Observation No. 20 · The fallback nobody has run

Ten locations were still closed on day ten.

On July 26, malware got into the network of AnMed, a South Carolina health system built around the 461-bed AnMed Medical Center in Anderson and more than 60 physician practices across South Carolina and Georgia. Within days the system had closed 83 facilities, taken down its MyChart patient portal, and shifted clinicians onto paper. Ten days later, on August 5, ten locations were still closed, several of them outpatient imaging sites, and AnMed had not said when the rest would reopen.

Urgent care and emergency services stayed open the entire time. Clinicians could still pull medical records and prescribe medications, “on a temporarily limited basis,” according to AnMed’s own updates page. The hospital kept functioning by dropping into downtime procedures: the manual, paper-based routines every health system keeps on file for the day its computer systems disappear.

That routine has an industry name, downtime, and an industry problem: it takes longer to climb out of than it should. Baxter Lee, president of healthcare cybersecurity firm Clearwater, said extended recoveries like AnMed’s usually signal a gap in preparation. “When recovery stretches this far, it is usually a sign that something in the preparation, whether that is the backups, incident response planning and testing, was not where it needed to be,” he said. Jason Griffin, managing director at the cybersecurity firm Nordic, offered a more forgiving read: “Every incident is different, but extended recovery periods have become more common as healthcare organizations take a deliberate approach to restoring systems.” Both are pointing at the same fork: whether the fallback was ever actually rehearsed, or only ever written down.

AnMed isn’t an outlier. The University of Mississippi Medical Center took more than a week to reopen clinics after a February ransomware attack knocked its electronic health records offline. Signature Healthcare in Massachusetts ran downtime procedures for more than a week after an April attack that also forced ambulance diversions. A slow climb back to normal is becoming the expected outcome of a healthcare cyberattack. Healthcare breaches, most of them caused by cyberattacks, cost an average of $6.6 million per incident, according to IBM research cited in the same reporting, and smaller systems with thinner cash reserves tend to feel that cost more acutely than large multi-hospital networks do.

Every business that runs on a computer has a downtime process somewhere, even if nobody calls it that. It’s the paper invoice pad kept in the truck for when the tablet app won’t load. It’s the work order clipped to a board when the scheduling software goes dark. It’s knowing, off the top of your head, which supplier will still take a phone order when their ordering portal is down.

Here’s the test AnMed’s ten days point to. A fallback that nobody has actually run only exists on paper. The real measure is whether someone in your shop could execute it cold, today, without you walking them through it. A binder updated every year and opened by no one is a document about a plan, not a plan.

The fix costs almost nothing. Once a quarter, run the shop for an hour as if the software is down: write the invoice by hand, log the job on paper, watch for where someone hesitates or the process breaks. Fix that piece, then go back to normal. It’s the same logic as a fire drill. Cheap when nothing’s wrong, the only thing that matters on the day something is.

If your primary system went dark for ten days, is your manual fallback something people actually know how to run, or a binder nobody has opened?

← More observations