Healthcare-focused IT for New Jersey practicesCall 732-362-4949
EHR downtime guide

EHR Downtime Plan Checklist for Medical Practices

Protect the patient schedule, assign one outage owner, use approved documentation, coordinate vendors, and reconcile the day after access returns.

This guide supports practice-side technology planning. Practice clinical leadership owns care decisions and approved clinical downtime procedures. The EHR vendor owns its contracted platform.

Medical office EHR continuity and system availability planningIllustrative downtime command packet
Keep outside the EHR

One packet. Three operating states.

01Prepare roles, contacts, forms, and schedule access
02Control the patient day and one escalation channel
03Restore access, reconcile work, and record gaps
The packet is an operating aid, not a clinical policy or platform recovery guarantee.
Quick answer

A useful plan controls the patient day, not only the login screen.

A medical practice needs a written EHR downtime path that names who declares downtime, how approved schedule and documentation workflows continue, who contacts each vendor, and who reconciles the work after access returns.

Before an outage

Build a downtime packet staff can reach.

Store the current packet outside the EHR in a practice-approved location. The goal is one trusted starting point, not scattered screenshots, old phone numbers, and staff memory.

Clinical boundary: HealthDesk can map practice-side technology, vendor dependencies, access questions, and test evidence. Clinical leaders approve care procedures, forms, medication workflows, and patient decisions.
01

Declaration and command

Name the practice leader who declares downtime, the technical coordinator, the staff update channel, and the next update time.

02

Current contacts

List the EHR vendor, internet carrier, phone provider, billing or clearinghouse, imaging vendors, IT support, and after-hours escalation details.

03

Schedule access

Document the approved daily schedule export or alternative, who produces it, how current it should be, and where staff can reach it.

04

Approved forms

Include only practice-approved downtime forms and instructions for registration, messages, orders, referrals, documentation, and follow-up.

05

Dependency map

Record whether identity, internet, Wi-Fi, phones, printers, scanners, portals, imaging, e-prescribing, and billing share the same failure path.

06

Return and reconciliation

Name who enters downtime work, who reviews completion, how exceptions are tracked, and when the event record is closed.

The desk card

Use one sequence during downtime and another when access returns.

The first sequence limits confusion. The second prevents a successful login from being mistaken for a completed recovery.

While the EHR is unavailable
When access returns
01

Name one outage owner.

Record start time, symptoms, affected users and locations, business impact, ticket numbers, and next update.

02

Confirm the failure boundary.

Check whether the issue affects one device, identity access, the local network, internet, phones, one location, or the vendor platform.

03

Protect the schedule.

Move the front desk to the approved schedule copy, check-in process, phone script, and urgent-message route.

04

Use approved downtime work.

Follow the practice-approved clinical and administrative forms. Do not improvise with personal email, consumer apps, or random local files.

05

Open one coordinated escalation.

Send useful non-sensitive facts to the correct technical owner and keep staff updates in one channel.

01

Confirm stable access.

Check the agreed users, locations, modules, interfaces, and devices before declaring the interruption over.

02

Freeze the downtime packet.

Collect approved forms and logs so new paperwork does not continue after the transition point.

03

Reconcile by workflow.

Compare the schedule, messages, orders, referrals, scans, prescriptions, billing items, and follow-up work in the approved order.

04

Assign every exception.

Give missing, duplicate, rejected, or unclear items an owner and a completion check.

05

Revise the plan.

Record what failed, what was unavailable, which contacts were wrong, and when the updated packet will be reviewed.

Do not place PHI, passwords, screenshots with patient data, or access keys in public or unsecured tickets.
Local issue or vendor outage?

Route the symptom to the owner that controls it.

Do not ask every vendor to solve every symptom. Start with the observed boundary, then coordinate one escalation path.

Observed pattern
Useful first questions
Likely first owner
One workstation or browser

Can the user reach other approved services? Does another approved device work? Did a local change occur?

IT support
One or several user accounts

Is the error identity, password, MFA, role, licensing, or EHR access? Are unaffected users still working?

IT plus EHR vendor
Whole office or location

Are internet, phones, Wi-Fi, cloud services, or multiple applications also affected?

IT and carrier
EHR only across users or sites

Do other approved cloud services work? Has the vendor posted a service event? Which modules are unavailable?

EHR vendor
EHR access restored, interfaces missing

Which results, orders, images, scans, messages, or billing exchanges are delayed? Who owns each interface?

Named vendors

The ONC 2025 SAFER Contingency Planning Guide emphasizes written downtime and recovery policies, named clinical and technical leadership, communication, accessible procedures, and re-entry of information collected during downtime.

Keep the workday controlled

Each workflow needs an approved fallback and a return owner.

A schedule copy alone is not a complete downtime plan. Map the parts of the day that can create missed work, duplicate work, or unsafe handoffs after the EHR returns.

Front desk

Schedule and patient communication

Approved schedule access, arrivals, cancellations, phone scripts, urgent messages, and who communicates delays or rescheduling decisions.

Clinical leadership

Care and documentation procedures

Practice-approved forms, order and result handling, prescriptions, clinical priorities, patient decisions, and the authority to limit services.

