Ask most administrators whether their data is backed up and the answer is a confident yes. Ask when someone last restored a file, a server or an entire system from that backup, and the room gets quiet. A backup that has never been tested is a hope, not a plan.
For healthcare providers, reliable backups serve two purposes. They protect resident records, billing data and operational files from hardware failure, mistakes and disasters. They also provide the best defense against ransomware, where the attackers' leverage disappears if you can restore cleanly.
A widely used guideline for backups is the 3-2-1 rule:
3 copies of your data: the original plus two backups
2 different types of storage, such as a local appliance and cloud storage
1 copy off-site and separated from your main network
Many security professionals now add a fourth idea: at least one copy should be immutable or offline, meaning it cannot be altered or deleted even by someone with administrator credentials. Modern ransomware often hunts for backups and deletes them before encrypting the main systems, so a backup reachable from the same network login as everything else may not survive an attack.
Make a list, because gaps often hide in places nobody thinks about.
File servers and shared drives
Databases and servers that support clinical or billing software, where you host any on-site
Email and cloud documents. Cloud services like Microsoft 365 and Google Workspace have strong availability, but they do not necessarily provide the retention and recovery options you may want. Review what your plan includes.
Configuration files for firewalls, switches and wireless equipment, which make rebuilding much faster
Laptops and workstations that store files locally
Anything your EMR vendor does not host and back up for you
If your EMR is a cloud service such as PointClickCare, ask the vendor what they back up, how often, and what recovery commitments they make. You remain responsible for planning how you would operate and access information if the service were unavailable.
Two terms help set expectations:
Recovery point objective (RPO): how much data you can afford to lose, measured in time. Nightly backups mean you could lose up to a day of work.
Recovery time objective (RTO): how long you can be down before the impact becomes unacceptable.
Ask department heads, not just IT, what these numbers should be. The director of nursing may have a very different tolerance for lost documentation than the marketing coordinator, and your backup design should reflect that.
Testing is the step most often skipped. A simple routine looks like this:
Monthly: restore a few random files and open them.
Quarterly: restore a full folder or application to a test location and confirm it works.
Annually: run a larger exercise, such as restoring a key server in a test environment and timing how long it takes.
Document each test: date, what was restored, who did it, how long it took and any problems. That record helps with HIPAA contingency planning, which expects data backup, disaster recovery and emergency mode operation planning, and with cyber insurance applications that increasingly ask about backup testing.
Backups on the same network, with the same admin password. One compromised account can erase both.
Success emails nobody reads. Someone should review alerts and confirm that jobs finish.
Backing up the data but not the instructions. Keep documented steps, license keys and vendor contacts.
No encryption. Backups contain the same protected health information as live systems and should be encrypted in transit and at rest.
Forgetting retention. Some problems, like slow-moving corruption or an attacker lingering for weeks, are only discovered later. Keep enough history to go back.
Use separate credentials for backup systems, with multi-factor authentication where possible
Restrict who can delete or change backup settings
Keep at least one copy that is air-gapped, immutable or otherwise out of reach of the production network
Monitor for unusual events such as sudden deletions or changed retention settings
If you cannot answer when your last successful restore test was, that is your first task. UnityCare IT helps healthcare organizations design backups around the 3-2-1 approach, set recovery targets that match clinical needs, and run regular restore tests so you know the plan works before you need it.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172