Draft:Electronic health record availability
Review waiting, please be patient.
This may take 5 weeks or more, since drafts are reviewed in no specific order. There are 2,528 pending submissions waiting for review.
Where to get help
How to improve a draft
You can also browse Wikipedia:Featured articles and Wikipedia:Good articles to find examples of Wikipedia's best writing on topics similar to your proposed article. Improving your odds of a speedy review To improve your odds of a faster review, tag your draft with relevant WikiProject tags using the button below. This will let reviewers know a new draft has been submitted in their area of interest. For instance, if you wrote about a female astronomer, you would want to add the Biography, Astronomy, and Women scientists tags. Editor resources
Reviewer tools
|
Electronic health record availability is the ability of electronic health record (EHR) systems to keep clinical information accessible and usable by authorized health care professionals when it is needed for patient care.
In information security, availability is one of the three components of the CIA triad, together with confidentiality and integrity. In health care, availability involves more than keeping an application or server continuously operational: it also includes the ability to retain access to clinically necessary information when the usual access path is unavailable, and to restore normal operations safely.[1][2][3]
Loss of access to an EHR can directly affect clinical care because information such as medication lists, allergies, test results, diagnoses, and previous treatment may no longer be available through the usual workflow. Technical standards, safety guidance, and the health informatics literature therefore treat continuity of access as both an information-security issue and a patient safety concern.[4][5]
Approaches to maintaining availability include measures activated during a system interruption as well as system architectures intended to reduce dependence on a single access path. They include downtime procedures, alternative methods of viewing clinical information, local operation with data synchronization, and backup and recovery mechanisms.[6][7][8]
Clinical significance of EHR downtime
[edit]Electronic records have become central to activities such as reviewing medical history, prescribing, ordering and reviewing tests, and documenting care. When EHR systems are unavailable, clinical teams may need to use alternative workflows and may have slower or more limited access to information needed for clinical decisions.
Studies of EHR downtime have identified problems involving patient identification, medications, laboratory testing, and clinical workflows.[4] In emergency departments, prolonged outages have been associated with increased workload and longer patient stays,[9] while studies in surgical settings have also examined operational effects of temporary loss of EHR access.[10]
Downtime may be planned, such as during maintenance, or unplanned as a result of software or hardware failure, power outages, loss of Internet or internal network connectivity, disasters, or security incidents.[11][3] Because different failures affect different parts of an information system, continuity of care depends not only on restoring the primary EHR but also on procedures and alternative paths for obtaining clinically necessary information.
Availability and information security
[edit]Availability is a fundamental property of information security. Confidentiality concerns preventing unauthorized disclosure, while integrity concerns preserving the accuracy and consistency of information. Availability concerns whether information and services can be accessed and used when required.
This property has particular importance in health care because unavailable information can directly affect clinical work. ISO 27799 specifies information-security controls for health information and applies to information processed in different technical environments, including local infrastructure and cloud-based services.[2] The National Institute of Standards and Technology (NIST) Special Publication 800-66, which provides guidance for implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule in the United States, similarly treats confidentiality, integrity, and availability as properties that must be protected for electronic protected health information.[1]
Protecting an EHR therefore involves more than preventing unauthorized access or modification. It also involves planning how necessary clinical information will remain accessible when a system, network, Internet connection, or another normally used component becomes unavailable.
Continuity and resilience strategies
[edit]Strategies for maintaining EHR access can operate in two complementary ways: through contingency mechanisms activated during downtime, and through system architecture designed to reduce dependence on a single access path. The former include operational procedures, standby systems, and recovery mechanisms. The latter include architectures that maintain data or functions locally and synchronize them with remote infrastructure, allowing one access path to remain usable when another is interrupted.[6][7][8]
These mechanisms serve different purposes. A backup can allow data to be restored after a failure but does not necessarily provide immediate access during an outage. Similarly, a downtime procedure may preserve part of the clinical workflow after the primary system becomes unavailable, whereas an architecture capable of local operation may allow normal functions to continue through some types of connectivity failure.
Multiple access paths and local operation
[edit]Some EHR systems are designed to provide more than one way of accessing clinical information during normal operation. For example, a system may keep operational data and functions on local, on-premises infrastructure, while synchronizing changes with remote infrastructure when connectivity is available. In this configuration, loss of external connectivity does not necessarily interrupt local operations.