Operations

Referrals, scans, billing, and queues

How administrative work is captured, where it waits, who owns external handoffs, and how duplicates or missed items are found.

Technology

Access and vendor dependencies

Internet, identity, phones, devices, printing, scanning, imaging, interfaces, backups, and one coordinated escalation record.

HealthDesk scope: practice-side technical discovery, dependency mapping, coordination, testing questions, and recovery evidence. Clinical policies, legal conclusions, breach determinations, vendor platform recovery, and clinical validation remain with their responsible owners.
After access returns

Reconcile the patient day before closing the event.

Recovery is incomplete until the practice can account for downtime work, assign exceptions, and confirm the agreed review is finished.

01Mark the transition point.Record when normal entry resumed and which locations, users, modules, or interfaces were checked.
02Collect the approved records.Bring together downtime forms, message logs, schedule annotations, vendor tickets, and exception notes.
03Re-enter in the approved order.Use practice priorities for encounters, messages, orders, referrals, documents, prescriptions, billing, and follow-up.
04Review missing or duplicate work.Track items that failed, appeared twice, need clarification, or depend on a delayed external system.
05Sign off and revise.Clinical and operational owners complete their reviews. Technical gaps receive owners and a revision date.
A short tabletop test

Rehearse one realistic outage as a safe tabletop.

Choose a representative patient-hour scenario and walk the written path. Record what staff could not reach or answer.

  1. Choose a planned scenario, such as EHR access unavailable while phones and internet still work.
  2. Assign the outage lead, clinical lead, front desk lead, technical contact, and reconciliation owner.
  3. Walk schedule access, approved forms, communication, escalation, return, and reconciliation.
  4. Record missing contacts, inaccessible documents, unclear authority, and untested dependencies.
  5. Assign each gap. Set the next packet review date.
Need a second set of technical eyes?

HealthDesk can help map the practice-side systems, vendor dependencies, and evidence questions for a bounded downtime readiness review.

Request an EHR downtime readiness review
Illustrative test record

What should remain after the exercise?

Scenario and boundaryWhat was assumed unavailable, what remained available, and what was excluded.
Roles and authorityWho declared downtime, led clinical decisions, contacted vendors, updated staff, and owned return.
Observed evidenceWhich schedule, contact, form, route, dependency, or recovery step worked or failed.
Open gapsEach unresolved question with an owner, next action, and due date.
Revision controlPacket version, approval date, distribution point, and next review or test date.
Use the page that owns the work

Move from the guide to the correct technical path.

The article owns education. Each service page owns a different implementation or support decision.

Planned continuity and restore evidenceBackup scope, restore testing, recovery priorities, and contingency readiness.Disaster recovery
Recurring local technology ownershipUsers, devices, identity, internet, network, phones, and vendor coordination.Managed IT
A repeat access or workstation issueRoutine troubleshooting for a current but non-emergency local problem.IT support
An EHR change already selectedImplementation readiness, interfaces, go-live, and stabilization.EHR implementation
EHR downtime questions

Answers a practice manager should be able to see now.

What should a medical practice do first when the EHR goes down?

Name one outage owner, record the time and observed scope, protect the patient schedule, move to approved downtime procedures, and open one coordinated vendor or IT escalation.

Where should the downtime plan be stored?

Keep a current, practice-approved copy outside the EHR where authorized staff can reach it during internet or platform unavailability. Control distribution and revisions.

When should the EHR vendor be contacted?

Contact the vendor when the observed pattern points to the platform or when multiple users or locations are affected. Share non-sensitive facts, ticket ownership, and business impact.

When should local IT support be involved?

Involve IT when the boundary is unclear or when identity, workstations, network, internet, phones, printers, scanners, interfaces, or another local dependency may be involved.

Is access restoration the end of the outage?

No. The practice still needs to confirm stable access, stop downtime entry, reconcile approved records, assign exceptions, and complete clinical and operational review.

Does this checklist make a practice HIPAA compliant?

No. It is an educational planning aid. HIPAA applicability, formal risk analysis, legal conclusions, clinical policies, and compliance determinations remain outside this article and require fact-specific review.

Evidence and limits

Official guidance grounds the planning questions.

How to use this article

HHS guidance describes contingency-plan components that include data backup, disaster recovery, emergency-mode operations, testing and revision, and application/data criticality analysis. ONC SAFER material addresses EHR downtime and recovery practices. These sources do not endorse HealthDesk IT, establish compliance, replace clinical policy, or guarantee continuity or recovery.

EHR downtime readiness review

Start with the outage path that still has an open owner.

Share non-sensitive context about the practice, EHR environment, dependencies, and the question the current plan does not answer. HealthDesk will determine fit and the safest next planning step.

  • Call: 732-362-4949
  • Useful context: locations, broad EHR platform, schedule access, internet or phone dependencies, current vendors, and test status
  • Do not send: PHI, passwords, access keys, patient screenshots, live exports, or confidential configuration files

Email or phone is required. Submission does not create a client relationship, guarantee availability or recovery, establish compliance, or authorize access to systems or ePHI.