Every healthcare organization says it has backups. Fewer can say how long a full restore would take, whether the backups would survive a ransomware attack, or when they last tested one. A backup you have never restored is a hope, not a plan.
If you are choosing a new backup product or service, or reviewing the one you have, these questions will help you separate marketing from protection.
Before talking to any vendor, answer two questions for each important system:
Recovery time objective: how long can this system be down before care is affected? The EHR may need hours, an archive may tolerate days.
Recovery point objective: how much recent data can you afford to lose? One day of charting is a very different loss than one hour.
List the systems in priority order: EHR or EMR, medication systems, nurse call, phones, file servers, email, billing, and any local databases. Many organizations discover that some systems they depend on are not backed up at all.
Modern ransomware hunts for backups and deletes or encrypts them. Ask whether the product offers immutable storage, meaning data cannot be changed or deleted for a set period, or an air-gapped copy that is disconnected from your network.
The long-standing 3-2-1 guideline is three copies of data, on two types of media, with one offsite. Many experts now add one immutable or offline copy. Ask how the vendor meets that.
If an attacker who steals a domain administrator password can log in to the backup console and delete everything, you do not have a protected backup. Ask about separate credentials and multi-factor authentication on the console.
How long does a full restore take at our data size and internet speed? Ask for a realistic estimate, not a best-case figure.
Can you restore a single file, a mailbox or a whole server?
Can systems be started from a backup copy in the cloud or on a local appliance while the main problem is fixed?
Who performs the restore, and what is the support response at 2 a.m. on a Sunday?
Will the vendor sign a business associate agreement? If they will not, they cannot hold your patient data.
Is data encrypted in transit and at rest, and who holds the keys?
Where is the data stored, and can you get it back if you end the contract?
What does the vendor do with your data after termination?
Does it cover cloud services such as Microsoft 365 or Google Workspace? Many assume the provider backs up their mail and files. In general, those providers protect their infrastructure, but deleted or encrypted data in your account is largely your responsibility.
Does it cover laptops and workstations, or only servers?
Does it support the databases behind your clinical applications correctly, or just copy files?
Does it cover the EHR vendor's hosted data? If your EHR is cloud-hosted, ask the vendor in writing what they back up and how you can get your data out.
Will the vendor send alerts and a report when a backup fails?
Does the service include periodic test restores, and will you receive evidence?
How long is data retained, and does that match your record retention requirements?
Backup stored on a drive plugged into a server, always connected.
No restore test in the past year.
Vague answers about who can delete backups.
Pricing that excludes restores or charges heavily for retrieving your own data.
Write down your recovery objectives, what the product covers and the date of the last test. This supports your HIPAA contingency plan, which requires data backup, disaster recovery and emergency mode operation procedures.
UnityCare IT designs and monitors backup and recovery for healthcare organizations and can run a restore test so you know what to expect before you need it. If you are not sure what your current backups would recover, we can help you find out.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172