This differs from a contingency system that is activated only after a failure. In an offline-first architecture, the local data store forms part of the routine read-and-write workflow, and changes are synchronized or reconciled with a central or remote system when communication becomes available.[8]
Where copies or services can be reached through distinct paths, failure of one component does not necessarily remove every means of accessing clinical information. A connectivity failure may leave local operation unaffected, while a local equipment or infrastructure failure may be mitigated by synchronized data or services maintained elsewhere, depending on the implementation.
Local infrastructure or multiple access paths do not by themselves guarantee availability. The SAFER contingency-planning guidance recommends considering hardware duplication, network redundancy, and data replication as part of disaster recovery planning.[3] Systems that maintain multiple writable copies must also preserve integrity and address synchronization and possible differences between versions.
A 2026 feasibility study evaluated an offline-first EHR used in clinics serving vulnerable populations, including its operation and synchronization under intermittent connectivity.[8] Other studies have examined continuity during EHR downtime through contingency planning, local backup systems, and dedicated downtime procedures in health care settings.[6][7]
Implementation examples
[edit]Systems combining local or disconnected operation with synchronization have been implemented in different clinical settings. Designs vary: some use a local database or server synchronized with central infrastructure, while others allow installed applications to retain the clinical data required for offline work and synchronize changes when connectivity returns.
In the United States, Binsera EHR is described by its developer as an offline-first EHR in which critical clinical functions can use locally available data during connectivity outages. Its documented offline functions include clinical documentation, medication information, and orders; changes are synchronized with remote infrastructure after connectivity is restored, with conflict handling and audit logging.[12]
Tamanu, developed by the Australian organization Beyond Essential Systems, is an open-source electronic medical record designed for environments without continuous connectivity. The World Health Organization describes Tamanu as offline-first and capable of synchronization.[13] Its facility architecture can use local servers that continue serving users without Internet access and synchronize bidirectionally with central infrastructure when communication is available.[14]
In the United Kingdom, Morse is a mobile electronic patient record used by organizations of the National Health Service. NHS Shetland reported that clinicians can access and enter patient information while offline, with records and notes synchronized when a connection becomes available.[15]
In Brazil, HiDoctor combines locally installed software with synchronized data and remote access. A 2013 academic study at the Federal University of Pelotas described its MedSync technology as keeping databases updated across computers used in locations such as a medical office, home, and hospital while also providing Internet access to the information.[16] Current product documentation describes each installed computer or device as a synchronization point that exchanges changes with other points, while synchronized data can also be accessed through a web interface.[17]
Denmark-based Auditdata Manage, used in audiology services, operates with the desktop Bridge application. Selected patient data can be loaded into Bridge for offline clinical work and synchronized back to the online Manage database when connectivity is restored.[18][19][20]
In Italy, Graffico develops custom clinical-management and electronic-record systems. For deployments requiring continued operation during connectivity problems, the company describes an optional offline mode in which required functions and data remain available locally and data are synchronized automatically after connectivity returns.[21] Unlike a fixed feature of a single standardized product, this architecture is described as being selected according to the requirements of each deployment.
Downtime and contingency procedures
[edit]Contingency plans define how clinical work should continue when electronic systems are unavailable. They may include paper forms, temporary procedures for patient identification and prescribing, defined staff responsibilities, communication methods, and processes for entering information into the EHR after normal service has been restored.[3][5]
Preparation can also include periodic drills so that staff know how to work during an outage. The effectiveness of downtime procedures depends not only on technical infrastructure but also on training, assignment of responsibilities, and prior identification of clinical functions that need to be restored first.[6]
Redundant and alternative access paths
[edit]Even where the primary EHR is not designed for disconnected operation, organizations may deploy systems specifically intended for downtime. These mechanisms aim to preserve at least read access to clinical information while the primary system is being recovered.
Reported approaches include read-only copies, independent repositories, and local downtime viewers. In one hospital network, a downtime viewer maintained recent clinical data on computers in patient-care areas after access to the primary EHR was lost.[7] Studies of EHR contingency planning have also identified clinic-level read-only backup systems among practices used to support continuity of care.[6]
The usefulness of an alternative path depends on its independence from the failure that caused the outage. A contingency web page hosted on a separate server, for example, may still be unavailable if it depends on the same failed network.[7] Availability can therefore involve diversity of access paths as well as conventional server redundancy.
