For years, healthcare cybersecurity conversations focused heavily on prevention. 

How do we stop ransomware? 
How do we block unauthorized access? 
How do we protect electronic protected health information? 

Those questions still matter. 

But healthcare leaders are now asking another question, one that is just as important: 

What happens if critical systems go down anyway? 

That question sits at the center of recovery readiness. 

Cyberattacks happen. Technology fails. Cloud services go offline. Vendors experience incidents. Storms, power events, and network outages interrupt operations. No healthcare organization can eliminate every disruption. 

That is why resilience and recovery have become central to healthcare cybersecurity planning. 

The proposed HIPAA Security Rule updates have drawn new attention to this issue, including proposed expectations for written procedures to restore certain relevant electronic information systems and data within 72 hours of loss. 1 

For healthcare organizations, that conversation extends far beyond compliance. 

It touches patient care, EHR access, phone systems, scheduling, billing, referrals, prescriptions, claims, network availability, cloud systems, vendor coordination, and staff communication. 

Recovery is not just an IT function. 

It is how the organization continues to serve patients when technology is under pressure. 

At a Glance: 72-Hour Restoration Objective 

  • The 72-hour restoration objective is part of the proposed updates to the HIPAA Security Rule. It is not a current universal HIPAA requirement.  
  • HHS has proposed written procedures to restore certain relevant electronic information systems and data within 72 hours.  
  • Recovery planning is broader than backup storage. It includes systems, access, applications, workflows, vendors, communications, and people.  
  • EHR downtime, phone outages, network failures, and cloud interruptions can quickly affect patient care.  
  • Backups are important, but tested restoration procedures create confidence.  
  • Healthcare organizations should prioritize recovery based on the impact on patient care, not just on technical asset lists.  
  • DataTel’s HIPAA Readiness Assessment includes a clinical downtime impact calculator and a prioritized 90-day roadmap.  

What Is the Proposed 72-Hour Recovery Objective? 

The proposed 72-hour recovery objective refers to language in the HIPAA Security Rule NPRM that would require regulated entities to establish written procedures to restore certain relevant electronic information systems and data within 72 hours of loss. HHS also says the proposed rule would require organizations to analyze the relative criticality of relevant systems and technology assets to determine restoration priority. 1 

That language has received attention because it is more specific than many recovery expectations healthcare organizations have historically planned around. 

The current HIPAA Security Rule remains in effect today. The proposed updates are not final. HHS describes the current Security Rule as a national set of standards requiring covered entities and business associates to protect electronic protected health information through administrative, physical, and technical safeguards. 2 

So the right response is not panic. 

It is readiness. 

Healthcare organizations should use the proposed 72-hour objective as a practical prompt for evaluating whether recovery plans align with the realities of patient care operations. 

Simple Definition 

The proposed 72-hour recovery objective is a proposed HIPAA Security Rule expectation for written procedures to restore certain relevant electronic information systems and data within 72 hours. It focuses on operational recovery, not just backup storage. 

That distinction matters. 

Healthcare organizations do not deliver care through backup files. They deliver care through systems, applications, communications platforms, workflows, vendors, and people. 

A successful recovery requires all those pieces to work together. 

What the Proposed Recovery Objective Does Not Mean 

Many organizations hear “72-hour recovery” and immediately think of backups. 

That interpretation is incomplete. 

The proposed objective is not simply asking, “Do you have a copy of the data?” 

It raises broader questions: 

  • Can critical systems be restored?  
  • Can users access those systems?  
  • Can clinicians access patient information?  
  • Can patients contact the practice?  
  • Can staff communicate internally?  
  • Can scheduling continue?  
  • Can prescriptions, referrals, claims, and billing move forward?  
  • Can operations continue safely while systems are being restored?  

 

The focus is operational recovery. 

For a broader explanation of the proposed rule and what remains current versus proposed, see Proposed HIPAA Security Rule Changes: What Healthcare Organizations Should Prepare for Now 

Why Healthcare Organizations Are Paying Attention 

Healthcare operations depend on technology availability. 

A disruption to one critical platform can quickly ripple through several areas of the organization. 

