For years, healthcare cybersecurity conversations focused heavily on prevention.
How do we stop ransomware?
How do we block unauthorized access?
How do we protect electronic protected health information?
Those questions still matter.
But healthcare leaders are now asking another question, one that is just as important:
What happens if critical systems go down anyway?
That question sits at the center of recovery readiness.
Cyberattacks happen. Technology fails. Cloud services go offline. Vendors experience incidents. Storms, power events, and network outages interrupt operations. No healthcare organization can eliminate every disruption.
That is why resilience and recovery have become central to healthcare cybersecurity planning.
The proposed HIPAA Security Rule updates have drawn new attention to this issue, including proposed expectations for written procedures to restore certain relevant electronic information systems and data within 72 hours of loss. 1
For healthcare organizations, that conversation extends far beyond compliance.
It touches patient care, EHR access, phone systems, scheduling, billing, referrals, prescriptions, claims, network availability, cloud systems, vendor coordination, and staff communication.
Recovery is not just an IT function.
It is how the organization continues to serve patients when technology is under pressure.
At a Glance: 72-Hour Restoration Objective
- The 72-hour restoration objective is part of the proposed updates to the HIPAA Security Rule. It is not a current universal HIPAA requirement.
- HHS has proposed written procedures to restore certain relevant electronic information systems and data within 72 hours.
- Recovery planning is broader than backup storage. It includes systems, access, applications, workflows, vendors, communications, and people.
- EHR downtime, phone outages, network failures, and cloud interruptions can quickly affect patient care.
- Backups are important, but tested restoration procedures create confidence.
- Healthcare organizations should prioritize recovery based on the impact on patient care, not just on technical asset lists.
- DataTel’s HIPAA Readiness Assessment includes a clinical downtime impact calculator and a prioritized 90-day roadmap.
What Is the Proposed 72-Hour Recovery Objective?
The proposed 72-hour recovery objective refers to language in the HIPAA Security Rule NPRM that would require regulated entities to establish written procedures to restore certain relevant electronic information systems and data within 72 hours of loss. HHS also says the proposed rule would require organizations to analyze the relative criticality of relevant systems and technology assets to determine restoration priority. 1
That language has received attention because it is more specific than many recovery expectations healthcare organizations have historically planned around.
The current HIPAA Security Rule remains in effect today. The proposed updates are not final. HHS describes the current Security Rule as a national set of standards requiring covered entities and business associates to protect electronic protected health information through administrative, physical, and technical safeguards. 2
So the right response is not panic.
It is readiness.
Healthcare organizations should use the proposed 72-hour objective as a practical prompt for evaluating whether recovery plans align with the realities of patient care operations.
Simple Definition
The proposed 72-hour recovery objective is a proposed HIPAA Security Rule expectation for written procedures to restore certain relevant electronic information systems and data within 72 hours. It focuses on operational recovery, not just backup storage.
That distinction matters.
Healthcare organizations do not deliver care through backup files. They deliver care through systems, applications, communications platforms, workflows, vendors, and people.
A successful recovery requires all those pieces to work together.
What the Proposed Recovery Objective Does Not Mean
Many organizations hear “72-hour recovery” and immediately think of backups.
That interpretation is incomplete.
The proposed objective is not simply asking, “Do you have a copy of the data?”
It raises broader questions:
- Can critical systems be restored?
- Can users access those systems?
- Can clinicians access patient information?
- Can patients contact the practice?
- Can staff communicate internally?
- Can scheduling continue?
- Can prescriptions, referrals, claims, and billing move forward?
- Can operations continue safely while systems are being restored?
The focus is operational recovery.
For a broader explanation of the proposed rule and what remains current versus proposed, see Proposed HIPAA Security Rule Changes: What Healthcare Organizations Should Prepare for Now
Why Healthcare Organizations Are Paying Attention
Healthcare operations depend on technology availability.
A disruption to one critical platform can quickly ripple through several areas of the organization.
