When the EHR Goes Dark, Communications Fail Next: A Downtime Exercise for AV and UC

Downtime planning concentrates on the clinical applications, and reasonably so. Paper workflows, downtime forms, and read-only access get rehearsed.

The assumption underneath is that people can still reach each other while they use them.

That assumption deserves its own test, because the phones, paging, secure messaging, contact center and command-room displays can share dependencies with the systems that just failed.

What to settle before the exercise is written:

Decision Where it lands
What the outage boundary is Named explicitly, with what remains available stated rather than assumed
Which dependencies are shared Identity, WAN, hypervisor, power panel, carrier entry, administrator credentials
Whether the scenario is compound Several things fail at once, the way an incident does
Who is in the room while it is written Incident response, not only while it is run
What evidence is produced Artifacts with dates, not assurances

Key Takeaways

  • Joint Commission and the American Hospital Association launched the voluntary Cyber Resilience Readiness program on May 4, 2026, and added fee-based advisory services plus a voluntary certification in phase two on June 29, 2026.
  • The program addresses sustaining safe clinical operations during cyber-related technology outages lasting 30 days or longer.
  • Two platforms with separate hardware are not independent if they share an identity provider, a WAN, a hypervisor, or a power panel.
  • Exercise a compound failure. A clean single-system outage rehearses the easy case.
  • A backup path must never reconnect a quarantined environment. Communications recovery is subordinate to incident response.

On this page

Why Communications Is the Untested Lane

The communications estate is larger than a downtime plan tends to account for.

Desk and wireless phones. Emergency calling. Overhead paging. Nurse call and its integrations. Secure clinical messaging. Radios. The contact center. Video collaboration and telehealth. Interpreter access. Incident command rooms. Digital signage and wayfinding. Patient-facing messaging. Public and media updates.

Ask who owns each of these, who procured it, and when it was last tested.

Where those answers differ channel by channel, the failure that matters is the one that crosses several at once, and no single owner is positioned to notice it.

The Program This Sits Inside

There is now a named program framing this work.

Joint Commission and the American Hospital Association launched the Cyber Resilience Readiness program on May 4, 2026 as a voluntary initiative, aimed at helping hospitals and health systems sustain safe clinical operations during cyber-related technology outages lasting 30 days or longer. Phase one provided a free self-assessment.

On June 29, 2026 the two organizations rolled out phase two, adding fee-based advisory services from both partners and a Joint Commission certification.

The thirty-day framing is the part worth sitting with. A plan that works for four hours is a different artifact from one that works for four weeks, and the communications estate is where that difference shows up first.

Certification is voluntary. VIcom does not provide it, cannot confer it, and nothing in this article is a certification requirement. Reading AV and UC into that operational layer is VIcom’s extension of the program framing, not something the program states.

Redundant Is Not Independent

This is the distinction the whole exercise turns on.

Redundancy means more than one of something. Independence means a failure in one does not reach the other. Procurement can deliver redundancy without delivering independence, because independence has to be specified.

Two communications platforms shown with separate servers and separate vendors, but converging on four shared dependencies: identity provider, WAN, virtualization platform, and power panel. A failure in any shared dependency takes both platforms at once, so redundancy at the platform layer does not produce independence.
Two platforms, four shared dependencies. Redundant at the top, single-threaded underneath.

A hypothetical makes the distinction concrete. A hospital runs two UC servers so the platform survives a server failure, and both run on the same virtual infrastructure management plane. Its two session border controllers sit in the same rack, on the same power panel. Nothing about that estate is un-redundant, and none of it is independent.

Common convergence points worth checking by name:

  • One identity provider authenticating both platforms
  • One WAN or SD-WAN fabric carrying both
  • One virtualization platform or management plane hosting both
  • One power panel, UPS or generator circuit feeding both
  • One carrier, or two carriers sharing physical entry to the building
  • One administrator whose credentials are needed to change either

Map the Dependencies Before the Exercise

An exercise without a dependency map produces surprise rather than evidence.

