How to Talk to Your Board About EHR Downtime Risk Without Losing the Room

5 August 2026

AUTHORED BY: Chloe Williams

Presenting EHR downtime risk to a hospital board is a communication challenge as much as it is a financial or operational one. Board members are not healthcare IT experts. They do not understand HL7 interfaces, recovery time objectives, or the difference between a data backup and a downtime solution. What they do understand is fiduciary responsibility, reputational risk, regulatory liability, and the financial performance of the organization they govern. The conversation about EHR downtime risk succeeds when it is conducted in those terms, not in the language of IT infrastructure.

Most board presentations on downtime risk fail not because the underlying case is weak but because the presentation is framed incorrectly. Technical details crowd out the strategic picture. The financial case is presented without a concrete comparison to the cost of the solution. Regulatory risk is described in general terms without specific consequences. The board leaves the room understanding that downtime is a problem but not understanding why it requires their attention right now.

Getting this presentation right is worth the effort. The board’s engagement with downtime risk as a governance matter changes the organizational culture around preparedness in ways that no IT director’s memo or compliance document can replicate. When the board asks about downtime preparedness at the next quarterly meeting, the entire leadership team pays attention.

Frame It as Governance Risk, Not IT Risk

The first and most important framing decision in a board presentation on downtime risk is positioning it as a governance issue rather than an IT issue. IT issues belong in the IT committee or the management team’s agenda. Governance issues belong at the board level, and EHR downtime has the characteristics of a governance issue:

  • It creates financial exposure that affects the organization’s overall financial health and its ability to meet fiduciary obligations to the communities it serves
  • It creates regulatory risk that can affect Medicare and Medicaid participation, accreditation status, and the organization’s legal standing
  • It creates reputational risk that affects patient trust, physician confidence in the organization, and the community’s perception of the quality and reliability of care
  • It is a risk that, if materialized in a serious way, will become a board-level crisis whether or not it was ever discussed at the board level in advance

Presenting downtime risk through these four lenses, financial, regulatory, reputational, and crisis preparedness, transforms it from an IT infrastructure conversation into a governance conversation that board members are equipped to engage with.

Lead with the Financial Number

Board members respond to concrete financial figures. The presentation should open with a specific financial exposure calculation rather than a general statement about downtime being costly. A credible financial framing includes:

  • The organization’s actual downtime history over the past two to three years, expressed as total hours of system unavailability
  • A defensible per-hour cost figure drawn from published research, noting that research places the cost of healthcare downtime at several thousand dollars per minute for average organizations and higher for large health systems
  • The resulting historical cost of downtime at this organization, as a concrete dollar figure that board members can evaluate
  • A projection of the forward-looking exposure based on the current risk environment, specifically noting the increasing frequency of ransomware-driven outages across the healthcare industry and the extended duration of those events compared to routine technical failures

This financial framing makes the risk tangible and comparable to other financial risks the board routinely governs. It also sets up the investment case cleanly: once the board understands what downtime currently costs, the cost of a solution like dbtech’s tiered downtime program reads as a fraction of the exposure rather than as an additional cost to be justified.

Present the Regulatory Exposure Specifically

General statements about regulatory risk do not land with boards. Specific consequences do. The regulatory section of the presentation should name the specific frameworks and the specific consequences of non-compliance:

  • CMS Conditions of Participation require documented and tested emergency preparedness procedures that address technology failures. A deficiency finding can result in a corrective action plan with monitored milestones and, in serious cases, jeopardy to Medicare and Medicaid participation
  • The Joint Commission evaluates downtime preparedness as part of its accreditation standards, and findings become part of the public record that payers, physicians, and patients can access
  • HIPAA’s Security Rule requires specific contingency planning documentation for EHR outage scenarios, and a ransomware-driven outage that is not managed with adequate documentation and access controls creates potential breach notification obligations with their associated legal and reputational consequences
  • State health department surveys evaluate downtime preparedness through direct staff interviews, and findings at the state level carry their own corrective action requirements that are independent of Joint Commission and CMS processes

Presenting these frameworks by name, with their specific consequences, gives board members the information they need to assess the regulatory dimension of the risk rather than accepting a general assurance that compliance is being managed.

Address the Reputational Dimension

Boards are acutely sensitive to reputational risk, particularly in competitive healthcare markets where patient choice and physician alignment affect the organization’s market position. The reputational dimension of downtime risk has two components that resonate at the board level:

  • A significant patient safety event that occurs during a downtime event and is found to have been contributed to by inadequate preparedness creates lasting reputational and legal exposure that affects the organization’s standing in the community and with payers
  • Extended operational disruptions caused by a ransomware attack, which can take hospitals offline for days or weeks, create immediate and visible reputational damage that patients, physicians, and the media notice and remember

Neither of these scenarios requires detailed technical explanation to land with a board audience. The question to pose is simply: if our organization experienced a two-week ransomware-driven EHR outage next month, how would our board respond to questions from the community, payers, and regulators about what we had in place to protect patients during that event?

Make the Investment Decision Simple

The board is not being asked to approve a technical architecture or select a vendor. They are being asked to support a budget decision that addresses a governance risk. The investment case should be presented in the simplest possible terms:

  • This is what downtime currently costs us, based on our actual history
  • This is what the regulatory and reputational exposure looks like if we experience a significant event without adequate preparedness
  • This is the cost of the solution, using dbtech’s tiered pricing structure to present a specific, predictable monthly investment
  • This is the return: a reduction in per-outage cost, protection against the regulatory and reputational exposure described above, and the ability to demonstrate to CMS, the Joint Commission, and our community that we take downtime preparedness seriously as a patient safety commitment

The comparison between the exposure and the investment should be presented as a clear, direct table or single slide that the board can evaluate without requiring technical expertise to interpret. The math, when assembled correctly, makes the case on its own.

To prepare a board-ready downtime risk assessment for your organization, schedule a dbtech Downtime Audit Assessment that quantifies your current exposure and preparedness gaps in terms suitable for board presentation. To learn more about how dbtech supports organizational downtime preparedness at every level, request a demo or contact our team.

Want to learn more? Fill out the form below and a representative will call you ASAP!