Electronic Health Records 

Without EHR access, clinicians may struggle to: 

  • Review patient histories  
  • Check medications and allergies  
  • Document encounters  
  • Coordinate care  
  • Process orders  
  • Review treatment plans  

 

EHR downtime can also affect patient safety, staff productivity, and documentation integrity. DataTel’s article on EHR Downtime in Mental Health and SUD Care explores how deeply downtime can affect care delivery in sensitive clinical settings. 

Communications Systems 

Phone downtime can create immediate pressure. 

Patients may be unable to reach the practice. Staff may struggle to coordinate internally. Referrals may slow down. Appointment changes may not reach patients quickly. Call center teams may lose routing, queues, recordings, or reporting. 

For healthcare organizations already using voice services, resilience planning becomes much broader than telecom. DataTel VoIP Business Phone and DataTel Contact Center support can help organizations think about phone continuity as part of patient access, not just phone uptime. 

Networks and Internet Connectivity 

Most healthcare systems depend on network availability. 

Network or internet disruptions can affect: 

  • EHR platforms  
  • Cloud applications  
  • Imaging systems  
  • VoIP systems  
  • Patient portals  
  • Telehealth platforms  
  • Billing platforms  
  • Security monitoring  
  • Remote access  

 

A cloud-based system is only useful if staff can reach it. 

This is where DataTel Network, Server Management, and Cloud Management are integrated into recovery planning. 

Revenue Cycle Operations 

Downtime also affects the business side of care. 

Technology disruptions may slow: 

  • Scheduling  
  • Claims  
  • Billing  
  • Payment posting  
  • Eligibility checks  
  • Prior authorization workflows  
  • Patient communications  
  • Referral coordination  

 

Downtime creates clinical strain and operational costs. DataTel’s article, “The Hidden Cost of Downtime in Mental Health and Substance Use Disorder Care,” offers a closer look at how outages can affect both care delivery and business continuity. 

Backup vs. Recovery: Why the Difference Matters 

One of the most common misconceptions in healthcare cybersecurity is that backups guarantee recovery. 

They do not. 

Backups are essential. They preserve data. But recovery is the process of restoring systems, access, functionality, workflows, and operational capability. 

A healthcare organization may have excellent backups and still face serious recovery problems if: 

  • Restoration procedures are undocumented.  
  • Recovery roles are unclear.  
  • Critical applications are missing from the plan.  
  • System dependencies are unknown.  
  • Backup restoration has never been tested.  
  • Vendor responsibilities are unclear.  
  • Staff do not know downtime workflows.  
  • Phones and networks are not included in recovery planning.  

 

A backup answers one question: 

Do we have a copy of the data? 

Recovery answers a better question: 

Can we restore operations quickly enough to support patient care? 

Backup vs. Recovery 

Backup  Recovery 
Preserves data  Restores operations 
Creates copies of information  Restores systems, access, and workflows 
Often automated  Requires planning, people, and testing 
Supports resilience  Delivers resilience when validated 
Can exist without testing  Requires restoration exercises 
Answers “Do we have the data?”  Answers “Can we operate again?” 

Healthcare organizations often invest in backup systems but spend less time validating recovery. 

The proposed HIPAA Security Rule updates highlight why that gap matters. 

Why Downtime Is a Patient Care Issue 

Cybersecurity discussions often focus on confidentiality and privacy. 

Recovery planning adds another dimension: availability. 

When systems become unavailable, patient care may be affected. 

Healthcare organizations may experience: 

  • Delayed treatment  
  • Referral disruptions  
  • Scheduling delays  
  • Prescription workflow issues  
  • Documentation gaps  
  • Communication failures  
  • Reduced staff productivity  
  • Revenue cycle delays  
  • Patient frustration  

 

This is why recovery planning belongs in executive conversations. 

It is not simply about restoring servers. 

It is about keeping care moving. 

For a broader resilience strategy, see Healthcare Cyber Resilience: How to Reduce Risk Without Disrupting Patient Care 

The Question Healthcare Leaders Should Be Asking 

Instead of asking, “Do we have backups?” 

Healthcare leaders should ask, “If a critical system became unavailable tomorrow, how quickly could we restore operations?” 

That question often reveals the gap between data protection and true operational resilience. 

A healthcare organization may discover that the EHR can be restored, but the phone system has no alternate routing plan. 

Or that backups exist, but no one has tested restoration since the last infrastructure change. 

