When ransomware hits a care facility, the first question is always the same: do we have a backup? The second question, which people discover too late, is whether the backup still works and whether the attacker could reach it. Modern ransomware groups know that backups are the thing standing between you and a ransom payment, and they often try to delete or encrypt them first.
A solid backup strategy is not complicated, but it has a few specifics that matter. Here is how to think about it.
The long-standing guideline is simple:
Keep at least three copies of your important data
Store them on at least two different types of media or systems
Keep at least one copy offsite
Many security teams now add two more points: keep one copy immutable or offline, and verify that it can be restored. That brings the rule to 3-2-1-1-0, where the last number stands for zero restore errors.
A fire, a flood, a tornado or a burst pipe that damages your server closet will also damage a backup drive sitting next to it. Offsite copies, whether in a secure cloud service or a geographically separate location, protect against local disasters.
An immutable backup cannot be changed or deleted for a set retention period, even by an administrator. If an attacker steals an admin password, they still cannot wipe those copies. Many cloud backup services and some on-site appliances offer this feature. An offline copy, such as a drive that is disconnected after each backup, achieves a similar result, though it takes more manual discipline.
Think beyond the EHR. A typical facility depends on several systems:
Your EHR or EMR data, including any locally hosted components or interfaces
File shares with policies, schedules, forms and resident documents
Email and calendars, if hosted in a cloud service (cloud providers keep their own copies, but those are not a substitute for a backup you control)
Accounting, payroll and billing systems
Server configurations, firewall settings and network device configurations
Phone system and door access system configurations
If you use a cloud EHR, ask the vendor what they back up, how often and what your recovery options are. Do not assume.
Two terms help you decide how much protection you need:
Recovery point objective (RPO): how much data can you afford to lose? If your last backup is from last night, you may lose a full day of documentation.
Recovery time objective (RTO): how long can you operate without the system? Most facilities can work on paper for a short period, but not for a week.
Ask your administrator and director of nursing how long paper downtime procedures can realistically last. That answer should drive your backup frequency and your recovery plan.
An untested backup is a hope, not a plan. Many organizations discover failed or incomplete backups only during an emergency. A simple testing routine:
Each month, restore a handful of random files from backup to a separate location and confirm they open.
Each quarter, restore a full server or application into a test environment and confirm it starts.
At least once a year, run a recovery exercise that includes people, not just technology: who makes the call, who contacts the EHR vendor, who informs families, and how long it really takes.
Keep a written record of each test. This also supports the HIPAA contingency planning requirements, which call for a data backup plan, a disaster recovery plan and an emergency mode operation plan.
Use separate credentials for backup administration and require MFA
Do not leave backup storage mapped as a drive on regular workstations
Alert on failed jobs and on unusual deletions
Encrypt backups, both in transit and at rest, so a lost drive or a cloud breach does not become a HIPAA incident
Limit who can change retention settings
Relying on a single external drive attached to the server
Backing up only the server and forgetting about cloud applications
Never checking the backup status reports
Keeping the only offsite copy on a staff member's home computer
Assuming that backup equals disaster recovery. Backups are data. Recovery also requires hardware, networking, licenses and people who know the steps.
If you cannot answer when your last successful restore test happened, that is your starting point. UnityCare IT designs and monitors backup and recovery for healthcare organizations, including immutable offsite copies and documented restore tests, and we can review your current setup and show you where the gaps are.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034