28.3 Information Systems Continuity
Key Takeaways
- Information systems continuity is an enterprise risk program—disaster recovery (DR), backups, cybersecurity, and downtime procedures are clinical and financial safety issues, not only IT tasks.
- Plans must address natural disasters, utility failures, cyberattacks (including ransomware), insider sabotage, and vendor/cloud outages with clear RTO/RPO targets by system criticality.
- Backups are useless without tested, offline/immutable copies, restoration drills, and documented downtime clinical workflows.
- Security controls (identity, access, network segmentation, endpoint protection, monitoring, BA oversight) reduce likelihood and blast radius of sabotage and cyber events.
- FACHE executives fund, exercise, and govern continuity alongside emergency preparedness (NIMS/HICS linkages), with board-level visibility of residual risk.
Information Systems Continuity
Quick Answer: Information systems continuity means the organization can continue safe care and critical operations when systems fail, are attacked, or facilities are disrupted—and can restore data and applications to agreed targets. FACHE executives must understand disaster planning and recovery, backup integrity, security against sabotage and cyber threats, and natural disaster scenarios as core enterprise responsibilities shared by IT, operations, clinical leaders, and the board.
Healthcare Technology and Information Management items may present ransomware, a data-center flood, a malicious insider, or multi-day EHR downtime. Strong answers emphasize preparedness, tested recovery, clinical downtime procedures, and governance—not hope that “IT will figure it out.”
Continuity vs. Availability vs. Disaster Recovery
Clarify terms used in executive discussion:
| Term | Meaning | Executive question |
|---|---|---|
| High availability | Design to minimize unplanned downtime (redundancy, clustering, dual power) | Which systems need near-continuous uptime? |
| Business continuity (BC) | Keep critical organizational functions running during disruption | How do we care for patients and collect cash if systems are down? |
| Disaster recovery (DR) | Restore IT systems and data after major loss | How fast and to what point-in-time can we recover? |
| Contingency / downtime procedures | Manual or alternate workflows during outage | Are paper/order processes trained and stocked? |
HIPAA Security Rule contingency planning expectations (data backup, disaster recovery, emergency mode operation, testing, applications criticality) align with these management concepts even when the exam frames them as leadership knowledge rather than compliance trivia.
Classify Systems and Set Recovery Objectives
Not every system needs the same recovery speed. Executives should insist on a business impact analysis (BIA) that ranks applications:
- Tier 1 (life-critical / mission-critical): EHR clinical functions, pharmacy, lab interfaces, ADT/bed management, identity/access for care, network/voice where dependent, revenue-critical claims paths as defined by the organization.
- Tier 2: Scheduling, imaging workflow components, portals, secondary analytics.
- Tier 3: Convenience apps, non-urgent reporting.
For each tier, define:
- RTO (Recovery Time Objective): maximum acceptable downtime.
- RPO (Recovery Point Objective): maximum acceptable data loss (e.g., last 15 minutes vs. last 24 hours).
- Dependencies: power, HVAC, network, cloud regions, third-party clearinghouses, medical devices.
Unrealistic RTOs without budget for redundant infrastructure create false assurance. Leaders should either fund the architecture or adjust operational expectations and downtime plans.
Disaster Planning: Threats Healthcare Must Assume
Continuity planning should explicitly cover:
| Threat category | Examples | Continuity implications |
|---|---|---|
| Natural disasters | Hurricane, flood, earthquake, wildfire, extreme weather | Facility damage, staff access, regional telecom failure, need for geographic diversity of data centers/cloud regions |
| Utility & infrastructure | Power, water, HVAC, ISP outages | Generators, UPS, dual carriers, cooling for data rooms |
| Cyberattacks | Ransomware, data destruction, DDoS | Immutable backups, segmentation, incident response, law enforcement/forensics, communication plans |
| Sabotage / insider threat | Malicious admin, disgruntled contractor, credential abuse | Least privilege, logging, separation of duties, rapid offboarding |
| Vendor / cloud failure | SaaS outage, region loss, supplier bankruptcy | Exit plans, data escrow, multi-region design, contractual SLAs |
| Human error / change failure | Bad patch, failed upgrade | Change control, backout plans, staging environments |
Natural disasters and cyber events increasingly co-occur (e.g., storm damages facilities while remote access surges). Plans should not be siloed by hazard type only.
Backup Strategy: What “We Have Backups” Must Mean
Backups are a control only if they are complete, protected, and restorable:
- 3-2-1 mindset (adapted): multiple copies, multiple media/locations, at least one offline or immutable copy resistant to ransomware encryption.