For each communications channel, record what it needs to work:

Layer Question
Network Which core, which VLAN, which path off site
Name and address DNS and DHCP, and what happens when they are unreachable
Identity Which directory, and whether a local fallback exists
Cloud Which tenant, and whether it is reachable when the WAN is impaired
Carrier Which carrier, which entry point, which session border controller, and which mobile network the wireless devices depend on
Compute Which servers or gateways, on which virtualization platform
Power Which panel, which UPS, which generator circuit, and runtime
Endpoint Whether the device needs PoE, and what its battery life is
Administration Who can change it during an outage, and how they authenticate

The row that matters is the last one. Confirm break-glass administrative access before the exercise rather than discovering it during one.

Design a Compound Failure

A single clean outage rehearses the easy case.

A more useful scenario removes several things at once, the way a real incident does. For example: identity services unavailable, the WAN impaired, and the normal mass-notification console unreachable from the command room.

Structure the exercise as:

  1. Define the outage boundary and what remains available
  2. Name the clinical priorities that must continue regardless
  3. Inject changing conditions rather than a static scenario
  4. Force the primary channel to fail
  5. Validate that the backup channel actually works, rather than asserting it
  6. Log decisions and the time each took
  7. Measure time to reach every unit
  8. Capture corrective actions with owners

A hypothetical shows the gap. An exercise establishes that the backup radios work, and they do. On the night, the people who need them cannot say which channel is assigned, and the spare batteries are in a cabinet nobody has the key to. Nothing in that finding is about radios.

Note the distinction between a tabletop and a functional test. A tabletop verifies that people know the plan. It does not verify that the radio has coverage in the basement or that the spare batteries are charged. High-risk gaps found in a tabletop deserve a safe, authorized functional test afterwards.

Run It by Clinical Workflow

Channels are the wrong unit of analysis. Workflows are the right one.

  • How does a nurse reach a physician who is not answering a page
  • How does the transfer center operate without its usual application
  • How does security receive an emergency-calling alert
  • How is a rapid response or code called and heard
  • How are patients and families told what is happening
  • How does an interpreter join a bedside conversation
  • How does leadership convene, and where
  • How is an external media briefing supported
  • How does a unit receive a change in direction two hours later

Each of these crosses several channels. That is the point.

Where Containment Overrides Communication

This constraint is non-negotiable and belongs in the exercise design, not discovered during it.

A backup pathway must not automatically reconnect a quarantined environment, re-enable a disabled account, or bypass a segmentation control that incident response put in place. Restoring communication is subordinate to containing the incident.

Exercise leadership therefore needs incident response in the room while the scenario is written, not only while it is run. A communications workaround that undoes containment is a finding about the plan, not a success.

For the same reason, this article does not publish specific defensive configurations, and a real exercise should not circulate them either.

The Evidence That Proves It

Readiness is a set of artifacts, not a belief.

  • Contact lists current as of a stated date, and reachable without the network
  • Call trees that have been tested, with the date of the last test
  • Radio coverage confirmed in basements, stairwells, plant rooms and the loading dock
  • Assigned channels documented and known to the people who need them
  • Spare radio batteries located, charged, and someone accountable for both
  • UPS runtimes measured rather than specified
  • Generator circuit maps identifying what is actually on emergency power
  • Carrier diversity confirmed to the point of physical entry
  • Spare endpoints available and configured
  • Laminated quick guides where the network cannot reach
  • Break-glass administrative credentials tested within a stated period
  • The date and findings of the last exercise

Prioritize by Patient Impact, Then Retest

Not every gap is worth the same money.

A workable order is patient-safety impact, then time to failure, then likelihood, then effort. A gap that degrades in minutes and touches clinical escalation outranks one that degrades in days and touches signage.

Then retest the ones that were fixed. An untested remediation is a plan, not a control.

Existing guidance on emergency operations center AV for local government covers the same independence question in an incident-command room, and clinical telehealth room reliability covers testing a care workflow rather than a connection.

Take the Dependency Map Into the Exercise

The dependency map, the compound-failure structure, the workflow questions, the containment constraint and the evidence list are on a one-page worksheet for the team that writes the scenario.

Download the communications downtime worksheet — PDF, one page, no registration.

Sources

Related Reading

Where VIcom Fits

VIcom can map and test the technical communications chain across UC, paging, AV, command-center, network and power, document what actually shares a dependency, help design independent paths where they are justified, stage replacement equipment, and participate in exercises the organization leads.

VIcom does not substitute for clinical emergency management, does not provide certification, and does not set clinical priorities. Program details, certification requirements and guidance all change; confirm current requirements with the publishing bodies.

Connect with VIcom by filling out the form below.