Backups are the last line of defense when ransomware, hardware failure, fire or a simple mistake destroys data. They are also one of the most commonly misunderstood parts of IT. Many facilities believe they are protected because a backup job runs every night, only to discover during an emergency that the backup was incomplete, encrypted along with everything else, or impossible to restore quickly.
The 3-2-1 rule is a simple framework that avoids most of those failures.
3 copies of your data: the original plus two backups.
2 different types of storage: for example, a local appliance and a cloud service, rather than two drives of the same kind in the same cabinet.
1 copy offsite: away from the building, so a fire, flood or tornado does not take everything.
Many security teams now add a fourth idea: at least one copy should be immutable or offline, meaning it cannot be changed or deleted by an attacker who gets into your network. Ransomware operators often look for and destroy backups first.
Start by listing what you would need to keep operating:
Shared drives with administrative, HR and billing documents
Scanned resident records and eFax archives
Email and calendars
Servers that run local applications
Configuration files for firewalls, switches and Wi-Fi
Any locally hosted databases
If your EHR is cloud-hosted, such as a vendor-hosted PointClickCare environment, ask the vendor in writing what they back up, how often and how restores work. Do not assume that cloud means backed up in the way you need. Cloud email and file-sharing services also have limits on how long deleted items can be recovered.
Two questions guide everything:
How much data can we afford to lose? If the answer is "no more than a day of work," nightly backups may be enough. If it is an hour, you need more frequent ones.
How long can we be down? A facility that must document care continuously needs a faster recovery plan, plus paper downtime procedures, than a back office that can wait a day.
Use separate credentials for backup systems, and require multi-factor authentication.
Do not leave a backup drive permanently mapped on every computer; ransomware will encrypt it.
Encrypt backups, since they contain protected health information.
Keep at least one copy that cannot be altered from your regular network.
A backup you have never restored is a hope, not a plan. Build testing into the calendar:
Monthly: restore a few random files and confirm they open.
Quarterly: restore a full folder or a virtual server to a test location.
Annually: walk through a full recovery scenario with the people who would be involved, including administrators.
Document the results. HIPAA's contingency plan requirements call for data backup, disaster recovery and emergency mode operation plans, and testing evidence helps show you take them seriously.
Backing up only servers and forgetting laptops, scanners or key business office computers
Never checking backup failure alerts
Keeping the only backup in the same building as the server
Relying on a single person who knows how restores work
Assuming file sync services such as shared folders are the same thing as backup
List what data matters most and where it lives
Confirm there are at least three copies, two storage types and one offsite
Confirm one copy is protected from deletion by an attacker
Assign someone to review backup reports weekly
Schedule and document restore tests
Store recovery instructions where they can be found when the network is down
UnityCare IT designs and monitors backup and recovery for healthcare organizations, including restore testing and documentation. If you are not sure your backups would hold up in a real emergency, we can help you find out before you need them.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172