9.8 Abbreviation Policies, Professional Standards & EHR Downtime Procedures
Key Takeaways
- Organizations must maintain an approved abbreviation list and a Do Not Use list, and prohibited abbreviations apply to orders and medication-related documentation.
- Professional standards for health records require entries that are accurate, complete, timely, legible, authenticated, and never altered to conceal.
- Downtime may be planned or unplanned, and both require pre-positioned paper forms, printed patient lists, and a defined communication tree.
- Downtime documentation is reconciled into the EHR after restoration, entered with the actual date and time of care and identified as a late entry.
- Data backup, disaster recovery, and emergency mode operation plans are Required implementation specifications of the Security Rule's Contingency Plan standard.
Three test plan tasks converge on documentation discipline under pressure: task 4.A (adhere to professional standards of care as they pertain to health records), task 4.J (comply with regulations regarding the use of abbreviations in the EHR system), and task 4.K (initiate down-time procedures related to the EHR, including data recovery). Knowledge statements 4.K14 (acceptable abbreviation practices), 4.K15 (data backup and recovery methods), and 4.K16 (data storage guidelines) support them.
Abbreviation Governance
Every accredited organization maintains two lists, and the distinction is testable.
- The approved abbreviation list enumerates the abbreviations, acronyms, and symbols that may be used in the organization's records. Anything not on it is spelled out. The list exists because the same abbreviation means different things in different specialties — PT is physical therapy, prothrombin time, or patient depending on context.
- The Do Not Use list enumerates abbreviations that are prohibited because they have caused harm. The Joint Commission's official list applies to all orders and all handwritten, medication-related documentation, and organizations often extend it to all documentation:
| Prohibited | Confused With | Write Instead |
|---|---|---|
| U, u | 0, 4, cc | "unit" |
| IU | IV, the number 10 | "International Unit" |
| Q.D., QD, q.d., qd | QOD; the period looks like an I | "daily" |
| Q.O.D., QOD, q.o.d., qod | QD | "every other day" |
| Trailing zero (1.0 mg) | 10 mg if the decimal is missed | "1 mg" |
| No leading zero (.5 mg) | 5 mg if the decimal is missed | "0.5 mg" |
| MS, MSO4, MgSO4 | Morphine sulfate vs. magnesium sulfate | Full drug name |
Additional abbreviations on The Joint Commission's "possible future inclusion" list — such as > and < for greater/less than, drug name abbreviations, apothecary units, @, cc, and µg — are commonly prohibited by organizational policy.
Enforcing it in the EHR
The EHR is the enforcement mechanism: build prohibited strings into dictionary blocks and order-entry validations, remove them from pick lists and order sentences, strip them from templates and smart phrases, and audit free-text fields for their appearance. Section 6.2 covers the documentation review that catches what the system misses.
Professional Standards for Health Record Entries
Task 4.A is broad, but the operative standards are consistent across accreditors and payers. An entry must be:
- Accurate — reflecting what actually occurred
- Complete — containing all required elements for the entry type
- Timely — made at or near the time of the event, within the timeframe policy defines
- Legible and comprehensible — including approved abbreviations only
- Authenticated — signed by the author, with cosignature where required
- Attributable — made under the author's own unique credentials
- Unaltered — corrections made by erratum or addendum, never by deletion, overwriting, or backdating (Section 3.4)
- Objective — recording facts and clinical observations, not personal opinions about the patient or disparaging remarks
The prohibitions matter as much as the requirements: never document care that was not provided, never chart in advance, never alter a record after learning of a claim or request, and never document under another person's credentials.
Downtime: Planned and Unplanned
| Type | Cause | Notice |
|---|---|---|
| Planned | Upgrades, maintenance, infrastructure work | Scheduled and communicated in advance (Section 4.6) |
| Unplanned | Hardware failure, network outage, power loss, ransomware, natural disaster | None |
Preparation, before anything breaks
- Downtime forms — paper registration, order, progress note, MAR, and result forms pre-positioned in every department
- Downtime reports — automatically generated and printed or written to a standalone downtime computer on a schedule (commonly every few hours), containing the current census, active orders, allergies, and medication lists
- Downtime computer or read-only viewer kept current so staff can at least read recent data
- Communication tree — who declares downtime, who notifies departments, how updates are issued when email is down
- Practiced procedures — drills, because a plan no one has executed fails on the first real event
During downtime
- Declare and communicate through the defined channel; state which systems are affected and the expected duration.
- Switch to paper, using the downtime forms with the patient's identifiers written on every page.
- Use the last downtime report for allergies, medications, and active orders.
- Record the actual date and time of every action on paper, because these times, not the entry times, are the clinical record.
- Batch and sequence paper documentation so it can be entered in order after restoration.
- Escalate safety issues — a critical result during downtime is communicated by phone and documented on paper.
- Log the downtime: start time, systems affected, workarounds used, and end time.
After restoration — downtime reconciliation
- Confirm systems are stable and interfaces have caught up before entering the backlog.
- Enter paper documentation into the EHR, identified as a late entry showing both the actual date and time of care and the date and time of entry (Section 3.4).
- Reconcile orders placed on paper into the electronic order record so tracking and results routing work.
- Reconcile medications administered on the paper MAR.
- Scan the original paper documents into the record per policy.
- Verify that interfaced data queued during the outage — results, ADT, immunization messages — actually posted, and work the interface error queue.
- Reconcile charges so nothing captured on paper is lost (Section 8.2).
- Debrief: what worked, what failed, what changes are needed.
Backup and Recovery
Knowledge statements 4.K15 and 4.K16 cover backup, recovery, and storage. The Security Rule's Contingency Plan standard makes three implementation specifications Required — Data Backup Plan, Disaster Recovery Plan, and Emergency Mode Operation Plan — and two Addressable — Testing and Revision Procedures, and Applications and Data Criticality Analysis.
Operationally, that means maintaining backups on the 3-2-1 pattern described in Section 10.6 (three copies, two media types, one offsite), encrypting backups at rest and in transit, testing restores rather than assuming backups work, keeping at least one copy immutable or offline so ransomware cannot encrypt it, and defining a recovery time objective and recovery point objective that the clinical leadership has actually agreed to.
A verbal order is transcribed into the EHR as 'MSO4 2 mg IV q.d.' Which parts of this entry violate The Joint Commission Do Not Use list?
After a four-hour unplanned EHR outage, staff must enter documentation recorded on paper. How should these entries be made?
Which implementation specification of the Security Rule's Contingency Plan standard is Required rather than Addressable?