Or that cloud vendors provide uptime documentation, but internal internet redundancy is weak. 

Or that staff knows how to document downtime manually, but no one has tested how that information will be reconciled after restoration. 

These are not abstract concerns. 

They are readiness issues. 

What Systems Must Healthcare Organizations Be Able to Recover? 

When healthcare leaders think about disaster recovery, they often focus on the EHR. 

That makes sense. The EHR is usually one of the most visible systems in the organization. 

But modern healthcare operations depend on a much broader technology environment. 

A strong recovery strategy should consider every system that affects patient care, operations, communications, and revenue. 

EHR Recovery 

EHR recovery is often the priority because it directly affects clinical work. 

Healthcare organizations should evaluate: 

Access to Patient Records 

Ask: 

  • How quickly can records be restored?  
  • Can clinicians access critical patient information during downtime?  
  • Are alternate workflows documented?  
  • Can staff access recent medication, allergy, and treatment information?  

Clinical Documentation 

Ask: 

  • How will encounters be documented during downtime?  
  • How will notes be entered after restoration?  
  • How will documentation integrity be maintained?  
  • Who approves the reconciliation process?  

Medication and Treatment Information 

Ask: 

  • How will medication histories be accessed?  
  • How will allergy information be checked?  
  • How will treatment plans be reviewed?  
  • What happens if clinical decision support is unavailable?  

 

EHR recovery is not only about the application. 

It is about the clinical workflows around the application. 

Communications Recovery: More Than Just Phones 

Communications often become more important during a disruption, not less. 

Patients need instructions. Staff need updates. Vendors need coordination. Leadership needs status reports. Clinical teams need clear direction. 

Healthcare organizations should evaluate: 

  • Phone system resilience  
  • Failover capabilities  
  • Alternate call routing  
  • Contact center continuity  
  • Emergency communication procedures  
  • Patient notification options  
  • Internal communication channels  
  • Vendor escalation paths  

 

Questions to ask include: 

  • What happens if our primary phone system fails?  
  • Can calls be redirected?  
  • Can patients still reach us?  
  • Can staff communicate internally?  
  • Can leadership communicate recovery priorities?  
  • Can referral partners reach the right contacts?  

 

For organizations with patient access teams, DataTel Contact Center can support planning around call routing, queue visibility, reporting, and patient communication workflows. 

Network and Internet Connectivity Recovery 

Nearly every healthcare system depends on network availability. 

Without network or internet access, staff may lose access to: 

  • EHR systems  
  • Cloud services  
  • VoIP platforms  
  • Imaging systems  
  • Patient portals  
  • Billing systems  
  • Telehealth platforms  
  • Security systems  
  • Remote access  

 

Recovery planning should address both internal networks and external connectivity. 

Internal Network Recovery 

Evaluate: 

  • Network architecture  
  • Critical switches, firewalls, and access points  
  • Segmentation strategies  
  • Vendor access pathways  
  • Device dependencies  
  • Recovery procedures  

 

Ask: 

  • Which network components must come back first?  
  • Which systems depend on which network services?  
  • Can critical systems be isolated during an incident?  
  • Are network diagrams current?  

Internet Connectivity 

Evaluate: 

  • Internet redundancy  
  • Failover options  
  • Carrier dependencies  
  • Firewall and routing dependencies  
  • Service restoration procedures  

 

A cloud application does not help if users cannot connect to it. 

Cloud and SaaS Recovery Considerations 

Healthcare organizations increasingly rely on cloud-hosted and Software-as-a-Service platforms. 

Common examples include: 

  • EHR systems  
  • Practice management systems  
  • Patient communication platforms  
  • Collaboration platforms  
  • Billing systems  
  • Security platforms  
  • Backup platforms  

 

Many organizations assume cloud providers automatically solve recovery challenges. 

That assumption can create risk. 

Cloud providers may manage infrastructure resilience, but healthcare organizations still need to understand access, configuration, data retention, recovery commitments, incident communication, identity controls, and vendor responsibilities. 

Ask cloud providers: 

  • What are your recovery objectives?  
  • How often are backups performed?  
  • How are restoration procedures tested?  
  • What geographic redundancy exists?  
  • How will we receive incident updates?  
  • What access controls protect our environment?  
  • What evidence can you provide?  

