How-To

How to Run an EMR Downtime Drill

A downtime drill is a scheduled, time-boxed rehearsal in which your practice operates as though the EMR were unavailable: registering patients, documenting encounters, ordering, and prescribing on paper, and then loading all of it back into the chart afterward. Ninety minutes on a slow afternoon, plus a debrief, is enough for a first one. Most practices have a contingency binder. Very few have ever opened it while patients were in the waiting room, which is the only condition under which you find out whether it works.

What a downtime drill actually is

It is not a tabletop discussion, and it is not a fire drill where everyone walks outside and back in. It is a live rehearsal with real arriving patients, real documentation, and a real back-load afterward. The output is not a green checkmark. The output is a gap list: every question your staff asked that nobody could answer.

Why the binder is not the plan

The HIPAA Security Rule's contingency plan standard, at 45 CFR 164.308(a)(7), requires a data backup plan, a disaster recovery plan, and an emergency mode operation plan. Those three are required implementation specifications. Two more, testing and revision procedures and an applications and data criticality analysis, are addressable, which does not mean optional. Addressable means you must assess whether the specification is reasonable and appropriate for your environment and document what you decided and why. In practice, an untested contingency plan is a difficult thing to defend after an outage, and a worse thing to rely on during one.

On the proposed rule: the 2026 HIPAA Security Rule updates are proposed, not final, and are not in effect. Drill because an outage is a matter of when, and because your existing obligations already point here. Do not restructure your program around a rule that has not been finalized, and be skeptical of anyone selling on the premise that it has.

ONC's SAFER Guides include a Contingency Planning guide specifically covering planned and unplanned EHR unavailability. It is free, it is a self-assessment checklist, and it is a better starting point than anything you will build from scratch.

What to drill first

ScenarioRealistic triggerWhat it actually tests
Planned downtimeVendor maintenance window or version upgradeRead-only access, pre-printed schedules, staff communication
Short unplanned outageConnectivity or vendor-side outage lasting a few hoursPaper forms, prescribing fallback, phone triage, when to reschedule
Extended outageRansomware, data center event, prolonged vendor incidentScheduling, billing hold, lab and referral workflows, patient communication, decision to close
Partial degradationLab interface down, e-prescribing down, or portal down while the EMR is upDetection, manual workaround, and backlog reconciliation
Read-only failoverFailover to a read-only copy of the recordWhether staff realize it is read-only and do not document into a void

Partial degradation is the most common failure mode and the least drilled. The EMR is up, so nobody declares downtime, and a single broken interface quietly accumulates a backlog for three days. Drill it second, right after the short unplanned outage.

Building the downtime packet

  • Printed, dated, and versioned, stored physically at every site and also on a device that does not depend on the EMR or the network.
  • Downtime forms: registration and demographics, encounter or progress note, orders, medication list, allergy list, vitals, consent.
  • A nightly export of tomorrow's schedule with each patient's current medication and allergy list.
  • Paper prescription pads and a written controlled-substance fallback procedure. Know the applicable federal and state rules before the day you need them, not during it.
  • A contact tree: vendor support line with your account number and severity definitions, internet provider, lab and imaging partners, clearinghouse, IT support, and leadership.
  • Named authority: who declares downtime, and who declares recovery. If it is ambiguous, downtime gets declared roughly forty minutes late, every time.
  • A front-desk and phone script so patients hear one consistent, calm explanation.
The highest-value item on that list: the nightly offline export of tomorrow's schedule with medications and allergies. Without it, an outage at 8:00 a.m. means you do not know who is coming or what they are taking. With it, you can still run a clinic.

Running the drill

  1. Pick a genuinely low-volume block. Sixty to ninety minutes. Tell staff a drill is happening; do not tell them the exact failure mode.
  2. Declare downtime out loud, start a clock, and assign a scribe whose only job is to write down every question anyone asks. Those questions are your gap list.
  3. For a first drill, do not actually take the EMR offline. Simulate it by prohibiting its use. You are testing your people and your paper, and there is no reason to accept real clinical risk to do that.
  4. Register two or three real arriving patients on the paper forms.
  5. Document two or three real encounters on the downtime encounter form.
  6. Exercise one order path end to end, typically a lab, including how the order physically reaches the lab.
  7. Exercise one prescribing path end to end, using a non-controlled medication, including the pharmacy call or fax fallback.
  8. Handle one inbound phone request, such as a refill or a records request, under downtime rules.
  9. Declare recovery and immediately begin the back-load. Do not skip this. It is the part that fails.
  10. Debrief within twenty-four hours, while the scribe's handwriting is still legible and the gaps still sting.

The half nobody practices: recovery

Practices rehearse going down and never rehearse coming back up, which is where the real damage happens. Recovery has four parts, and each one needs an owner and a deadline before the drill starts.

  • Back-load. Who re-enters the paper encounters, in what order, by when? Set an explicit target, such as all downtime encounters entered within one business day, and measure against it.
  • Reconcile orders. Compare orders placed on paper against orders now in the system. Duplicate lab orders are the classic downtime injury: ordered on paper, then ordered again in the EMR by someone who did not know.
  • Capture charges. Charges from downtime encounters are the ones that quietly never get billed. Reconcile the encounter forms against the charge log, not against memory.
  • Preserve the audit trail. Notes created from a downtime record should say so, including when the care was delivered versus when the note was entered.

What to measure

  • Time from failure to "downtime declared." Detection lag is almost always the ugliest number in the drill.
  • Percentage of staff who could locate the downtime packet without asking anyone.
  • Encounters completed per hour on paper, compared with a normal hour. This is your actual capacity under downtime, and it is what you plan around.
  • Back-load completion time against the target you set.
  • Number of duplicate or missing orders found in reconciliation.
  • Number of gap-list items closed before the next drill. This is the only metric that proves the drill was worth doing.

How often to drill

Twice a year at a minimum. Additionally after any EMR version change that alters forms or order paths, and after any real outage, because a real outage is a free drill and should be debriefed exactly like one. Add the location of the downtime packet to new-hire onboarding; the person who cannot find it is almost always the one who started six weeks ago.

The takeaway

The point of a drill is not to prove your plan works. It is to find out, cheaply and on a slow Tuesday, all the ways it does not. Simulate rather than actually pulling the plug for the first one, use real arriving patients, appoint a scribe, and rehearse the back-load as seriously as the outage. Then close the gap list before the next drill, because a drill that produces a gap list nobody closes is just a slower way of being unprepared.

Common questions

Does HIPAA require us to test our contingency plan?

Under 45 CFR 164.308(a)(7), testing and revision procedures for the contingency plan are an addressable implementation specification. That means you must assess whether periodic testing is reasonable and appropriate for your environment and document your decision, not that you may simply skip it.

Should we actually take the EMR offline for the drill?

Not for your first one. Simulate the outage by prohibiting use of the system during a low-volume block. Live failover tests are a later exercise, coordinated with your vendor and typically run outside clinic hours.

What is the piece practices most often forget?

A nightly export, stored offline, of the next day's schedule with each patient's current medication and allergy list. Without it, a morning outage means you do not know who is coming or what they are on.

How long should a downtime drill take?

Sixty to ninety minutes of live operation, plus the back-load, plus a debrief within twenty-four hours. Longer drills mostly test patience rather than preparedness.