28.3 Information Systems Continuity

Key Takeaways

  • Information systems continuity is an enterprise risk program—disaster recovery (DR), backups, cybersecurity, and downtime procedures are clinical and financial safety issues, not only IT tasks.
  • Plans must address natural disasters, utility failures, cyberattacks (including ransomware), insider sabotage, and vendor/cloud outages with clear RTO/RPO targets by system criticality.
  • Backups are useless without tested, offline/immutable copies, restoration drills, and documented downtime clinical workflows.
  • Security controls (identity, access, network segmentation, endpoint protection, monitoring, BA oversight) reduce likelihood and blast radius of sabotage and cyber events.
  • FACHE executives fund, exercise, and govern continuity alongside emergency preparedness (NIMS/HICS linkages), with board-level visibility of residual risk.
Last updated: August 2026

Information Systems Continuity

Quick Answer: Information systems continuity means the organization can continue safe care and critical operations when systems fail, are attacked, or facilities are disrupted—and can restore data and applications to agreed targets. FACHE executives must understand disaster planning and recovery, backup integrity, security against sabotage and cyber threats, and natural disaster scenarios as core enterprise responsibilities shared by IT, operations, clinical leaders, and the board.

Healthcare Technology and Information Management items may present ransomware, a data-center flood, a malicious insider, or multi-day EHR downtime. Strong answers emphasize preparedness, tested recovery, clinical downtime procedures, and governance—not hope that “IT will figure it out.”

Continuity vs. Availability vs. Disaster Recovery

Clarify terms used in executive discussion:

TermMeaningExecutive question
High availabilityDesign to minimize unplanned downtime (redundancy, clustering, dual power)Which systems need near-continuous uptime?
Business continuity (BC)Keep critical organizational functions running during disruptionHow do we care for patients and collect cash if systems are down?
Disaster recovery (DR)Restore IT systems and data after major lossHow fast and to what point-in-time can we recover?
Contingency / downtime proceduresManual or alternate workflows during outageAre paper/order processes trained and stocked?

HIPAA Security Rule contingency planning expectations (data backup, disaster recovery, emergency mode operation, testing, applications criticality) align with these management concepts even when the exam frames them as leadership knowledge rather than compliance trivia.

Classify Systems and Set Recovery Objectives

Not every system needs the same recovery speed. Executives should insist on a business impact analysis (BIA) that ranks applications:

  • Tier 1 (life-critical / mission-critical): EHR clinical functions, pharmacy, lab interfaces, ADT/bed management, identity/access for care, network/voice where dependent, revenue-critical claims paths as defined by the organization.
  • Tier 2: Scheduling, imaging workflow components, portals, secondary analytics.
  • Tier 3: Convenience apps, non-urgent reporting.

For each tier, define:

  • RTO (Recovery Time Objective): maximum acceptable downtime.
  • RPO (Recovery Point Objective): maximum acceptable data loss (e.g., last 15 minutes vs. last 24 hours).
  • Dependencies: power, HVAC, network, cloud regions, third-party clearinghouses, medical devices.

Unrealistic RTOs without budget for redundant infrastructure create false assurance. Leaders should either fund the architecture or adjust operational expectations and downtime plans.

Disaster Planning: Threats Healthcare Must Assume

Continuity planning should explicitly cover:

Threat categoryExamplesContinuity implications
Natural disastersHurricane, flood, earthquake, wildfire, extreme weatherFacility damage, staff access, regional telecom failure, need for geographic diversity of data centers/cloud regions
Utility & infrastructurePower, water, HVAC, ISP outagesGenerators, UPS, dual carriers, cooling for data rooms
CyberattacksRansomware, data destruction, DDoSImmutable backups, segmentation, incident response, law enforcement/forensics, communication plans
Sabotage / insider threatMalicious admin, disgruntled contractor, credential abuseLeast privilege, logging, separation of duties, rapid offboarding
Vendor / cloud failureSaaS outage, region loss, supplier bankruptcyExit plans, data escrow, multi-region design, contractual SLAs
Human error / change failureBad patch, failed upgradeChange control, backout plans, staging environments

Natural disasters and cyber events increasingly co-occur (e.g., storm damages facilities while remote access surges). Plans should not be siloed by hazard type only.