 

Vendor resilience is part of organizational resilience. For a deeper discussion of vendor readiness, see “Are BAAs Enough for HIPAA?” What Healthcare Organizations Should Ask Vendors and Business Associates 

Medical Device Recovery Planning 

Medical devices sometimes receive less attention during recovery planning, especially in smaller or mid-sized healthcare organizations. 

That can be a mistake. 

Many devices now depend on: 

  • Network connectivity  
  • Vendor platforms  
  • Cloud integrations  
  • Centralized management systems  
  • Local servers  
  • Identity and access controls  
  • Support contracts  

 

Healthcare organizations should understand: 

  • Which devices depend on network access  
  • What happens if connectivity is lost  
  • Which vendors support device recovery  
  • What alternate workflows exist  
  • Which devices are critical to patient care  
  • Whether device downtime procedures are documented  

 

Medical device planning should not sit outside the recovery strategy. 

It should be part of the same resilience conversation. 

Recovery Testing Matters More Than Recovery Documentation 

Most healthcare organizations have some form of recovery documentation. 

Fewer have tested it recently. 

That distinction matters. 

A recovery plan is a hypothesis until it has been tested. 

Testing shows whether the plan works in the real environment, with real dependencies, real vendors, real timing constraints, and real people involved. 

What Recovery Testing Reveals 

Recovery exercises often uncover: 

  • Missing steps  
  • Outdated documentation  
  • Unclear roles  
  • Technology dependencies  
  • Communication gaps  
  • Vendor delays  
  • Resource limitations  
  • Access problems  
  • Unexpected system order requirements  
  • Documentation and evidence gaps  

 

These discoveries are not failures. 

They are opportunities to improve before a real outage occurs. 

For organizations focused on proof and audit readiness, HIPAA Policies Are Not Enough: What Evidence Healthcare Organizations Need to Prove Readiness explains why testing records, recovery evidence, and documentation matter. 

Types of Recovery Testing 

Healthcare organizations can test recovery in several ways. 

Test Type  What It Evaluates  Why It Matters 
Tabletop exercise  Decision-making, escalation, communication, roles  Helps leaders and staff practice response without affecting systems 
Technical recovery test  Backup restoration, system recovery, application availability  Validates whether systems can be restored 
Operational downtime exercise  Clinical workflows, patient communication, scheduling, manual processes  Tests whether the organization can keep serving patients 
Vendor coordination review  Escalation paths, service commitments, response timing  Identifies third-party dependency gaps 
Communications drill  Phone routing, internal messaging, patient notices  Confirms people can communicate when primary systems fail 

The goal is confidence. 

Not theoretical confidence. 

Operational confidence. 

Recovery Runbooks: Turning Plans into Action 

During a disruption, complex documents are hard to use. 

People need clarity. 

A recovery runbook provides step-by-step guidance for restoring systems and supporting operations. It should be practical enough for teams to use under pressure. 

Effective recovery runbooks often include: 

Roles and Responsibilities 

Define: 

  • Recovery leaders  
  • Technical owners  
  • Communications leads  
  • Executive stakeholders  
  • Vendor contacts  
  • Clinical operations contacts  
  • Compliance contacts  

Recovery Procedures 

Document: 

  • Restoration steps  
  • System dependencies  
  • Prioritization sequences  
  • Escalation paths  
  • Required credentials  
  • Decision points  
  • Validation steps  

Communication Plans 

Include: 

  • Internal communication procedures  
  • Vendor communication procedures  
  • Patient communication guidance  
  • Leadership update cadence  
  • Contact lists  
  • Alternate channels  

 

The best recovery plans are often simple, current, and easy to use. 

During a crisis, clarity matters more than complexity. 

The Most Common Recovery Planning Mistakes 

Healthcare organizations often make the same recovery planning mistakes. 

Mistake 1: Assuming Backups Equal Recovery 

Backups support recovery. They do not guarantee recovery. 

Restoration must be tested. 

Mistake 2: Focusing Only on Technology 

Recovery requires people, processes, communications, vendors, and leadership. 

Technology is one part of the work. 

Mistake 3: Ignoring Dependencies 

Applications rarely operate alone. 

An EHR may depend on identity systems, internet connectivity, integrations, local devices, vendor portals, and network infrastructure. 