- Scope: databases, configurations, virtual machines, identity systems, and critical interface configs—not only user files.
- Encryption and access control on backup stores; backup admins are high-value targets.
- Regular restore tests (partial and full) with documented results; untested backups are assumed failed.
- Retention aligned with clinical, legal, and operational needs.
- Air-gapped / immutable / offline options specifically for ransomware resilience.
Executives should ask for evidence of the last successful restore test for Tier 1 systems—not a policy PDF alone.
Disaster Recovery Architecture and Runbooks
DR capability typically involves:
- Secondary data center or cloud region with replication matching RPO.
- Documented runbooks for failover, failback, and communications.
- DNS, identity, and network dependencies included in drills.
- Vendor coordination for hosted EHR or clearinghouse recovery timelines.
- Clear decision authority for declaring disaster and invoking failover (who decides, based on what criteria).
Tabletop exercises and technical failover tests should include clinical and operations leaders, not only infrastructure engineers. HICS/NIMS structures used for facility emergencies should know how IT incidents escalate and who joins the command structure for cyber events.
Security as Continuity Prevention and Containment
Security reduces both likelihood and impact of sabotage and cyber disasters:
| Control area | Continuity value |
|---|---|
| Identity & access management | MFA, least privilege, privileged access management, rapid termination |
| Network segmentation | Limits ransomware lateral movement; protects medical devices |
| Endpoint detection & response | Faster containment |
| Vulnerability & patch management | Reduces exploit windows; balances clinical device constraints |
| Logging & SIEM monitoring | Detects sabotage and intrusion earlier |
| Email/web filtering & phishing defense | Blocks common ransomware entry |
| Third-party / BA risk management | Vendor breaches are organizational incidents |
| Data loss prevention & encryption | Limits exfiltration harm |
Insider sabotage is not only external hacking: terminated privileged users, shared admin passwords, and unmonitored contractor access create continuity risk. HR and IT offboarding must be synchronized.
Clinical and Operational Downtime Procedures
Even perfect DR takes time. Continuity requires emergency mode operation:
- Paper or downtime EHR modules for orders, med administration, and results.
- Downtime registration and ADT processes; clear later backload rules to protect data integrity.
- Medication safety: how pharmacies verify orders without CPOE; how BCMA downtime is handled.
- Critical results communication without normal routing.
- Elective schedule decisions if outage is prolonged.
- Revenue-cycle downtime: charge capture logs to prevent massive revenue loss after recovery.
- Staffing and communication (radios, call trees, public messages) when email/EHR chat fail.
Downtime procedures fail when supplies are outdated, staff are untrained, or recovery backload is unplanned—creating a second disaster of incomplete charts and lost charges.
Governance, Funding, and Board Oversight
Continuity is a risk appetite decision:
- Fund DR and cyber controls proportional to clinical dependency on systems.
- Include continuity metrics in enterprise risk management (time since last restore test, backup immutability status, MFA coverage, known single points of failure).
- Align with emergency management, facilities, and communications.
- Review cyber insurance requirements carefully—policies increasingly demand MFA, EDR, and immutable backups.
- After-action reviews following incidents and drills with tracked corrective actions.
Boards need residual risk statements: “We can recover EHR clinicals within X hours with Y minutes of data loss under scenario Z” is more useful than generic assurance.
Exam Scenarios to Internalize
- Ransomware encrypts production and connected backups: stress immutable/offline copies, incident command, downtime care, and lawful notification pathways.
- Regional flood threatens primary data center: geographic diversity and staff access plans matter as much as generators.
- Privileged contractor deletes virtual machines: logging, privilege limits, and tested restores determine survival.
- EHR host announces multi-day regional outage: RTO reality, downtime clinical ops, and patient communication become executive work.
Executive Takeaway
Information systems continuity is inseparable from safe care and financial stability. FACHE leaders classify critical systems, set honest RTO/RPO targets, demand tested backups and DR, invest in security that contains sabotage and cyberattacks, prepare for natural and utility disasters, and ensure clinical downtime procedures work when technology does not. Continuity is exercised and governed—not merely documented.
Ransomware encrypts production EHR servers. Online backups are also encrypted because they shared continuous network credentials with production. Which continuity lesson is MOST important for executives?
Which pair BEST matches recovery objectives executives should set for a Tier-1 clinical system?
A hurricane forces evacuation of the primary data center campus, and key IT staff cannot reach the site. Which continuity design BEST addresses this natural-disaster scenario?