Ask most administrators whether their data is backed up and the answer is yes. Ask when the last restore test was performed and the room often goes quiet. A backup you have never restored is a hope, not a plan.
For healthcare organizations, backups protect more than convenience. They protect resident records, billing history, scanned documents and the ability to keep operating after ransomware, hardware failure, fire or a simple mistake.
A long-standing guideline for backup design is easy to remember:
Keep at least three copies of your data. That includes the original and two backups.
Store copies on at least two different types of media or systems, for example a local appliance and cloud storage.
Keep at least one copy offsite, away from the building.
Many security professionals now add more. One copy should be offline or immutable, meaning it cannot be changed or deleted for a set period even by someone with administrator credentials. This matters because ransomware often looks for and destroys backups before announcing itself.
Make a list rather than assuming. Common items include:
File servers and shared drives
Databases for your EHR or billing system, where you host them yourself
Email and calendars, which cloud providers do not back up the way many people assume
Cloud applications that your organization depends on
Configuration files for firewalls, switches and phone systems
Laptops of key staff, where important files may be stored locally
If your EHR is hosted by the vendor, ask in writing how they back up your data, how long they retain it and how quickly they can restore it. Your obligations under HIPAA, including the contingency plan standard, apply even when a vendor holds the data.
How much data can you afford to lose? If backups run nightly, you could lose up to a day of work. For some systems that is acceptable. For others, it is not.
How long can the system be down before it seriously harms operations? Restoring terabytes from the cloud over a modest internet connection may take far longer than people expect.
Ask the people who use each system to help answer these questions. Nursing leadership can tell you what a day without the EHR means; the business office can explain billing deadlines.
A monthly or quarterly test is ideal. Choose a few files and restore them to a different location. At least once a year, test restoring an entire system to confirm the process, the documentation and the timing. Record the result and keep it with your contingency plan.
Common problems discovered during tests include backups that silently failed months ago, missing encryption keys, systems nobody remembered to include, and recovery steps that only one person understood.
Encrypt backups in transit and at rest.
Use separate credentials for backup systems, with multifactor authentication.
Keep backup servers off the regular domain where practical.
Monitor for failed jobs and have someone accountable for reviewing alerts.
Keep at least one copy that cannot be altered by an attacker on your network.
In a major incident you cannot restore everything at once. Decide in advance which systems come first, for example identity services, the EHR, phones, file shares and then lower priority tools. Write down dependencies, because many systems need others to be running first.
Relying on a single external drive plugged in all the time
Assuming a file-sync service such as a shared drive is a backup, when deleted or encrypted files may sync as well
Never checking logs for failures
Forgetting departed employees who were the only people with the keys or passwords
UnityCare IT designs, monitors and tests backup systems for healthcare organizations. If you are not sure when your last successful restore happened, we can run a test with you and tell you plainly where you stand.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034