ORANGE COUNTY BUSINESS CYBERSECURITY
Cyber Downtime Readiness for Orange County Healthcare Practices

Healthcare cyber downtime readiness is not only an IT problem. If scheduling, electronic health records, imaging, lab interfaces, phones, prescriptions, payments, email, or identity services become unavailable, the practice must continue making safe decisions with incomplete digital support. Small medical and dental offices often have fewer redundant systems and fewer people available to coordinate recovery, yet the consequences of improvised downtime can reach patient safety, privacy, revenue, and trust.
This guide provides a practical readiness model for outpatient practices in Irvine and across Orange County. It does not assume that every disruption is ransomware or that every practice needs a hospital-scale command structure. The goal is to define essential services, prepare usable manual workflows, preserve evidence, coordinate vendors, and restore systems in a controlled order.
Executive summary
HHS’s healthcare Cybersecurity Performance Goals describe basic incident planning and preparedness as an essential goal and connect it to safe response, restoration, recovery, backup strategies, policies, and incident response. HHS’s ransomware guidance also explains that HIPAA contingency planning includes data backup, disaster recovery, emergency-mode operations, application and data criticality analysis, and periodic testing.
A defensible downtime program should answer:
- Who declares downtime and who has clinical, operational, security, privacy, and recovery authority?
- Which patient services continue, reduce, divert, or stop at each level of disruption?
- How do staff identify patients, document care, verify medications, receive results, prescribe, schedule, and communicate without normal systems?
- Which offline contacts, forms, instructions, devices, and supplies are available at each location?
- How are backups isolated, restored, validated, and reconciled with records created during downtime?
- How are incidents involving vendors, cloud services, phones, Internet, and identity handled?
- When was the complete workflow last exercised under realistic conditions?
Define downtime levels and activation authority
Not every outage requires the same response. Create simple levels that staff can recognize:
| Level | Example condition | Operating decision |
|---|---|---|
| Local degradation | One workstation, printer, scanner, or noncritical application fails | Continue with local workaround and support escalation |
| Service outage | Scheduling, phones, email, EHR module, lab, imaging, or e-prescribing unavailable | Activate workflow-specific downtime procedure |
| Suspected cyber incident | Unexpected encryption, suspicious sign-in, malicious forwarding, widespread endpoint alerts, or vendor security notice | Isolate affected paths, preserve evidence, activate incident leadership |
| Extended clinical downtime | Multiple critical systems unavailable beyond the practice’s safe tolerance | Reduce services, divert or reschedule where necessary, use full downtime operations |
| Recovery and reconciliation | Systems return but data, interfaces, identities, or trust are not fully validated | Controlled restoration, record entry, reconciliation, monitoring |
Name the person authorized to declare each level and a backup when that person is unreachable. Staff should not wait for a group email if email is unavailable. Keep an offline contact tree with current mobile and alternate numbers for leaders, clinicians, IT, cybersecurity, EHR, phone, Internet, lab, imaging, pharmacy, payment, legal, insurance, and other critical partners.
Put patient safety before system restoration speed
The clinical leader should decide which services can continue safely. Build procedures for patient identification, allergies, medications, urgent history, orders, results, referrals, informed consent, escalation, and transfer. The procedure should state when incomplete information requires delaying a service or sending a patient to a higher level of care.
Downtime forms should be standardized, numbered or otherwise traceable, legible, dated, timed, signed, protected from unauthorized access, and reconciled later. Store enough copies at each site in a controlled location. Avoid inventing forms during the incident.

Prepare the workflows that fail first
Registration and scheduling
Maintain a current, appropriately protected way to identify the day’s appointments and essential contact information. Define how staff record arrivals, cancellations, follow-up, referrals, and rescheduling without creating duplicate patients or exposing paper lists.
Clinical documentation
Use approved downtime notes with patient identifiers, date and time, author, service, decisions, orders, and follow-up. Define how papers are secured, transported, scanned or entered later, quality checked, and destroyed according to approved policy.
Medication and prescribing
Plan how clinicians verify allergies, current medications, contraindications, refill history, and pharmacy information when normal sources are unavailable. Define whether phone, paper, or alternate prescribing methods are legally and operationally available. Do not improvise shortcuts around controlled-substance or identity requirements; obtain appropriate legal and professional guidance.
Laboratory and imaging
Maintain vendor contacts, manual order and result paths, specimen labeling procedures, priority rules, and result reconciliation. Decide how critical results reach the correct clinician and how acknowledgement is documented.
Phones, secure communication, and patient notices
Prepare alternate phones or call routing, approved messaging channels, recorded-message procedures, website or status-page ownership, and scripts that state what is known without speculation. Do not disclose a cyberattack, data breach, attacker, or exposure before the facts support that language.
Payments and billing
Define whether payment collection stops, uses an approved alternate process, or is deferred. Protect card and patient information. Record services and charges for later reconciliation without creating unofficial spreadsheets or unprotected personal-device records.
Separate clinical continuity from cyber containment
During a suspected cyber incident, a well-intended workaround can spread the problem or destroy evidence. Staff should know which devices may be disconnected, which should remain powered for investigation, and who makes that decision. Do not connect personal USB drives, restore files into untrusted systems, or move data to consumer accounts.
Prepare clean communication and recovery resources that do not depend on the affected environment. These may include a separately managed device, printed contact list, known-good recovery instructions, and approved alternate connectivity. The design should be reviewed so it does not create a permanent unmonitored backdoor.
The practice’s HIPAA breach notification and incident-response plan should distinguish operational containment from the later legal analysis of whether protected health information was acquired, accessed, used, or disclosed in an impermissible way.