Offline synchronization
[edit]Systems that allow disconnected work must subsequently synchronize locally produced changes with other repositories. In environments with multiple devices, the process must incorporate changes produced at different points while preserving consistency among copies.[8]
Synchronization becomes more complex when multiple devices or facilities record changes before reconnecting to the central repository. Continuity of access must therefore be balanced with preservation of information integrity.[8]
Backup and recovery
[edit]Backups have a different role from mechanisms that maintain access during an outage. Their primary purpose is to enable systems and data to be restored after loss, corruption, or unavailability of the original infrastructure.
Recovery planning includes identifying critical systems, setting priorities and acceptable restoration times, maintaining suitable backups, and periodically testing whether restoration actually works.[22] The existence of a backup file without tested restoration procedures does not itself ensure information availability.
Repositories separate from the primary EHR may also preserve access to specific clinical resources. A study published in 2025, for example, evaluated an offsite repository intended to keep clinical order sets available during EHR downtime.[23]
Data governance
[edit]Availability is also part of data governance in health care. Governance of clinical information includes assigning responsibility for access, maintaining data quality and integrity, defining retention requirements, and ensuring that information remains available throughout its life cycle.[24]
The location and distribution of data copies are only some elements of that governance. Maintaining both local and remote access paths can reduce dependence on a single access point, but it also requires rules for access control, updating, integrity, synchronization, and recovery. Likewise, using externally hosted infrastructure does not remove an organization's responsibility to establish how its information can be accessed and recovered when required.
From a continuity perspective, a central objective is to avoid making access to clinically necessary information dependent on a single point of failure. The SAFER guidance identifies single points of failure, including dependence on a single Internet connection, as a risk to information availability and integrity.[3] Organizations therefore need to understand where their data are stored, how they are accessed and synchronized, how they can be recovered, and which alternatives will remain available if the usual access path fails.
United States
[edit]In the United States, EHR availability is addressed in part through the HIPAA Security Rule. The rule applies to electronic protected health information (ePHI) held by regulated entities rather than specifically to EHR products. It requires regulated entities to ensure the confidentiality, integrity, and availability of the ePHI they create, receive, maintain, or transmit. The United States Department of Health and Human Services defines availability in this context as information being accessible and usable on demand by an authorized person.[25]
The Security Rule also requires contingency planning for emergencies or other events that damage systems containing ePHI. HHS guidance describes this as including plans for data backup, restoration of lost data, and continuation of critical processes in emergency mode.[25] NIST SP 800-66 Rev. 2 provides implementation guidance for these requirements and addresses contingency planning, recovery, testing, and assessment of critical services.[1]
The rule is technology-neutral and does not prescribe a particular local, cloud, or hybrid EHR architecture.[25] Separately, the Office of the National Coordinator for Health Information Technology's SAFER guidance addresses planned and unplanned EHR unavailability and provides recommended practices for downtime preparation, continued access to clinical information, and recovery.[3]
See also
[edit]References
[edit]- 1 2 3 "SP 800-66 Rev. 2 — Implementing the HIPAA Security Rule: A Cybersecurity Resource Guide". Computer Security Resource Center. National Institute of Standards and Technology. February 2024. doi:10.6028/NIST.SP.800-66r2. Retrieved 24 September 2026.
- 1 2 "ISO 27799:2025 — Health informatics — Information security controls in health based on ISO/IEC 27002". International Organization for Standardization. 2025. Retrieved 24 September 2026.
- 1 2 3 4 5 6 "2025 SAFER Guide: Contingency Planning". HealthIT.gov. Office of the National Coordinator for Health Information Technology. Retrieved 24 September 2026.
- 1 2 Larsen, E.; Fong, A.; Wernz, C.; Ratwani, R. M. (2018). "Implications of electronic health record downtime: an analysis of patient safety event reports". Journal of the American Medical Informatics Association. 25 (2): 187–191. doi:10.1093/jamia/ocx057. PMC 7647128. PMID 28575417.
- 1 2 Larsen, E.; Hoffman, D.; Rivera, C.; Kleiner, B. M.; Wernz, C.; Ratwani, R. M. (2019). "Continuing Patient Care during Electronic Health Record Downtime". Applied Clinical Informatics. 10 (3): 495–504. doi:10.1055/s-0039-1692678. PMC 6620179. PMID 31291677.