Electronic Health Records
Without EHR access, clinicians may struggle to:
- Review patient histories
- Check medications and allergies
- Document encounters
- Coordinate care
- Process orders
- Review treatment plans
EHR downtime can also affect patient safety, staff productivity, and documentation integrity. DataTel’s article on EHR Downtime in Mental Health and SUD Care explores how deeply downtime can affect care delivery in sensitive clinical settings.
Communications Systems
Phone downtime can create immediate pressure.
Patients may be unable to reach the practice. Staff may struggle to coordinate internally. Referrals may slow down. Appointment changes may not reach patients quickly. Call center teams may lose routing, queues, recordings, or reporting.
For healthcare organizations already using voice services, resilience planning becomes much broader than telecom. DataTel VoIP Business Phone and DataTel Contact Center support can help organizations think about phone continuity as part of patient access, not just phone uptime.
Networks and Internet Connectivity
Most healthcare systems depend on network availability.
Network or internet disruptions can affect:
- EHR platforms
- Cloud applications
- Imaging systems
- VoIP systems
- Patient portals
- Telehealth platforms
- Billing platforms
- Security monitoring
- Remote access
A cloud-based system is only useful if staff can reach it.
This is where DataTel Network, Server Management, and Cloud Management are integrated into recovery planning.
Revenue Cycle Operations
Downtime also affects the business side of care.
Technology disruptions may slow:
- Scheduling
- Claims
- Billing
- Payment posting
- Eligibility checks
- Prior authorization workflows
- Patient communications
- Referral coordination
Downtime creates clinical strain and operational costs. DataTel’s article, “The Hidden Cost of Downtime in Mental Health and Substance Use Disorder Care,” offers a closer look at how outages can affect both care delivery and business continuity.
Backup vs. Recovery: Why the Difference Matters
One of the most common misconceptions in healthcare cybersecurity is that backups guarantee recovery.
They do not.
Backups are essential. They preserve data. But recovery is the process of restoring systems, access, functionality, workflows, and operational capability.
A healthcare organization may have excellent backups and still face serious recovery problems if:
- Restoration procedures are undocumented.
- Recovery roles are unclear.
- Critical applications are missing from the plan.
- System dependencies are unknown.
- Backup restoration has never been tested.
- Vendor responsibilities are unclear.
- Staff do not know downtime workflows.
- Phones and networks are not included in recovery planning.
A backup answers one question:
Do we have a copy of the data?
Recovery answers a better question:
Can we restore operations quickly enough to support patient care?
Backup vs. Recovery
| Backup | Recovery |
| Preserves data | Restores operations |
| Creates copies of information | Restores systems, access, and workflows |
| Often automated | Requires planning, people, and testing |
| Supports resilience | Delivers resilience when validated |
| Can exist without testing | Requires restoration exercises |
| Answers “Do we have the data?” | Answers “Can we operate again?” |
Healthcare organizations often invest in backup systems but spend less time validating recovery.
The proposed HIPAA Security Rule updates highlight why that gap matters.
Why Downtime Is a Patient Care Issue
Cybersecurity discussions often focus on confidentiality and privacy.
Recovery planning adds another dimension: availability.
When systems become unavailable, patient care may be affected.
Healthcare organizations may experience:
- Delayed treatment
- Referral disruptions
- Scheduling delays
- Prescription workflow issues
- Documentation gaps
- Communication failures
- Reduced staff productivity
- Revenue cycle delays
- Patient frustration
This is why recovery planning belongs in executive conversations.
It is not simply about restoring servers.
It is about keeping care moving.
For a broader resilience strategy, see Healthcare Cyber Resilience: How to Reduce Risk Without Disrupting Patient Care
The Question Healthcare Leaders Should Be Asking
Instead of asking, “Do we have backups?”
Healthcare leaders should ask, “If a critical system became unavailable tomorrow, how quickly could we restore operations?”
That question often reveals the gap between data protection and true operational resilience.
A healthcare organization may discover that the EHR can be restored, but the phone system has no alternate routing plan.
Or that backups exist, but no one has tested restoration since the last infrastructure change.
