How to Align Your Downtime Preparedness Program with Your Cyber Incident Response Plan

17 September 2026

AUTHORED BY: Chloe Williams

Most healthcare organizations have two relevant plans for managing significant technology failures: a downtime preparedness program that addresses EHR unavailability, and a cyber incident response plan that addresses the organizational response to a cybersecurity event. In most organizations, these two plans were developed independently, are owned by different teams, and are not explicitly coordinated with each other.

This separation creates a dangerous gap. The most severe and increasingly common cause of extended EHR downtime in healthcare is a ransomware attack, which is simultaneously a downtime event and a cyber incident. When that event occurs, the organization needs both plans to activate, and they need to activate in a coordinated way. If the two plans have never been aligned, the response will be fragmented: the IT team following the cyber incident response protocol, the clinical team following the downtime protocol, and the two teams working in parallel without the coordination that an extended, complex event requires.

Aligning the downtime preparedness program with the cyber incident response plan is not about merging them into a single document. They serve different purposes and require different expertise to execute. It is about ensuring that the two plans are explicitly coordinated at the points where they must work together, and that the people responsible for each understand how their response interacts with the other.

Where the Plans Diverge and Why That Matters

Understanding where the downtime preparedness program and the cyber incident response plan diverge is the starting point for alignment. The divergence is most significant at several specific points:

The activation trigger. The downtime preparedness program is typically activated when the EHR becomes unavailable, regardless of cause. The cyber incident response plan is activated when a cybersecurity threat or breach is detected or suspected, which may happen before or after the EHR goes offline. In a ransomware scenario, the cyber incident response plan may need to be activated while the EHR is still running, if suspicious network activity is detected before the ransomware has completed its encryption. The two plans need to specify how activation of one affects the other, and who has authority to activate each.

The network isolation decision. Cyber incident response best practice in a ransomware scenario typically involves isolating affected network segments to prevent the spread of the malware. This containment action can directly affect the downtime preparedness program: if the network segment containing the HL7 integration between the EHR and the downtime workstations is isolated, the downtime workstations may lose their data feed. The plans need to address this scenario explicitly, specifying whether the HL7 integration is treated as essential infrastructure to be protected or as a potentially contaminated connection to be severed, and what the clinical implications of each decision are.

The use of downtime workstations during a cyber event. dbtech’s on-premise architecture stores patient data locally, which means the downtime workstations can function without internet connectivity. However, if the local network is compromised or intentionally isolated, the question of whether the downtime workstations can safely be used becomes a security decision as much as a clinical one. The cyber incident response team and the clinical team need a shared protocol for determining when it is safe to activate the downtime workstations during a cyber event and what precautions are required.

The communication obligation. Downtime events require internal communication to staff, patients, and potentially leadership and the board. Cyber incidents require additional external communication obligations, including potential breach notification to HHS under the HIPAA Breach Notification Rule, possible notification to law enforcement, and public communication decisions. These communication obligations overlap and must be coordinated, but they are owned by different teams and governed by different timelines.

The Alignment Work That Closes the Gap

Aligning the two plans requires a structured process that brings the downtime program owner and the cyber incident response team into a shared planning conversation, likely for the first time. The specific alignment work that produces a coordinated response capability includes:

Creating a joint scenario that combines both response protocols. Walk through a ransomware scenario together, with the cyber incident response team describing what their protocol requires at each stage and the downtime program owner identifying where those actions intersect with the clinical continuity protocols the downtime plan describes. Document the specific decision points where the two plans must coordinate and assign ownership for each joint decision.

Establishing a joint command structure for extended events. In a routine technical outage, the downtime coordinator manages the clinical response while the IT team manages the restoration. In a major ransomware event, the response involves the CIO, the CISO, legal counsel, the CNO, the administrator on call, and potentially the board. The command structure for who makes which decisions during a cyber-driven downtime event needs to be explicitly defined before an event requires it.

Defining the data preservation obligations for a cyber event. In a non-cyber downtime event, the primary documentation obligation is capturing clinical care data during the outage for later EHR reconciliation. In a cyber event, there is an additional forensic preservation obligation: preserving evidence of the attack, the affected systems, and the timeline of events for the forensic investigation. These two obligations can conflict, and the plans need to specify how they are balanced.

Testing the alignment with a joint tabletop exercise. As described in our post on how to create a downtime tabletop exercise that prepares leadership for real decisions, a joint tabletop exercise that presents a cyber-driven downtime scenario and requires both the cyber incident response team and the clinical downtime team to respond simultaneously is the most effective way to identify the alignment gaps that exist between the two plans. Those gaps are almost always more numerous and more significant than either team anticipated before the exercise.

The Specific Technical Decisions That Must Be Pre-Made

Several technical decisions that arise during a cyber-driven downtime event are too time-sensitive to make in the moment without prior agreement. These decisions need to be pre-made in the alignment documentation:

  • Under what conditions will the HL7 integration between the EHR and the downtime workstations be severed during a cyber event, and who has authority to make that decision?
  • If the HL7 feed is severed, are the downtime workstations considered safe for clinical use with the locally cached patient data, or does their use require additional security verification before activation?
  • What is the maximum acceptable time between a ransomware detection event and a clinical downtime declaration, given that clinical staff need to activate downtime procedures before the ransomware has disabled the EHR entirely?
  • If the downtime workstations themselves are compromised, what is the fallback clinical continuity protocol, and has it been tested?

Pre-making these decisions and documenting them in the alignment section of both plans ensures that they can be executed under the extreme time pressure of a real ransomware event rather than being debated in real time while the attack is progressing. To discuss how dbtech supports the alignment of downtime preparedness with cyber incident response planning, contact our team or request a demo.

Want to learn more? Fill out the form below and a representative will call you ASAP!