Mistake 4: Never Testing Recovery Procedures 

Untested plans often fail when they are needed most. 

Testing turns assumptions into evidence. 

Mistake 5: Overlooking Communications 

Some organizations focus on systems and forget how staff, patients, providers, vendors, and leadership will communicate during downtime. 

That gap can slow recovery and increase confusion. 

Mistake 6: Treating Vendors as Separate from Recovery 

Vendors are part of the operating environment. 

If a vendor supports EHR access, communications, cloud systems, backups, phones, billing, or cybersecurity, their recovery capabilities matter. 

The Goal Is Operational Continuity 

The purpose of recovery planning is not simply restoring servers. 

The goal is to maintain the ability to serve patients. 

Healthcare organizations should evaluate recovery through a practical lens: 

Can we continue delivering care while technology is being restored? 

That question changes the conversation. 

It brings clinical operations, communications, IT, compliance, leadership, and vendors into the same room. 

It also helps organizations prioritize what matters most. 

For decision-stage leaders evaluating whether their current provider can support that level of coordination, see How to Choose a Healthcare IT, Cybersecurity, and Communications Provider 

Healthcare Recovery Maturity Model 

Recovery readiness develops in stages. 

Understanding where your organization stands can help prioritize next steps. 

Maturity Level  Characteristics  Practical Concern 
Level 1: Reactive  Limited documentation, unclear ownership, untested backups, informal downtime workflows  Recovery depends on individual knowledge 
Level 2: Documented  Plans exist, critical systems are listed, basic roles are assigned  Documentation may not be validated 
Level 3: Tested  Recovery exercises occur, restoration is validated, lessons learned are documented  The organization is moving from assumption to evidence 
Level 4: Managed  Recovery metrics, executive reporting, vendor reviews, and improvement processes exist  Recovery becomes an operational discipline 
Level 5: Resilient  Continuity, cybersecurity, vendor management, communications, and recovery are integrated  The organization focuses on maintaining patient care, not just restoring systems 

The goal is not to jump from Level 1 to Level 5 immediately. 

The goal is steady improvement. 

Recovery Readiness Checklist 

Healthcare organizations evaluating recovery maturity should review the following areas. 

Governance 

  • Have recovery responsibilities been assigned?  
  • Are recovery plans documented?  
  • Are recovery objectives defined?  
  • Are critical systems prioritized?  
  • Does leadership receive recovery readiness updates?  

Technology 

  • Are backups tested?  
  • Have restoration procedures been validated?  
  • Are network recovery procedures documented?  
  • Are cloud dependencies understood?  
  • Are identity systems included in recovery planning?  
  • Are endpoint and device dependencies documented?  

Operations 

  • Are downtime workflows documented?  
  • Can patient care continue during disruptions?  
  • Can scheduling, billing, referrals, prescriptions, and claims continue?  
  • Are communication procedures established?  
  • Have alternate workflows been tested?  

Vendors 

  • Are vendor recovery capabilities understood?  
  • Have critical vendor dependencies been identified?  
  • Are escalation procedures documented?  
  • Are service commitments reviewed?  
  • Are business associates periodically evaluated?  

Testing 

  • Are tabletop exercises conducted?  
  • Are technical recovery tests performed?  
  • Are communications drills completed?  
  • Are lessons learned documented?  
  • Are corrective actions tracked?  

 

Organizations that answer “no” to several of these questions have a clear opportunity to strengthen resilience. 

What Healthcare Leaders Should Do in the Next 90 Days 

Recovery readiness can feel overwhelming. 

A 90-day plan helps organizations make progress without trying to solve everything at once. 

Days 1 to 30: Build Visibility 

Start by understanding what must be restored first and why. 

Recommended activities: 

  • Identify critical systems.  
  • Inventory operational dependencies.  
  • Review EHR, phone, network, cloud, and vendor dependencies.  
  • Document recovery objectives.  
  • Evaluate current recovery plans.  
  • Review backup reports.  
  • Identify patient care workflows affected by downtime.  
  • Review recent incidents or near misses.  

 

Estimate your clinical downtime exposure with DataTel’s HIPAA Readiness Assessment and downtime impact calculator. 

Days 31 to 60: Validate Assumptions 

Move from documentation to evidence. 