Or that cloud vendors provide uptime documentation, but internal internet redundancy is weak.
Or that staff knows how to document downtime manually, but no one has tested how that information will be reconciled after restoration.
These are not abstract concerns.
They are readiness issues.
What Systems Must Healthcare Organizations Be Able to Recover?
When healthcare leaders think about disaster recovery, they often focus on the EHR.
That makes sense. The EHR is usually one of the most visible systems in the organization.
But modern healthcare operations depend on a much broader technology environment.
A strong recovery strategy should consider every system that affects patient care, operations, communications, and revenue.
EHR Recovery
EHR recovery is often the priority because it directly affects clinical work.
Healthcare organizations should evaluate:
Access to Patient Records
Ask:
- How quickly can records be restored?
- Can clinicians access critical patient information during downtime?
- Are alternate workflows documented?
- Can staff access recent medication, allergy, and treatment information?
Clinical Documentation
Ask:
- How will encounters be documented during downtime?
- How will notes be entered after restoration?
- How will documentation integrity be maintained?
- Who approves the reconciliation process?
Medication and Treatment Information
Ask:
- How will medication histories be accessed?
- How will allergy information be checked?
- How will treatment plans be reviewed?
- What happens if clinical decision support is unavailable?
EHR recovery is not only about the application.
It is about the clinical workflows around the application.
Communications Recovery: More Than Just Phones
Communications often become more important during a disruption, not less.
Patients need instructions. Staff need updates. Vendors need coordination. Leadership needs status reports. Clinical teams need clear direction.
Healthcare organizations should evaluate:
- Phone system resilience
- Failover capabilities
- Alternate call routing
- Contact center continuity
- Emergency communication procedures
- Patient notification options
- Internal communication channels
- Vendor escalation paths
Questions to ask include:
- What happens if our primary phone system fails?
- Can calls be redirected?
- Can patients still reach us?
- Can staff communicate internally?
- Can leadership communicate recovery priorities?
- Can referral partners reach the right contacts?
For organizations with patient access teams, DataTel Contact Center can support planning around call routing, queue visibility, reporting, and patient communication workflows.
Network and Internet Connectivity Recovery
Nearly every healthcare system depends on network availability.
Without network or internet access, staff may lose access to:
- EHR systems
- Cloud services
- VoIP platforms
- Imaging systems
- Patient portals
- Billing systems
- Telehealth platforms
- Security systems
- Remote access
Recovery planning should address both internal networks and external connectivity.
Internal Network Recovery
Evaluate:
- Network architecture
- Critical switches, firewalls, and access points
- Segmentation strategies
- Vendor access pathways
- Device dependencies
- Recovery procedures
Ask:
- Which network components must come back first?
- Which systems depend on which network services?
- Can critical systems be isolated during an incident?
- Are network diagrams current?
Internet Connectivity
Evaluate:
- Internet redundancy
- Failover options
- Carrier dependencies
- Firewall and routing dependencies
- Service restoration procedures
A cloud application does not help if users cannot connect to it.
Cloud and SaaS Recovery Considerations
Healthcare organizations increasingly rely on cloud-hosted and Software-as-a-Service platforms.
Common examples include:
- EHR systems
- Practice management systems
- Patient communication platforms
- Collaboration platforms
- Billing systems
- Security platforms
- Backup platforms
Many organizations assume cloud providers automatically solve recovery challenges.
That assumption can create risk.
Cloud providers may manage infrastructure resilience, but healthcare organizations still need to understand access, configuration, data retention, recovery commitments, incident communication, identity controls, and vendor responsibilities.
Ask cloud providers:
- What are your recovery objectives?
- How often are backups performed?
- How are restoration procedures tested?
- What geographic redundancy exists?
- How will we receive incident updates?
- What access controls protect our environment?
- What evidence can you provide?
Vendor resilience is part of organizational resilience. For a deeper discussion of vendor readiness, see “Are BAAs Enough for HIPAA?” What Healthcare Organizations Should Ask Vendors and Business Associates
Medical Device Recovery Planning
Medical devices sometimes receive less attention during recovery planning, especially in smaller or mid-sized healthcare organizations.
