Ask most administrators whether their organization has backups and the answer is yes. Ask when the last successful restore was tested and the room often goes quiet. Backups are your last line of defense against ransomware, hardware failure, accidental deletion and disasters, and they only count if you can recover real data in a reasonable amount of time.
A widely used guideline is the 3-2-1 rule:
Keep at least three copies of important data: the original and two backups
Store them on at least two different types of storage, such as a local appliance and cloud storage
Keep at least one copy offsite, away from your building and your network
Many security teams now add a modern twist: at least one copy should be immutable or offline, meaning ransomware and a compromised administrator account cannot alter or delete it. Attackers frequently look for backups first so that you cannot recover without paying.
Start with a list of systems and data, then rank them by how badly operations would suffer without them.
Your EHR data, whether it is hosted by a vendor or stored locally
File servers and shared drives with admissions, HR and billing files
Email and calendar data
Phone system configurations and recordings
Network device configurations, such as firewall and switch settings
Security camera and door-access data if you rely on it
Laptops and workstations that hold unique local files
If your EHR is cloud-hosted, ask the vendor how they back up data, how long they retain it and what recovery options exist. Do not assume a hosted service covers every need. Most vendors also describe responsibility for your own data in their agreements, so read them.
Two terms help set expectations.
Recovery point objective is how much data you can afford to lose, measured in time. If backups run nightly, you could lose up to a day of work.
Recovery time objective is how long you can be down before the effect is unacceptable.
Ask your leadership and clinical team to define these for each major system. A billing database and a medication record may have very different answers. Your backup design should then match them.
A backup job that reports success only tells you that files were written. Testing tells you they can be used.
Restore a handful of random files every month and confirm they open
Once or twice a year, restore a full system into a test environment
Time the restore and compare it with your recovery time objective
Record the result, the person who did it and any problems found
Keep these test records. They support your HIPAA contingency planning documentation, which expects data backup and disaster recovery procedures.
Encrypt backups in storage and in transit
Use separate credentials for backup systems, with multi-factor authentication
Keep backup systems off your regular domain login if possible
Restrict who can delete or change retention settings
Monitor for failed jobs and alert someone who will act
Backing up only to a drive that is always attached to the network, so ransomware encrypts it too
Relying on a staff member who takes a drive home, with no encryption or log
Never checking alerts for failed jobs
Forgetting cloud services, since many assume email and file sharing platforms are automatically protected against every loss
Having no written steps for who restores what and in which order
On one page, list the order in which systems come back, who is responsible, vendor contact numbers and where the instructions are stored. Keep a printed copy, because you may not be able to open a digital copy during an outage.
If you cannot say with confidence when you last restored data, that is the place to start. UnityCare IT designs and monitors backup and recovery for healthcare and senior-living organizations, including restore testing and documentation, and can review your current setup against the 3-2-1 approach.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172