Downtime planning concentrates on the clinical applications, and reasonably so. Paper workflows, downtime forms, and read-only access get rehearsed.
The assumption underneath is that people can still reach each other while they use them.
That assumption deserves its own test, because the phones, paging, secure messaging, contact center and command-room displays can share dependencies with the systems that just failed.
What to settle before the exercise is written:
| Decision | Where it lands |
|---|---|
| What the outage boundary is | Named explicitly, with what remains available stated rather than assumed |
| Which dependencies are shared | Identity, WAN, hypervisor, power panel, carrier entry, administrator credentials |
| Whether the scenario is compound | Several things fail at once, the way an incident does |
| Who is in the room while it is written | Incident response, not only while it is run |
| What evidence is produced | Artifacts with dates, not assurances |
Key Takeaways
- Joint Commission and the American Hospital Association launched the voluntary Cyber Resilience Readiness program on May 4, 2026, and added fee-based advisory services plus a voluntary certification in phase two on June 29, 2026.
- The program addresses sustaining safe clinical operations during cyber-related technology outages lasting 30 days or longer.
- Two platforms with separate hardware are not independent if they share an identity provider, a WAN, a hypervisor, or a power panel.
- Exercise a compound failure. A clean single-system outage rehearses the easy case.
- A backup path must never reconnect a quarantined environment. Communications recovery is subordinate to incident response.
On this page
- Why Communications Is the Untested Lane
- The Program This Sits Inside
- Redundant Is Not Independent
- Map the Dependencies Before the Exercise
- Design a Compound Failure
- Run It by Clinical Workflow
- Where Containment Overrides Communication
- The Evidence That Proves It
- Prioritize by Patient Impact, Then Retest
- Take the Dependency Map Into the Exercise
Why Communications Is the Untested Lane
The communications estate is larger than a downtime plan tends to account for.
Desk and wireless phones. Emergency calling. Overhead paging. Nurse call and its integrations. Secure clinical messaging. Radios. The contact center. Video collaboration and telehealth. Interpreter access. Incident command rooms. Digital signage and wayfinding. Patient-facing messaging. Public and media updates.
Ask who owns each of these, who procured it, and when it was last tested.
Where those answers differ channel by channel, the failure that matters is the one that crosses several at once, and no single owner is positioned to notice it.
The Program This Sits Inside
There is now a named program framing this work.
Joint Commission and the American Hospital Association launched the Cyber Resilience Readiness program on May 4, 2026 as a voluntary initiative, aimed at helping hospitals and health systems sustain safe clinical operations during cyber-related technology outages lasting 30 days or longer. Phase one provided a free self-assessment.
On June 29, 2026 the two organizations rolled out phase two, adding fee-based advisory services from both partners and a Joint Commission certification.
The thirty-day framing is the part worth sitting with. A plan that works for four hours is a different artifact from one that works for four weeks, and the communications estate is where that difference shows up first.
Certification is voluntary. VIcom does not provide it, cannot confer it, and nothing in this article is a certification requirement. Reading AV and UC into that operational layer is VIcom’s extension of the program framing, not something the program states.
Redundant Is Not Independent
This is the distinction the whole exercise turns on.
Redundancy means more than one of something. Independence means a failure in one does not reach the other. Procurement can deliver redundancy without delivering independence, because independence has to be specified.

A hypothetical makes the distinction concrete. A hospital runs two UC servers so the platform survives a server failure, and both run on the same virtual infrastructure management plane. Its two session border controllers sit in the same rack, on the same power panel. Nothing about that estate is un-redundant, and none of it is independent.
Common convergence points worth checking by name:
- One identity provider authenticating both platforms
- One WAN or SD-WAN fabric carrying both
- One virtualization platform or management plane hosting both
- One power panel, UPS or generator circuit feeding both
- One carrier, or two carriers sharing physical entry to the building
- One administrator whose credentials are needed to change either
Map the Dependencies Before the Exercise
An exercise without a dependency map produces surprise rather than evidence.
For each communications channel, record what it needs to work:
| Layer | Question |
|---|---|
| Network | Which core, which VLAN, which path off site |
| Name and address | DNS and DHCP, and what happens when they are unreachable |
| Identity | Which directory, and whether a local fallback exists |
| Cloud | Which tenant, and whether it is reachable when the WAN is impaired |
| Carrier | Which carrier, which entry point, which session border controller, and which mobile network the wireless devices depend on |
| Compute | Which servers or gateways, on which virtualization platform |
| Power | Which panel, which UPS, which generator circuit, and runtime |
| Endpoint | Whether the device needs PoE, and what its battery life is |
| Administration | Who can change it during an outage, and how they authenticate |
The row that matters is the last one. Confirm break-glass administrative access before the exercise rather than discovering it during one.