Backup Strategy: What “We Have Backups” Must Mean

Backups are a control only if they are complete, protected, and restorable:

  • 3-2-1 mindset (adapted): multiple copies, multiple media/locations, at least one offline or immutable copy resistant to ransomware encryption.
  • Scope: databases, configurations, virtual machines, identity systems, and critical interface configs—not only user files.
  • Encryption and access control on backup stores; backup admins are high-value targets.
  • Regular restore tests (partial and full) with documented results; untested backups are assumed failed.
  • Retention aligned with clinical, legal, and operational needs.
  • Air-gapped / immutable / offline options specifically for ransomware resilience.

Executives should ask for evidence of the last successful restore test for Tier 1 systems—not a policy PDF alone.

Disaster Recovery Architecture and Runbooks

DR capability typically involves:

  • Secondary data center or cloud region with replication matching RPO.
  • Documented runbooks for failover, failback, and communications.
  • DNS, identity, and network dependencies included in drills.
  • Vendor coordination for hosted EHR or clearinghouse recovery timelines.
  • Clear decision authority for declaring disaster and invoking failover (who decides, based on what criteria).

Tabletop exercises and technical failover tests should include clinical and operations leaders, not only infrastructure engineers. HICS/NIMS structures used for facility emergencies should know how IT incidents escalate and who joins the command structure for cyber events.

Security as Continuity Prevention and Containment

Security reduces both likelihood and impact of sabotage and cyber disasters:

Control areaContinuity value
Identity & access managementMFA, least privilege, privileged access management, rapid termination
Network segmentationLimits ransomware lateral movement; protects medical devices
Endpoint detection & responseFaster containment
Vulnerability & patch managementReduces exploit windows; balances clinical device constraints
Logging & SIEM monitoringDetects sabotage and intrusion earlier
Email/web filtering & phishing defenseBlocks common ransomware entry
Third-party / BA risk managementVendor breaches are organizational incidents
Data loss prevention & encryptionLimits exfiltration harm

Insider sabotage is not only external hacking: terminated privileged users, shared admin passwords, and unmonitored contractor access create continuity risk. HR and IT offboarding must be synchronized.

Clinical and Operational Downtime Procedures

Even perfect DR takes time. Continuity requires emergency mode operation:

  • Paper or downtime EHR modules for orders, med administration, and results.
  • Downtime registration and ADT processes; clear later backload rules to protect data integrity.
  • Medication safety: how pharmacies verify orders without CPOE; how BCMA downtime is handled.
  • Critical results communication without normal routing.
  • Elective schedule decisions if outage is prolonged.
  • Revenue-cycle downtime: charge capture logs to prevent massive revenue loss after recovery.
  • Staffing and communication (radios, call trees, public messages) when email/EHR chat fail.

Downtime procedures fail when supplies are outdated, staff are untrained, or recovery backload is unplanned—creating a second disaster of incomplete charts and lost charges.

Governance, Funding, and Board Oversight

Continuity is a risk appetite decision:

  • Fund DR and cyber controls proportional to clinical dependency on systems.
  • Include continuity metrics in enterprise risk management (time since last restore test, backup immutability status, MFA coverage, known single points of failure).
  • Align with emergency management, facilities, and communications.
  • Review cyber insurance requirements carefully—policies increasingly demand MFA, EDR, and immutable backups.
  • After-action reviews following incidents and drills with tracked corrective actions.

Boards need residual risk statements: “We can recover EHR clinicals within X hours with Y minutes of data loss under scenario Z” is more useful than generic assurance.

Exam Scenarios to Internalize

  • Ransomware encrypts production and connected backups: stress immutable/offline copies, incident command, downtime care, and lawful notification pathways.
  • Regional flood threatens primary data center: geographic diversity and staff access plans matter as much as generators.
  • Privileged contractor deletes virtual machines: logging, privilege limits, and tested restores determine survival.
  • EHR host announces multi-day regional outage: RTO reality, downtime clinical ops, and patient communication become executive work.

Executive Takeaway

Information systems continuity is inseparable from safe care and financial stability. FACHE leaders classify critical systems, set honest RTO/RPO targets, demand tested backups and DR, invest in security that contains sabotage and cyberattacks, prepare for natural and utility disasters, and ensure clinical downtime procedures work when technology does not. Continuity is exercised and governed—not merely documented.

Test Your Knowledge

Ransomware encrypts production EHR servers. Online backups are also encrypted because they shared continuous network credentials with production. Which continuity lesson is MOST important for executives?

A
B
C
D
Test Your Knowledge

Which pair BEST matches recovery objectives executives should set for a Tier-1 clinical system?

A
B
C
D
Test Your Knowledge

A hurricane forces evacuation of the primary data center campus, and key IT staff cannot reach the site. Which continuity design BEST addresses this natural-disaster scenario?

A
B
C
D