Know every critical vendor dependency
Outpatient practices may rely on vendors for EHR, practice management, billing, clearinghouse, imaging, labs, transcription, phones, Internet, Microsoft 365, backup, endpoint management, secure messaging, pharmacy services, and payment processing. The downtime plan should include:
- service and security contacts that work outside the affected portal;
- customer and vendor responsibilities;
- incident-notification terms;
- data export and emergency-access options;
- availability and recovery commitments;
- backup responsibility and restore process;
- subprocessor and integration dependencies;
- identity, API, and remote-support access;
- evidence the vendor can provide during an incident;
- termination and transition procedure.
Do not assume a cloud vendor’s backup automatically provides practice-level recovery. Verify what is backed up, how often, how long, who can request restoration, how identity is verified, how a restore is tested, and whether the practice can obtain an independent export.
Build and test recoverable backups
HHS ransomware guidance emphasizes frequent backups, restore testing, and consideration of backups kept offline and unavailable from normal networks because ransomware may disrupt online copies. For a practice, the backup plan should cover systems the practice controls and clarify what each SaaS vendor protects.
Document:
- systems, databases, documents, configurations, and keys included;
- backup frequency and retention;
- isolation from ordinary and privileged accounts;
- encryption and key recovery;
- immutable or offline copies where appropriate;
- monitoring for failed or altered backups;
- restore priority, dependencies, and clean environment;
- recovery-time and recovery-point objectives;
- test date, result, time, data integrity, and corrective action.
A successful backup job is not a successful recovery test. Restore representative data and applications, validate that authorized users can use them, and verify interfaces and security configuration.
Restore in a controlled order
Recovery should follow patient safety and dependency, not the order in which vendors respond. A possible sequence is:
- establish a clean identity and administration path;
- validate network, endpoint, and security-monitoring foundations;
- restore the authoritative clinical record and essential access;
- restore pharmacy, lab, imaging, communications, and scheduling integrations based on clinical need;
- reconcile downtime documentation and transactions;
- validate billing and administrative systems;
- increase monitoring and review for persistence or repeated misuse.
Before reconnecting, confirm the cause and access path are sufficiently understood, compromised credentials are revoked, known malicious persistence is removed, vulnerabilities are addressed, backups are trustworthy, and logging is operating. Maintain a decision log for restoration, exceptions, and residual risk.
Reconcile every downtime record
Returning the EHR to service does not end downtime. Assign teams to enter or scan records, match orders and results, identify duplicates, confirm medication and allergy updates, reconcile appointments and referrals, post charges, and resolve messages.
Use a two-person or quality-review process for high-impact entries. Track each downtime record from creation to verified incorporation and approved disposal. Preserve the chronology needed for patient care, compliance, billing, investigation, and correction.
Exercise the plan, not only the meeting
Run a scenario in which the EHR, phones, email, and normal contact portal are unavailable at the same time. Provide only information staff would realistically have. Test:
- declaration and contact-tree activation;
- patient identification and service triage;
- medication, lab, imaging, and referral workflows;
- paper form availability and privacy;
- vendor escalation outside the portal;
- cybersecurity containment and evidence preservation;
- alternate communication;
- backup restore and clean-access steps;
- recovery decision and record reconciliation;
- leadership, privacy, legal, insurance, and public-communication escalation.
Record start time, decisions, delays, unavailable resources, unsafe workarounds, and corrective actions. Assign owners and dates. Repeat affected parts after improvements.
A 60-day readiness sequence
Days 1–15: identify critical services
Map clinical and administrative systems, owners, vendors, data, interfaces, and maximum tolerable downtime. Define downtime levels and decision authority.
Days 16–30: prepare workflows and resources
Approve paper forms, offline contacts, communication scripts, clinical escalation, medication/lab/imaging procedures, payment decisions, and secure storage. Place controlled packets at each site.
Days 31–45: verify technology and vendors
Review identity, remote access, endpoint protection, segmentation, logging, backups, restore evidence, vendor notification, and emergency-access arrangements. Correct gaps before the exercise.
Days 46–60: exercise and remediate
Run the combined clinical and cyber scenario, test a restore, reconcile sample downtime records, and report unresolved risk to leadership.
OC Security Audit’s healthcare clinic cybersecurity guidance and HIPAA compliance roadmap for Orange County healthcare practices can help connect downtime readiness to the wider risk, safeguard, policy, and evidence program.
Questions practice leaders should ask
- Can staff continue safe patient operations if EHR, phones, email, and vendor portals are unavailable together?
- Are approved downtime packets present and current at every location?
- Which services must stop when authoritative information is unavailable?
- Can leaders contact every critical vendor outside the affected systems?
- When did the practice last restore data and validate a usable application?
- How are records created during downtime reconciled and quality checked?
- Who approves restoration and public statements?
- What did the last exercise reveal, and were the findings closed?
Sources
- HHS Cyber Gateway: Healthcare and Public Health Cybersecurity Performance Goals
- HHS OCR: Fact Sheet on Ransomware and HIPAA
- HHS OCR: October 2022 Cybersecurity Newsletter on Security Incident and Contingency Planning
- HHS ASPR TRACIE: Hospital Downtime Operations Checklist
- CISA and partners: StopRansomware Guide
Prepare the practice before the next disruption
Contact OC Security Audit to discuss an independent healthcare cybersecurity, HIPAA security, backup, incident-response, or downtime-readiness review. Learn more about Ali Hassani, CISO and his experience across healthcare IT, cybersecurity, infrastructure, compliance auditing, and operational leadership.
Connect this downtime plan to the first-alert incident-response sequence, review the current and proposed HIPAA Security Rule hardening direction, and use the Stryker disruption analysis to examine operational dependencies that can extend beyond a single system.
Update and correction history
- July 2026: Initial analysis prepared from HHS and CISA healthcare cybersecurity, HIPAA contingency, ransomware, and downtime guidance available through July 2026.