Recommended activities: 

  • Conduct a tabletop exercise.  
  • Review backup restoration procedures.  
  • Validate communication plans.  
  • Evaluate downtime workflows.  
  • Review vendor recovery commitments.  
  • Test call routing or failover options.  
  • Review network and internet redundancy.  
  • Document findings and ownership.  

 

This is also the right time to review whether recovery is connected to broader risk analysis. For guidance, see HIPAA Risk Analysis vs. Vulnerability Scan: What Healthcare Practices Often Miss 

Days 61 to 90: Strengthen Resilience 

Focus on improvements with the greatest operational impact. 

Examples include: 

  • Expanding recovery testing  
  • Improving recovery runbooks  
  • Strengthening communication procedures  
  • Updating vendor escalation paths  
  • Formalizing evidence collection  
  • Improving executive reporting  
  • Addressing high-risk technical safeguards  
  • Updating remediation plans  

 

For technical readiness, leaders may also want to review Does HIPAA Require MFA, Encryption, Vulnerability Scanning, and Network Segmentation? 

How DataTel Helps Healthcare Organizations Improve Recovery Readiness 

Many healthcare organizations understand that recovery matters. 

The difficult part is bringing together EHR access, phones, networks, cloud systems, cybersecurity, vendors, backups, and operations into a single practical plan. 

DataTel helps healthcare organizations evaluate and improve readiness across the systems that support care. 

Managed IT and Infrastructure Support 

DataTel Fully Managed IT helps healthcare organizations manage the operational foundation behind recovery readiness, including devices, networks, servers, cloud environments, support processes, and vendor coordination. 

Cybersecurity Readiness 

DataTel Cybersecurity supports risk reduction, monitoring, access controls, endpoint visibility, vulnerability management, and incident readiness. 

Network, Server, and Cloud Support 

Network and Server Management and Cloud Management help organizations understand the dependencies behind applications, communications, and recovery planning. 

Voice and Patient Communications 

VoIP Business Phone and Contact Center support communication continuity, call routing, and patient access planning. 

The goal is not to create a recovery plan that sits unused. 

The goal is to help healthcare organizations keep care moving when systems, vendors, or infrastructure are under strain. 

Take DataTel’s Free HIPAA Readiness Assessment 

Recovery planning has become a critical part of healthcare cybersecurity readiness. 

Take DataTel’s free HIPAA Readiness Assessment to evaluate your organization across: 

  • Recovery and resilience  
  • Access controls  
  • Compliance and audit readiness  
  • Governance and risk  
  • Communications readiness  

The assessment includes readiness scoring, a clinical downtime impact calculator, and a prioritized 90-day roadmap. 

Start here: Take the HIPAA Readiness Assessment

Frequently Asked Questions

What is the proposed 72-hour recovery objective?

The proposed HIPAA Security Rule updates include expectations for written procedures to restore certain relevant electronic information systems and data within 72 hours of loss. 

The current HIPAA Security Rule does not contain a universal 72-hour restoration requirement. The 72-hour objective is associated with the proposed updates to the HIPAA Security Rule currently under consideration. 

No. Backups are important, but they do not guarantee operational recovery. Healthcare organizations also need restoration procedures, testing, communication plans, vendor coordination, documented responsibilities, and downtime workflows. 

Backups preserve information. Recovery restores systems, access, functionality, workflows, and operational capability.

Priorities often include EHR systems, phone systems, contact centers, network infrastructure, internet connectivity, patient scheduling, billing, claims, prescriptions, referrals, identity systems, cloud platforms, and critical clinical applications. 

EHR downtime can affect patient records, medication information, allergy checks, documentation, orders, treatment plans, referrals, and clinical decision-making.

Phone systems support patient access, scheduling, referrals, internal coordination, emergency communication, and patient updates. During downtime, communication often becomes more important, not less. 

Healthcare organizations should periodically test recovery procedures and review them after major system, vendor, operational, or infrastructure changes. 

A recovery runbook should include roles, responsibilities, system priorities, dependencies, recovery steps, vendor contacts, escalation paths, communication procedures, and validation steps. 

Start by identifying critical systems, reviewing dependencies, testing backups, validating communication plans, reviewing vendor recovery commitments, and building a prioritized 90-day roadmap.