Insights · Behavioral Health

Your EHR goes down at 8 a.m. What happens to the next eight hours?

Behavioral health practices plan carefully for clinical emergencies and almost never for technical ones. A one-page downtime plan is the difference between a rough morning and a lost day.

By Andrew · NextGen Strategy PartnersAugust 31, 20265 min read

Behavioral health organizations plan meticulously for clinical crises. There are protocols for a client in acute distress, for a safety concern, for a difficult termination. Ask the same organization what happens if the EHR is unreachable at 8 a.m. on a Tuesday, and the answer is usually a long pause followed by "we'd call IT."

That gap matters because the day doesn't stop. Clients are already in the parking lot. Clinicians need schedules, histories, and treatment plans. Intake needs to verify insurance. Billing needs to close yesterday. When the system that holds all of it is unavailable, the question isn't whether you'll improvise — it's whether you'll improvise well, and whether the improvising creates a compliance problem on top of an operational one.

The improvisation is where the risk hides

Watch what naturally happens during an unplanned outage. Someone photographs a schedule with a personal phone. Notes get drafted in a personal email account "just until it's back." A clinician texts a colleague a client's name to confirm an appointment. None of it is malicious — all of it is PHI moving to places your safeguards don't reach, created under time pressure, and rarely cleaned up afterward.

Downtime doesn't just cost you a day of productivity. It quietly manufactures protected health information in places you never approved and can't easily find later.

The one-page downtime plan

This doesn't need to be a binder. One page, printed — because if it only exists in the system that's down, it doesn't exist:

Then test the assumption underneath it

Most downtime plans quietly assume the data comes back. That assumption is only true if your backups are separated from your network and have actually been restored — not just reported as successful. A restore test once a quarter is what converts "we have backups" into "we can be operational by this afternoon." It's also, not coincidentally, what your cyber-insurance carrier and your risk assessment both want documented.

The practical takeaway

Write the one-pager this week, print it, and put a copy at the front desk and in every clinician's office. Then ask your IT provider one question: when was our backup last test-restored, and how long would a full recovery take? Our free security assessment answers both — findings are yours either way.

You can't prevent every outage. You can decide, calmly and in advance, what a bad morning looks like — so the day bends instead of breaking, and nothing about the improvising comes back as a compliance finding later.

Andrew, founder of NextGen Strategy Partners

Andrew — Founder, NextGen Strategy Partners

Veteran-owned managed IT for the nonprofits, schools, behavioral health providers, and medical & dental practices of McHenry & Lake Counties. Request a free security assessment →

Find out where you stand — before someone else does.

Our free IT security assessment gives your leadership a plain-English report on your risks, your compliance gaps, and exactly what it would cost to fix them. No obligation, no jargon.

Request the free assessment