business-continuity plan are what let a practice survive these events. They are also a HIPAA requirement, not merely a best practice.

What HIPAA expects

The HIPAA Security Rule requires a contingency plan that includes data backup, disaster recovery, and emergency-mode operation — the ability to keep critical functions running and to restore lost data. In other words, backups and continuity planning are explicit regulatory obligations for covered entities, not optional extras. HHS provides guidance on these requirements.

Build a sound backup strategy

A widely used principle is the 3-2-1 approach: keep at least three copies of your data, on two different types of media, with one copy stored off-site. The off-site copy is what protects you when a local disaster or ransomware attack hits everything on the premises.

PrincipleWhat it means
3 copiesThe original plus two backups
2 media typesReduces single-technology failure risk
1 off-siteSurvives local disaster and ransomware
A backup you have not tested is a hope, not a plan. Restores fail for reasons backups do not reveal — corrupted files, incomplete coverage, expired credentials. Test restoration regularly.

Test, do not assume

The most common backup failure is discovering, during an actual emergency, that the backups do not restore. Schedule periodic test restores to verify that data is complete, current, and recoverable. Confirm that the systems patients depend on — the EHR, scheduling, and billing — are actually covered, and know how long a full restore takes.

Plan for downtime, not just data loss

Continuity is about more than files. What does the front desk do if the EHR is down at 9 a.m.? Define downtime procedures: how to register patients, document care, and reschedule if needed using paper or offline tools, and how to reconcile once systems return. Staff should know the plan before they need it.

Defend against ransomware specifically

Ransomware is a leading continuity threat in healthcare. Offline or immutable backups that attackers cannot encrypt are the key defense — if your only backups are reachable from the network, ransomware can take them too. Combine resilient backups with patching, endpoint protection, and staff phishing awareness. HHS has published specific guidance on ransomware and HIPAA.

Coordinate with your vendors and cloud services

Many practices now run critical systems — the EHR, billing, even backups — in vendor-hosted cloud environments. This does not remove your continuity obligations; it changes them. Understand what your vendors back up, how quickly they can restore service, and what their commitments are in an outage. Confirm that a Business Associate Agreement is in place for any vendor holding PHI, and that your own offline procedures cover the case where a vendor system, not yours, is the thing that is down. Cloud hosting can strengthen resilience, but only if you know precisely where the vendor's responsibility ends and yours begins, and have planned for the gaps.

Document and review

Write down your backup configuration, recovery steps, downtime procedures, and contacts, and store the plan somewhere reachable even when systems are down. Review it after any change to your systems and after any incident. Business continuity is a discipline of preparation — the work happens before the emergency, so the emergency becomes manageable.