The Modern Clinic Runs on IT: What Happens When the Technology Fails?
Walk into a modern medical clinic and much of the technology is deliberately unobtrusive. A receptionist confirms an appointment. A clinician opens a patient record. A prescription is transmitted electronically. Test results appear in a portal. Claims are submitted to an insurer. Staff communicate through email, messaging platforms and practice-management systems.
Behind those ordinary activities is an increasingly complicated technology environment.
Electronic medical records, identity platforms, laptops, mobile devices, cloud applications, payment systems, diagnostic equipment, internet connectivity and third-party service providers have become part of routine clinical operations. Even relatively small practices can depend on technology stacks that would have looked like enterprise IT environments a generation ago.
That dependence has produced enormous benefits. Information moves faster, clinicians can collaborate more effectively, and many administrative processes can be automated. It has also created an operational reality that healthcare organizations sometimes underestimate: when the technology stops working, the problem does not remain inside IT. It reaches the waiting room.
Downtime is a clinical and business problem
Cybersecurity discussions in healthcare understandably focus on patient information. Medical data is sensitive, heavily regulated and valuable to criminals. Confidentiality, however, is only one part of the problem.
A clinic can retain the confidentiality of every patient record and still face a serious incident if clinicians cannot access those records when they are needed.
Consider a primary-care practice that loses access to its electronic medical record system on a busy Monday morning. Staff may no longer have immediate access to medication histories, allergies, previous diagnoses, specialist correspondence or scheduled appointments. Prescriptions may have to be handled differently. Patients arriving for follow-up care may need to explain information normally available to the clinician within seconds.
The consequences extend beyond clinical information. If billing systems are unavailable, revenue collection can stop. If identity services fail, employees may be unable to access applications that are otherwise functioning normally. If internet connectivity is lost, cloud-based systems may become inaccessible even though neither the clinic nor the software provider has suffered an outage. This is why healthcare cybersecurity has to be understood partly as an availability problem.
The Canadian Centre for Cyber Security specifically warns that cyber incidents affecting healthcare can disrupt critical services and recommends that healthcare organizations maintain backups and prepare to continue caring for patients when technology is affected. Canada's National Cyber Threat Assessment 2025–2026 also identifies ransomware as a major threat to critical infrastructure and cites the 2023 attack on a shared IT provider that affected five hospitals in Southern Ontario, temporarily disrupted internal systems and contributed to delays in patient care. The underlying lesson applies well beyond hospitals.
A smaller clinic may have fewer systems, but it may also have less redundancy, fewer technical staff and less capacity to absorb an extended disruption.
A clinic is only as resilient as its dependencies
One of the more difficult aspects of modern healthcare technology is that an organization can experience significant disruption without any of its own systems being directly compromised.
The 2024 attack on Change Healthcare demonstrated this at national scale in the United States. The incident disrupted infrastructure used for pharmacy transactions, medical claims and healthcare payments. CMS introduced temporary flexibilities partly to keep funds flowing to affected providers and prevent disruption to patient access and provider solvency. UnitedHealth subsequently reported that restoring the affected ecosystem involved pharmacy, payment, claims, eligibility and other services used throughout the healthcare system.
For an individual clinic, this illustrates an important form of technology risk: dependency risk.
A practice may rely on a cloud-based electronic health record, a separate scheduling platform, Microsoft 365 or Google Workspace, an identity provider, a payment processor, a telecommunications provider, a managed IT company and several specialized clinical services. Each provider can have excellent security and still represent a dependency.
If the electronic medical record is delivered as SaaS, the clinic may have no server to restore when the provider is unavailable. If authentication depends on a cloud identity platform, an identity outage can effectively become an application outage. If the practice loses internet connectivity, several unrelated services can disappear simultaneously.
Business continuity planning therefore needs to go beyond an inventory of servers and backups. An organization should understand the external services required to perform its critical functions and what happens when each one becomes unavailable.
For every important clinical or administrative process, the practical question is straightforward: What would staff do if this system disappeared for the next four hours? What about two days?
Organizations often discover that they have answers for the first scenario but not the second.
Backups matter, but restoration matters more
Backups remain one of the most important controls in healthcare technology, particularly against ransomware. They are also one of the easiest controls to misunderstand.
An organization can have technically successful backups every night and still have a weak recovery capability.
The more important questions are whether the required data is actually included, whether the backups are protected from the same compromise affecting production systems, how long restoration takes, and whether anyone has recently tested the process.
The Canadian Cyber Centre recommends maintaining multiple backups, including copies isolated from production networks, and regularly testing restoration. Its ransomware guidance also emphasizes identifying critical systems and establishing the order in which they need to be recovered. That sequencing becomes particularly important in a clinic.