Design a Compound Failure
A single clean outage rehearses the easy case.
A more useful scenario removes several things at once, the way a real incident does. For example: identity services unavailable, the WAN impaired, and the normal mass-notification console unreachable from the command room.
Structure the exercise as:
- Define the outage boundary and what remains available
- Name the clinical priorities that must continue regardless
- Inject changing conditions rather than a static scenario
- Force the primary channel to fail
- Validate that the backup channel actually works, rather than asserting it
- Log decisions and the time each took
- Measure time to reach every unit
- Capture corrective actions with owners
A hypothetical shows the gap. An exercise establishes that the backup radios work, and they do. On the night, the people who need them cannot say which channel is assigned, and the spare batteries are in a cabinet nobody has the key to. Nothing in that finding is about radios.
Note the distinction between a tabletop and a functional test. A tabletop verifies that people know the plan. It does not verify that the radio has coverage in the basement or that the spare batteries are charged. High-risk gaps found in a tabletop deserve a safe, authorized functional test afterwards.
Run It by Clinical Workflow
Channels are the wrong unit of analysis. Workflows are the right one.
- How does a nurse reach a physician who is not answering a page
- How does the transfer center operate without its usual application
- How does security receive an emergency-calling alert
- How is a rapid response or code called and heard
- How are patients and families told what is happening
- How does an interpreter join a bedside conversation
- How does leadership convene, and where
- How is an external media briefing supported
- How does a unit receive a change in direction two hours later
Each of these crosses several channels. That is the point.
Where Containment Overrides Communication
This constraint is non-negotiable and belongs in the exercise design, not discovered during it.
A backup pathway must not automatically reconnect a quarantined environment, re-enable a disabled account, or bypass a segmentation control that incident response put in place. Restoring communication is subordinate to containing the incident.
Exercise leadership therefore needs incident response in the room while the scenario is written, not only while it is run. A communications workaround that undoes containment is a finding about the plan, not a success.
For the same reason, this article does not publish specific defensive configurations, and a real exercise should not circulate them either.
The Evidence That Proves It
Readiness is a set of artifacts, not a belief.
- Contact lists current as of a stated date, and reachable without the network
- Call trees that have been tested, with the date of the last test
- Radio coverage confirmed in basements, stairwells, plant rooms and the loading dock
- Assigned channels documented and known to the people who need them
- Spare radio batteries located, charged, and someone accountable for both
- UPS runtimes measured rather than specified
- Generator circuit maps identifying what is actually on emergency power
- Carrier diversity confirmed to the point of physical entry
- Spare endpoints available and configured
- Laminated quick guides where the network cannot reach
- Break-glass administrative credentials tested within a stated period
- The date and findings of the last exercise
Prioritize by Patient Impact, Then Retest
Not every gap is worth the same money.
A workable order is patient-safety impact, then time to failure, then likelihood, then effort. A gap that degrades in minutes and touches clinical escalation outranks one that degrades in days and touches signage.
Then retest the ones that were fixed. An untested remediation is a plan, not a control.
Existing guidance on emergency operations center AV for local government covers the same independence question in an incident-command room, and clinical telehealth room reliability covers testing a care workflow rather than a connection.
Take the Dependency Map Into the Exercise
The dependency map, the compound-failure structure, the workflow questions, the containment constraint and the evidence list are on a one-page worksheet for the team that writes the scenario.
Download the communications downtime worksheet — PDF, one page, no registration.
Sources
- American Hospital Association, AHA, Joint Commission announce cybersecurity readiness effort, published 2026-05-04; retrieved 2026-08-28.
- Joint Commission, Cyber Resilience Readiness Program, retrieved 2026-08-28.
- Joint Commission, Joint Commission and American Hospital Association Launch Second Phase of Cyber Resilience Readiness Program, published 2026-06-29; retrieved 2026-08-28.
- HHS 405(d), Health Industry Cybersecurity Practices, retrieved 2026-08-28.
Related Reading
- The clinical telehealth room reliability audit — testing the workflow, not the connection.
- Emergency operations center AV for local government — independence in an incident-command room.
- How to upgrade healthcare AV without compromising infection control — doing physical work in a live clinical area.
Where VIcom Fits
VIcom can map and test the technical communications chain across UC, paging, AV, command-center, network and power, document what actually shares a dependency, help design independent paths where they are justified, stage replacement equipment, and participate in exercises the organization leads.
VIcom does not substitute for clinical emergency management, does not provide certification, and does not set clinical priorities. Program details, certification requirements and guidance all change; confirm current requirements with the publishing bodies.
Connect with VIcom by filling out the form below.