- 1 2 3 4 5 Sittig, D. F.; Gonzalez, D.; Singh, H. (2014). "Contingency planning for electronic health record-based care continuity: a survey of recommended practices". International Journal of Medical Informatics. doi:10.1016/j.ijmedinf.2014.07.007. PMID 25200197.
- 1 2 3 4 5 Lyon, R.; Jones, A.; Burke, R.; Baysari, M. T. (2023). "What Goes Up, Must Come Down: A State-of-the-Art Electronic Health Record Downtime and Uptime Procedure in a Metropolitan Health Setting". Applied Clinical Informatics. doi:10.1055/s-0043-1768995. PMC 10322225. PMID 37406674.
- 1 2 3 4 5 6 Ashista, H.; Comas, A. S.; Selby, T.; Essar, M. Y.; Alawa, J.; Al-Hajj, S.; Nelson, E. (2026). "An offline-first electronic health record for vulnerable populations: A mixed-methods feasibility study". PLOS Digital Health. doi:10.1371/journal.pdig.0001204. PMC 12904448. PMID 41686834.
- ↑ Wretborn, J.; Ekelund, U.; Wilhelms, D. B. (2019). "Emergency Department Workload and Crowding During a Major Electronic Health Record Breakdown". Frontiers in Public Health. doi:10.3389/fpubh.2019.00267. PMID 31572707.
- ↑ Harrison, A. M.; Siwani, R.; Pickering, B. W.; Herasevich, V. (2019). "Clinical impact of intraoperative electronic health record downtime on surgical patients". Journal of the American Medical Informatics Association. 26 (10): 928–933. doi:10.1093/jamia/ocz029. PMC 7647211. PMID 30946466.
- ↑ Larsen, E. P.; Rao, A. H.; Sasangohar, F. (2020). "Understanding the scope of downtime threats: A scoping review of downtime-focused literature and news media". Health Informatics Journal. doi:10.1177/1460458220918539. PMID 32403967.
- ↑ "Offline-ready EHR platform". Binsera. Retrieved 24 September 2026.
- ↑ "Beyond Essential Systems". World Health Organization. Retrieved 24 September 2026.
- ↑ "Meet the secret hero of Tamanu – universal sync". Beyond Essential Systems. 3 December 2024. Retrieved 24 September 2026.
- ↑ "NHS Shetland set to improve community patient services across the region with introduction of Cambric's Morse mobile EPR solution". NHS Shetland. 5 February 2026. Retrieved 24 September 2026.
- ↑ Ferrari, Vanessa Lima (2013). "A utilização de um SIG em uma microempresa do ramo da saúde e suas (des)vantagens" (PDF) (in Portuguese). Federal University of Pelotas. pp. 44–45. Retrieved 24 September 2026.
- ↑ "MedSync — Sincronia multiponto em seu HiDoctor". HiDoctor (in Portuguese). Retrieved 24 September 2026.
- ↑ "Integrations". Auditdata. Retrieved 24 September 2026.
- ↑ "Public Release Notes — Manage 11.5.0". Auditdata. Retrieved 24 September 2026.
- ↑ "Contact Auditdata". Auditdata. Retrieved 24 September 2026.
- ↑ "Clinic & Medical Center Management Software". Graffico. Retrieved 24 September 2026.
- ↑ "SP 800-34 Rev. 1 — Contingency Planning Guide for Federal Information Systems". Computer Security Resource Center. National Institute of Standards and Technology. November 2010. doi:10.6028/NIST.SP.800-34r1. Retrieved 24 September 2026.
- ↑ Proctor, S.; Desai, B. (2025). "Development and Evaluation of Offsite Repository for Clinical Assets, a Resilient Solution for Order Set Access during EHR Downtimes". Applied Clinical Informatics. doi:10.1055/a-2620-6221. PMID 40419254.
- ↑ Ghaffari Heshajin, S.; Sedghi, S.; Panahi, S.; Takian, A. (2024). "A framework for health information governance: a scoping review". Health Research Policy and Systems. 22. doi:10.1186/s12961-024-01193-9. PMC 11325756. PMID 39148078.
- 1 2 3 "Summary of the HIPAA Security Rule". HHS.gov. U.S. Department of Health and Human Services. Retrieved 24 September 2026.
Category:Electronic health records Category:Information security Category:Patient safety