That can be a mistake.
Many devices now depend on:
- Network connectivity
- Vendor platforms
- Cloud integrations
- Centralized management systems
- Local servers
- Identity and access controls
- Support contracts
Healthcare organizations should understand:
- Which devices depend on network access
- What happens if connectivity is lost
- Which vendors support device recovery
- What alternate workflows exist
- Which devices are critical to patient care
- Whether device downtime procedures are documented
Medical device planning should not sit outside the recovery strategy.
It should be part of the same resilience conversation.
Recovery Testing Matters More Than Recovery Documentation
Most healthcare organizations have some form of recovery documentation.
Fewer have tested it recently.
That distinction matters.
A recovery plan is a hypothesis until it has been tested.
Testing shows whether the plan works in the real environment, with real dependencies, real vendors, real timing constraints, and real people involved.
What Recovery Testing Reveals
Recovery exercises often uncover:
- Missing steps
- Outdated documentation
- Unclear roles
- Technology dependencies
- Communication gaps
- Vendor delays
- Resource limitations
- Access problems
- Unexpected system order requirements
- Documentation and evidence gaps
These discoveries are not failures.
They are opportunities to improve before a real outage occurs.
For organizations focused on proof and audit readiness, HIPAA Policies Are Not Enough: What Evidence Healthcare Organizations Need to Prove Readiness explains why testing records, recovery evidence, and documentation matter.
Types of Recovery Testing
Healthcare organizations can test recovery in several ways.
| Test Type | What It Evaluates | Why It Matters |
| Tabletop exercise | Decision-making, escalation, communication, roles | Helps leaders and staff practice response without affecting systems |
| Technical recovery test | Backup restoration, system recovery, application availability | Validates whether systems can be restored |
| Operational downtime exercise | Clinical workflows, patient communication, scheduling, manual processes | Tests whether the organization can keep serving patients |
| Vendor coordination review | Escalation paths, service commitments, response timing | Identifies third-party dependency gaps |
| Communications drill | Phone routing, internal messaging, patient notices | Confirms people can communicate when primary systems fail |
The goal is confidence.
Not theoretical confidence.
Operational confidence.
Recovery Runbooks: Turning Plans into Action
During a disruption, complex documents are hard to use.
People need clarity.
A recovery runbook provides step-by-step guidance for restoring systems and supporting operations. It should be practical enough for teams to use under pressure.
Effective recovery runbooks often include:
Roles and Responsibilities
Define:
- Recovery leaders
- Technical owners
- Communications leads
- Executive stakeholders
- Vendor contacts
- Clinical operations contacts
- Compliance contacts
Recovery Procedures
Document:
- Restoration steps
- System dependencies
- Prioritization sequences
- Escalation paths
- Required credentials
- Decision points
- Validation steps
Communication Plans
Include:
- Internal communication procedures
- Vendor communication procedures
- Patient communication guidance
- Leadership update cadence
- Contact lists
- Alternate channels
The best recovery plans are often simple, current, and easy to use.
During a crisis, clarity matters more than complexity.
The Most Common Recovery Planning Mistakes
Healthcare organizations often make the same recovery planning mistakes.
Mistake 1: Assuming Backups Equal Recovery
Backups support recovery. They do not guarantee recovery.
Restoration must be tested.
Mistake 2: Focusing Only on Technology
Recovery requires people, processes, communications, vendors, and leadership.
Technology is one part of the work.
Mistake 3: Ignoring Dependencies
Applications rarely operate alone.
An EHR may depend on identity systems, internet connectivity, integrations, local devices, vendor portals, and network infrastructure.
Mistake 4: Never Testing Recovery Procedures
Untested plans often fail when they are needed most.
Testing turns assumptions into evidence.
Mistake 5: Overlooking Communications
Some organizations focus on systems and forget how staff, patients, providers, vendors, and leadership will communicate during downtime.
That gap can slow recovery and increase confusion.
