Almost every organization says it has backups. Far fewer can say how long a full restore would take, whether the backups are protected from ransomware or when they last tried one. A backup that has never been restored is a hope, not a plan.
For a care facility, backups protect more than convenience. They support access to resident records, financial data and operational systems after a hardware failure, a fire, a flood or a cyberattack. HIPAA's Security Rule also requires a data backup plan and a disaster recovery plan as part of contingency planning.
A widely used guideline for backups is simple:
3 copies of your data: the original plus two backups
2 different types of storage: for example, a local backup device and cloud storage
1 copy offsite, away from your building
Many security professionals now add a fourth point: at least one copy should be offline or unchangeable, so ransomware cannot reach it.
A single backup can fail, be corrupted or be accidentally deleted. A second copy protects against that.
Two copies on the same device share the same risks. A power surge or a failed controller can damage both. Mixing a local disk with cloud storage spreads the risk.
A fire or tornado that destroys your building also destroys backups kept in the next room. Oklahoma and neighboring states know well that severe weather can take out a whole site, so geography matters.
Modern ransomware often looks for backups and encrypts or deletes them first. Immutable storage, which cannot be altered for a set period, or an offline copy, gives you a clean fallback.
Think about everything you could not easily recreate:
File servers and shared drives
Databases and applications that are hosted locally
Email and calendar data, which cloud providers do not always back up in the way you may assume
Configuration files for firewalls, switches and phone systems
Laptops or workstations that store unique files
If your EHR is hosted by a vendor, ask what backup and recovery commitments they provide, how often, and how quickly they can restore. Get it in writing.
Two terms help you decide how much protection you need:
Recovery point objective (RPO): how much data you can afford to lose, measured in time. If backups run nightly, you could lose up to a day of work.
Recovery time objective (RTO): how long you can be without a system before it seriously affects care or operations.
Ask each department head what they would do without a system for four hours, a day or a week. The answers determine backup frequency and which systems restore first.
A backup report that says successful tells you the job completed. It does not prove the data is usable. Build testing into your routine:
Restore a few random files monthly and confirm they open.
Once or twice a year, restore a full system to a test environment and time it.
Document the restore steps so someone other than one specific technician can follow them.
Record results and fix failures promptly.
Use separate credentials for backup systems, not the main administrator login.
Require multi-factor authentication on cloud backup consoles.
Encrypt backups, in transit and at rest, since they contain protected health information.
Restrict who can delete or change retention settings.
Monitor alerts so a failed job is noticed the next morning, not next month.
Backing up only to a drive plugged into the same server
Assuming cloud file sync is a backup
Never checking that backups include new systems or folders
Having no written restore procedure
Keeping a single unencrypted portable drive in a desk drawer
A good first exercise is simply to ask your IT provider: where are our backups, how old is the newest one, and when did we last test a restore? UnityCare IT designs and monitors backup and recovery for healthcare organizations, including restore testing. We are happy to review your current setup and point out gaps.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172