EHR Downtime Plan Checklist for Medical Practices
Protect the patient schedule, assign one outage owner, use approved documentation, coordinate vendors, and reconcile the day after access returns.
This guide supports practice-side technology planning. Practice clinical leadership owns care decisions and approved clinical downtime procedures. The EHR vendor owns its contracted platform.
Illustrative downtime command packetOne packet. Three operating states.
A useful plan controls the patient day, not only the login screen.
A medical practice needs a written EHR downtime path that names who declares downtime, how approved schedule and documentation workflows continue, who contacts each vendor, and who reconciles the work after access returns.
Build a downtime packet staff can reach.
Store the current packet outside the EHR in a practice-approved location. The goal is one trusted starting point, not scattered screenshots, old phone numbers, and staff memory.
Declaration and command
Name the practice leader who declares downtime, the technical coordinator, the staff update channel, and the next update time.
Current contacts
List the EHR vendor, internet carrier, phone provider, billing or clearinghouse, imaging vendors, IT support, and after-hours escalation details.
Schedule access
Document the approved daily schedule export or alternative, who produces it, how current it should be, and where staff can reach it.
Approved forms
Include only practice-approved downtime forms and instructions for registration, messages, orders, referrals, documentation, and follow-up.
Dependency map
Record whether identity, internet, Wi-Fi, phones, printers, scanners, portals, imaging, e-prescribing, and billing share the same failure path.
Return and reconciliation
Name who enters downtime work, who reviews completion, how exceptions are tracked, and when the event record is closed.
Use one sequence during downtime and another when access returns.
The first sequence limits confusion. The second prevents a successful login from being mistaken for a completed recovery.
Name one outage owner.
Record start time, symptoms, affected users and locations, business impact, ticket numbers, and next update.
Confirm the failure boundary.
Check whether the issue affects one device, identity access, the local network, internet, phones, one location, or the vendor platform.
Protect the schedule.
Move the front desk to the approved schedule copy, check-in process, phone script, and urgent-message route.
Use approved downtime work.
Follow the practice-approved clinical and administrative forms. Do not improvise with personal email, consumer apps, or random local files.
Open one coordinated escalation.
Send useful non-sensitive facts to the correct technical owner and keep staff updates in one channel.
Confirm stable access.
Check the agreed users, locations, modules, interfaces, and devices before declaring the interruption over.
Freeze the downtime packet.
Collect approved forms and logs so new paperwork does not continue after the transition point.
Reconcile by workflow.
Compare the schedule, messages, orders, referrals, scans, prescriptions, billing items, and follow-up work in the approved order.
Assign every exception.
Give missing, duplicate, rejected, or unclear items an owner and a completion check.
Revise the plan.
Record what failed, what was unavailable, which contacts were wrong, and when the updated packet will be reviewed.
Route the symptom to the owner that controls it.
Do not ask every vendor to solve every symptom. Start with the observed boundary, then coordinate one escalation path.
Can the user reach other approved services? Does another approved device work? Did a local change occur?
Is the error identity, password, MFA, role, licensing, or EHR access? Are unaffected users still working?
Are internet, phones, Wi-Fi, cloud services, or multiple applications also affected?
Do other approved cloud services work? Has the vendor posted a service event? Which modules are unavailable?
Which results, orders, images, scans, messages, or billing exchanges are delayed? Who owns each interface?
The ONC 2025 SAFER Contingency Planning Guide emphasizes written downtime and recovery policies, named clinical and technical leadership, communication, accessible procedures, and re-entry of information collected during downtime.
Each workflow needs an approved fallback and a return owner.
A schedule copy alone is not a complete downtime plan. Map the parts of the day that can create missed work, duplicate work, or unsafe handoffs after the EHR returns.
Schedule and patient communication
Approved schedule access, arrivals, cancellations, phone scripts, urgent messages, and who communicates delays or rescheduling decisions.
Care and documentation procedures
Practice-approved forms, order and result handling, prescriptions, clinical priorities, patient decisions, and the authority to limit services.
Referrals, scans, billing, and queues
How administrative work is captured, where it waits, who owns external handoffs, and how duplicates or missed items are found.
Access and vendor dependencies
Internet, identity, phones, devices, printing, scanning, imaging, interfaces, backups, and one coordinated escalation record.
Reconcile the patient day before closing the event.
Recovery is incomplete until the practice can account for downtime work, assign exceptions, and confirm the agreed review is finished.
Rehearse one realistic outage as a safe tabletop.
Choose a representative patient-hour scenario and walk the written path. Record what staff could not reach or answer.
- Choose a planned scenario, such as EHR access unavailable while phones and internet still work.
- Assign the outage lead, clinical lead, front desk lead, technical contact, and reconciliation owner.
- Walk schedule access, approved forms, communication, escalation, return, and reconciliation.
- Record missing contacts, inaccessible documents, unclear authority, and untested dependencies.
- Assign each gap. Set the next packet review date.
HealthDesk can help map the practice-side systems, vendor dependencies, and evidence questions for a bounded downtime readiness review.
Request an EHR downtime readiness reviewWhat should remain after the exercise?
Move from the guide to the correct technical path.
The article owns education. Each service page owns a different implementation or support decision.
Answers a practice manager should be able to see now.
What should a medical practice do first when the EHR goes down?
Name one outage owner, record the time and observed scope, protect the patient schedule, move to approved downtime procedures, and open one coordinated vendor or IT escalation.
Where should the downtime plan be stored?
Keep a current, practice-approved copy outside the EHR where authorized staff can reach it during internet or platform unavailability. Control distribution and revisions.
When should the EHR vendor be contacted?
Contact the vendor when the observed pattern points to the platform or when multiple users or locations are affected. Share non-sensitive facts, ticket ownership, and business impact.
When should local IT support be involved?
Involve IT when the boundary is unclear or when identity, workstations, network, internet, phones, printers, scanners, interfaces, or another local dependency may be involved.
Is access restoration the end of the outage?
No. The practice still needs to confirm stable access, stop downtime entry, reconcile approved records, assign exceptions, and complete clinical and operational review.
Does this checklist make a practice HIPAA compliant?
No. It is an educational planning aid. HIPAA applicability, formal risk analysis, legal conclusions, clinical policies, and compliance determinations remain outside this article and require fact-specific review.
Official guidance grounds the planning questions.
Primary sources
How to use this article
HHS guidance describes contingency-plan components that include data backup, disaster recovery, emergency-mode operations, testing and revision, and application/data criticality analysis. ONC SAFER material addresses EHR downtime and recovery practices. These sources do not endorse HealthDesk IT, establish compliance, replace clinical policy, or guarantee continuity or recovery.