Mistake 6: Treating Vendors as Separate from Recovery
Vendors are part of the operating environment.
If a vendor supports EHR access, communications, cloud systems, backups, phones, billing, or cybersecurity, their recovery capabilities matter.
The Goal Is Operational Continuity
The purpose of recovery planning is not simply restoring servers.
The goal is to maintain the ability to serve patients.
Healthcare organizations should evaluate recovery through a practical lens:
Can we continue delivering care while technology is being restored?
That question changes the conversation.
It brings clinical operations, communications, IT, compliance, leadership, and vendors into the same room.
It also helps organizations prioritize what matters most.
For decision-stage leaders evaluating whether their current provider can support that level of coordination, see How to Choose a Healthcare IT, Cybersecurity, and Communications Provider
Healthcare Recovery Maturity Model
Recovery readiness develops in stages.
Understanding where your organization stands can help prioritize next steps.
| Maturity Level | Characteristics | Practical Concern |
| Level 1: Reactive | Limited documentation, unclear ownership, untested backups, informal downtime workflows | Recovery depends on individual knowledge |
| Level 2: Documented | Plans exist, critical systems are listed, basic roles are assigned | Documentation may not be validated |
| Level 3: Tested | Recovery exercises occur, restoration is validated, lessons learned are documented | The organization is moving from assumption to evidence |
| Level 4: Managed | Recovery metrics, executive reporting, vendor reviews, and improvement processes exist | Recovery becomes an operational discipline |
| Level 5: Resilient | Continuity, cybersecurity, vendor management, communications, and recovery are integrated | The organization focuses on maintaining patient care, not just restoring systems |
The goal is not to jump from Level 1 to Level 5 immediately.
The goal is steady improvement.
Recovery Readiness Checklist
Healthcare organizations evaluating recovery maturity should review the following areas.
Governance
- Have recovery responsibilities been assigned?
- Are recovery plans documented?
- Are recovery objectives defined?
- Are critical systems prioritized?
- Does leadership receive recovery readiness updates?
Technology
- Are backups tested?
- Have restoration procedures been validated?
- Are network recovery procedures documented?
- Are cloud dependencies understood?
- Are identity systems included in recovery planning?
- Are endpoint and device dependencies documented?
Operations
- Are downtime workflows documented?
- Can patient care continue during disruptions?
- Can scheduling, billing, referrals, prescriptions, and claims continue?
- Are communication procedures established?
- Have alternate workflows been tested?
Vendors
- Are vendor recovery capabilities understood?
- Have critical vendor dependencies been identified?
- Are escalation procedures documented?
- Are service commitments reviewed?
- Are business associates periodically evaluated?
Testing
- Are tabletop exercises conducted?
- Are technical recovery tests performed?
- Are communications drills completed?
- Are lessons learned documented?
- Are corrective actions tracked?
Organizations that answer “no” to several of these questions have a clear opportunity to strengthen resilience.
What Healthcare Leaders Should Do in the Next 90 Days
Recovery readiness can feel overwhelming.
A 90-day plan helps organizations make progress without trying to solve everything at once.
Days 1 to 30: Build Visibility
Start by understanding what must be restored first and why.
Recommended activities:
- Identify critical systems.
- Inventory operational dependencies.
- Review EHR, phone, network, cloud, and vendor dependencies.
- Document recovery objectives.
- Evaluate current recovery plans.
- Review backup reports.
- Identify patient care workflows affected by downtime.
- Review recent incidents or near misses.
Estimate your clinical downtime exposure with DataTel’s HIPAA Readiness Assessment and downtime impact calculator.
Days 31 to 60: Validate Assumptions
Move from documentation to evidence.
Recommended activities:
- Conduct a tabletop exercise.
- Review backup restoration procedures.
- Validate communication plans.
- Evaluate downtime workflows.
- Review vendor recovery commitments.
- Test call routing or failover options.
- Review network and internet redundancy.
- Document findings and ownership.
