Disaster Recovery Planning and CMS Emergency Preparedness

Oklahoma, Texas and Arkansas facilities know that severe weather, tornadoes, ice storms and power outages are part of the landscape. Long-term care providers that participate in Medicare and Medicaid must meet CMS emergency preparedness requirements, which include a risk assessment, policies and procedures, a communication plan and training and testing. Technology touches every one of those elements, yet IT recovery is sometimes treated as a separate topic. Connecting the two makes both stronger.

What CMS expects, in brief

The CMS emergency preparedness rule for long-term care facilities calls for four core elements:

An emergency plan based on a facility-based and community-based risk assessment, using an all-hazards approach

Policies and procedures that address the risks identified, including subsistence needs, evacuation, sheltering in place and the tracking of residents and staff

A communication plan that covers contacting staff, residents' families, physicians and other officials

Training and testing, including exercises, with review and updates at least annually

The rule also expects a system of medical documentation that preserves resident information, protects confidentiality and keeps records secure and available. That is directly an IT concern.

Where IT fits into the plan

Risk assessment

Include technology hazards alongside weather: loss of power, loss of internet, loss of the EHR, ransomware, server failure and loss of a building. For each, record which operations would be affected.

Records and documentation

Identify how resident information is protected and made available during an emergency.

Where does the EHR live, and can you reach it from another location?

Can you print current medication lists, face sheets, diagnoses, allergies and emergency contacts regularly, and keep them in a secure location for evacuation?

Are backups stored offsite, and how would you access them?

Who has the authority and the credentials to restore systems?

Communication

Keep updated, printed contact lists for staff, physicians, pharmacies, families and vendors

Confirm how you would communicate if phones or internet fail, such as cell phones, satellite options, or a mass notification service

Include your IT provider's emergency contacts and escalation paths

Power and connectivity

Determine which network equipment and workstations are on generator power

Use battery backup for critical devices so that systems run through the transfer

Plan for backup internet, such as a cellular connection, and test it

Write a simple IT recovery plan

An IT disaster recovery plan does not need to be long. A few pages can be enough if they are specific.

Critical systems list: Ranked by importance, with the maximum tolerable downtime for each

Dependencies: What each system needs to run, such as power, internet, a particular server or a vendor

Recovery steps: Who does what, in what order, with contact numbers

Backup locations: Where backups are stored and how to retrieve them

Alternate work arrangements: How staff would chart and communicate with limited technology

Decision points: When to declare a disaster and who decides

Keep a printed copy offsite and in the administrator's emergency binder.

Downtime procedures for clinical teams

Technology outages happen even in good weather. Prepare paper forms, a regularly updated printout of medication administration records and current orders, and a process for entering information after systems return. Train staff to use them, and practice on a quiet shift.

Test it

CMS expects annual testing through exercises. Consider including an IT component.

A tabletop exercise that walks leadership through a scenario, such as a tornado that damages the building or a ransomware attack that takes down the EHR

A restoration test of backups

A failover test of your backup internet or generator

A call tree test to see how quickly staff can be reached

After each exercise, write down what went well, what did not and who will fix each problem by when. Update the plan and share changes with staff.

HIPAA connection

The HIPAA Security Rule requires a contingency plan, including a data backup plan, a disaster recovery plan and an emergency mode operation plan. A well-built emergency preparedness program with IT elements helps satisfy both frameworks, and documentation can support each.

Getting started

Pick the single most likely technology disruption for your facility, perhaps a power outage or loss of internet, and trace what would happen hour by hour. The gaps you find are your first action items. UnityCare IT works with long-term care providers on disaster recovery planning, backup testing and exercises, and can help align your IT documentation with your emergency preparedness program.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172