Restoring a file server may be useful, but it may not restore clinical operations if identity services remain unavailable. Recovering the electronic health record may accomplish little if workstations cannot securely connect to it. A restored application may still depend on a database, network service or third-party integration that has not yet recovered. Recovery is therefore a systems problem rather than a backup problem.
A credible disaster-recovery plan needs to understand dependencies and establish recovery priorities based on business and clinical impact. It should also distinguish between systems an organization can restore itself and SaaS services where recovery depends almost entirely on the provider.
That distinction should influence procurement. Clinics should understand their vendors' backup practices, recovery commitments, incident-notification procedures and available data-export capabilities before an outage occurs.
Identity and devices have become critical infrastructure
The growing use of cloud applications has also made identity infrastructure more important to healthcare resilience. A decade ago, losing access to a local workstation account might inconvenience one employee. Today, a single cloud identity can provide access to email, electronic medical records, scheduling platforms, shared files, collaboration systems and administrative tools. That makes identity both a security control and an operational dependency.
Strong multifactor authentication, appropriate administrator privileges and well-managed accounts reduce the likelihood of compromise. But resilience requires thinking about failure as well. Organizations need processes for recovering administrator access, handling employee departures, replacing lost authentication devices and accessing critical services when normal authentication mechanisms are disrupted. The same principle applies to endpoint management.
Clinic computers are not merely office equipment. They are access points into clinical workflows. Devices need supported operating systems, timely updates, endpoint protection, encryption and controlled administrative privileges. Replacement also matters. If a ransomware response requires ten compromised computers to be rebuilt, how quickly can that happen?
A small clinic that owns twenty nearly identical managed laptops and can rapidly rebuild them may be more resilient than a larger practice with dozens of individually configured machines that nobody can reproduce reliably. Good device management therefore contributes to business continuity as much as security.
Downtime procedures have to work without IT
The most revealing test of a clinic's resilience may be surprisingly simple: turn off the technology and ask staff what happens next.
How are patients checked in?
How does a clinician obtain essential medical information?
How are prescriptions handled?
How are diagnostic results recorded?
How are urgent referrals communicated?
How will information captured during the outage eventually be reconciled with the electronic system?
These procedures cannot exist only in a document stored on the unavailable network.
Healthcare organizations need accessible downtime procedures, current contact information and staff who have practised working through realistic scenarios. HHS emergency-preparedness guidance similarly stresses robust downtime procedures because cyberattacks can affect both patient care and operational continuity. Exercises also expose dependencies that technical recovery plans miss.
A clinic may discover that its emergency contact list is stored only in Microsoft 365, that staff do not know how to operate a paper intake process, or that the only person who understands a critical vendor relationship is away. It may learn that restoring patient records is possible within several hours but restoring the scheduling system takes considerably longer. None of those findings requires a sophisticated penetration test. They require asking how the organization actually works when its normal assumptions fail.
Resilience is part of cybersecurity
Ransomware remains an obvious reason to take healthcare technology resilience seriously, but it should not define the entire problem.
Technology fails for many reasons. Cloud providers suffer outages. Software updates break applications. Hardware dies. Internet connections fail. Employees make mistakes. Vendors experience incidents. Attackers steal credentials or encrypt systems.
From the perspective of a clinician who cannot open a patient record, the immediate cause may matter less than the organization's ability to continue operating safely.
That is why backups, disaster recovery and business continuity should not be treated as administrative documents maintained primarily for compliance. Nor should cybersecurity be reduced to firewalls, endpoint software and annual awareness training. The objective is to preserve the organization's ability to deliver its essential services when technology is under stress.
For a modern clinic, that means understanding what systems it depends on, managing identities and devices properly, reducing unnecessary single points of failure, testing backups, evaluating SaaS providers, establishing realistic recovery priorities and giving staff workable procedures for the period before technology returns.
The more healthcare becomes digital, the more operational resilience becomes inseparable from patient care.
Related reading
Related reading
Perspective/Security//7 min read
Attackers Are Stealing Sessions, Not Passwords
Attackers can steal authenticated sessions without defeating MFA itself. Enterprises need phishing-resistant authentication, token protection and session-aware incident response.
Perspective/Security//8 min read
AI Agents Are Becoming Digital Identities. Security Architecture Isn’t Ready.
AI agents act across systems, but conventional IAM controls cannot fully govern their autonomy. Treating them as identities requires scoped access, ownership and traceability.
Perspective/Security//10 min read
Why Vulnerability Management Is a Risk Problem, Not a Scanning Problem
Scanners identify weaknesses, but business context determines what to fix first. Effective vulnerability management weighs exposure, exploitability and asset criticality.
Stay close to what matters.
New perspectives and practical analysis on security, risk, AI and product.