This is also the right time to review whether recovery is connected to broader risk analysis. For guidance, see HIPAA Risk Analysis vs. Vulnerability Scan: What Healthcare Practices Often Miss
Days 61 to 90: Strengthen Resilience
Focus on improvements with the greatest operational impact.
Examples include:
- Expanding recovery testing
- Improving recovery runbooks
- Strengthening communication procedures
- Updating vendor escalation paths
- Formalizing evidence collection
- Improving executive reporting
- Addressing high-risk technical safeguards
- Updating remediation plans
For technical readiness, leaders may also want to review Does HIPAA Require MFA, Encryption, Vulnerability Scanning, and Network Segmentation?
How DataTel Helps Healthcare Organizations Improve Recovery Readiness
Many healthcare organizations understand that recovery matters.
The difficult part is bringing together EHR access, phones, networks, cloud systems, cybersecurity, vendors, backups, and operations into a single practical plan.
DataTel helps healthcare organizations evaluate and improve readiness across the systems that support care.
Managed IT and Infrastructure Support
DataTel Fully Managed IT helps healthcare organizations manage the operational foundation behind recovery readiness, including devices, networks, servers, cloud environments, support processes, and vendor coordination.
Cybersecurity Readiness
DataTel Cybersecurity supports risk reduction, monitoring, access controls, endpoint visibility, vulnerability management, and incident readiness.
Network, Server, and Cloud Support
Network and Server Management and Cloud Management help organizations understand the dependencies behind applications, communications, and recovery planning.
Voice and Patient Communications
VoIP Business Phone and Contact Center support communication continuity, call routing, and patient access planning.
The goal is not to create a recovery plan that sits unused.
The goal is to help healthcare organizations keep care moving when systems, vendors, or infrastructure are under strain.
Take DataTel’s Free HIPAA Readiness Assessment
Recovery planning has become a critical part of healthcare cybersecurity readiness.
Take DataTel’s free HIPAA Readiness Assessment to evaluate your organization across:
- Recovery and resilience
- Access controls
- Compliance and audit readiness
- Governance and risk
- Communications readiness
The assessment includes readiness scoring, a clinical downtime impact calculator, and a prioritized 90-day roadmap.
Start here: Take the HIPAA Readiness Assessment
Frequently Asked Questions
What is the proposed 72-hour recovery objective?
The proposed HIPAA Security Rule updates include expectations for written procedures to restore certain relevant electronic information systems and data within 72 hours of loss.
Does HIPAA currently require recovery within 72 hours?
The current HIPAA Security Rule does not contain a universal 72-hour restoration requirement. The 72-hour objective is associated with the proposed updates to the HIPAA Security Rule currently under consideration.
Are backups enough for recovery?
No. Backups are important, but they do not guarantee operational recovery. Healthcare organizations also need restoration procedures, testing, communication plans, vendor coordination, documented responsibilities, and downtime workflows.
What is the difference between backup and recovery?
Backups preserve information. Recovery restores systems, access, functionality, workflows, and operational capability.
What systems should healthcare organizations prioritize during recovery?
Priorities often include EHR systems, phone systems, contact centers, network infrastructure, internet connectivity, patient scheduling, billing, claims, prescriptions, referrals, identity systems, cloud platforms, and critical clinical applications.
Why does EHR downtime planning matter?
EHR downtime can affect patient records, medication information, allergy checks, documentation, orders, treatment plans, referrals, and clinical decision-making.
Why do phone systems matter in healthcare recovery planning?
Phone systems support patient access, scheduling, referrals, internal coordination, emergency communication, and patient updates. During downtime, communication often becomes more important, not less.
How often should recovery procedures be tested?
Healthcare organizations should periodically test recovery procedures and review them after major system, vendor, operational, or infrastructure changes.
What should a recovery runbook include?
A recovery runbook should include roles, responsibilities, system priorities, dependencies, recovery steps, vendor contacts, escalation paths, communication procedures, and validation steps.
How can healthcare organizations start improving recovery readiness?
Start by identifying critical systems, reviewing dependencies, testing backups, validating communication plans, reviewing vendor recovery commitments, and building a prioritized 90-day roadmap.