When the Internet Goes Down: The Business Continuity Plan Most Santa Clarita Practices Do Not Have
The internet is down, it is 7:50 in the morning, and the schedule will not load. The phones work, which makes it worse, because patients are calling to confirm appointments nobody can see. Somebody restarts the router. Somebody else reaches a recording about an area outage with no estimated repair time. The first patient arrives at 8:00.
By the next morning the cut turns out to be under a road, which means permits, a locate ticket and traffic control, and the bad day quietly becomes a bad week. Nothing here was an attack, nobody did anything wrong, and everything the practice needs is on the wrong side of a broken line.
Overview
Once you are in an outage, the cause stops mattering. A shovel, a configuration change, a software update, a criminal, a government: the front desk experience is identical, and so is the arithmetic of how long the office stays open. So this piece does not rank threats. It looks at what is documented, then at the one business continuity decision that changes the outcome for a Santa Clarita practice.
The rule already asked for that decision, which is the part most practices are surprised by. HIPAA's contingency plan standard at 45 CFR 164.308(a)(7) requires procedures for responding to an emergency that damages systems holding electronic protected health information, naming fire, vandalism, system failure and natural disaster in its own text. Under it sit three required specifications: a data backup plan, a disaster recovery plan, and an emergency mode operation plan, the last defined as procedures to continue critical business processes while operating in emergency mode.
Most practices have the first. Some have the second. Almost nobody has written the third, and the third is exactly this: what the office does while the systems are down. It is required rather than addressable, so there is no alternative to document in its place. An accounting firm meets the same obligation through the written program our piece on the plan most small firms do not have covers.
The Challenge
Nine internet and cloud outages from the last fifteen years, newest first. Seven link to the documents their own institutions published. Two, Armenia and the European airports, rest on contemporaneous reporting instead, and we say so rather than blur them.
Iran, 2026: a country switched off, measured in months. Cloudflare's network data shows traffic falling to near zero on January 8, then a second shutdown from February 28 running well under one percent of normal for roughly 87 days before a partial return on May 26, after three shorter shutdowns in June 2025. Nothing like this is coming to Santa Clarita and we will not pretend otherwise. It earns a place because it is the only entry measured in months, and no plan written in any American office assumes weeks.
Amazon Web Services, October 2025: one region, thousands of unrelated businesses. Amazon's own post event summary describes a latent race condition that produced an empty DNS record for DynamoDB in the Northern Virginia region, running from late on October 19 until mid afternoon the next day and pulling Lambda, ECS, EKS, Connect, Redshift and EC2 down with it. Companies with no relationship to each other stopped at the same moment because they had all, without discussing it, rented the same room.
European airports, September 2025: nobody involved was breached. Check in software from Collins Aerospace was hit with ransomware, and Heathrow, Brussels and Berlin spent days boarding passengers by hand, with the EU cybersecurity agency confirming ransomware as the cause. The airports had good security and it was beside the point: they had outsourced a function they could not operate without, which is the mechanism our piece on third party vendor risk follows.
CrowdStrike, July 2024: not an attack at all. A content update from a security vendor took down an estimated 8.5 million Windows machines in a morning, and CISA issued its own alert noting it was not malicious activity. Hospitals diverted patients and procedures were postponed. The software doing the damage was the software bought to prevent it, which is not an argument against endpoint security. It is an argument that every dependency is one, including the ones wearing a badge.
Change Healthcare, February 2024: the one that stopped practices getting paid. Ransomware at a single clearinghouse interrupted claims and pharmacy routing nationally, and HHS keeps its own page calling the magnitude unprecedented and recording roughly 192.7 million individuals as impacted. Practices that had done nothing wrong could not bill for weeks, which our piece on ransomware in a regulated practice follows through.
The FAA, January 2023: every departure in the country held. The first nationwide ground stop since 2001, and the agency's own statement says contract personnel unintentionally deleted files while correcting synchronization between the live database and its backup, with no evidence of a cyberattack. Read that with your own environment in mind. The damage happened during routine maintenance of the safety net, which is why our piece on backup versus recovery exists.
Southwest Airlines, December 2022: ten days to recover from four. A storm started it and the operation could not be rebuilt afterward. The Department of Transportation's penalty announcement records 16,900 cancelled flights and more than two million passengers stranded. The lesson for a far smaller organization is the recovery curve: the disruption lasted days, the inability to catch up lasted much longer.
Rogers, July 2022: a national carrier, and 911 with it. Canada's telecom regulator published an independent assessment finding that staff removed an access control list filter during a network upgrade, flooding the core routers and crashing them within minutes. More than 12 million customers lost service for about 26 hours: mobile, home phone, internet, 911 calling and debit payments across the country, together.
Armenia, spring 2011: a shovel. A woman scavenging for scrap copper near a railway line in Georgia put her spade through a fiber optic cable. That one cable carried about 90 percent of Armenia's international traffic, and some 3.2 million people lost the internet for up to 12 hours. Carriers with a route through Iran stayed partly alive, which is this whole piece arriving fifteen years early: the ones with a second path kept working, and the ones without it waited.
Why It Matters
The likely version is boring and local. No Santa Clarita practice is going to be switched off by a government. It is going to lose a circuit to construction on Soledad Canyon or to a maintenance window that goes wrong, and the reason a bad day becomes a bad week is permits, locate tickets and a repair crew's queue, none of which you can escalate.
Nobody chose the dependency in one sitting. A practice bought an EHR, a phone system, a payment terminal and a scheduler across six years and ended up with all four resting on a handful of data centers nobody named out loud. Two circuits from two resellers in one conduit is the same mistake a layer down, and the FAA's 2023 account is the institutional version, where the damage happened between the primary and its backup.
The cost is not the outage, it is the catch up. A practice that spends two days on paper spends the next fortnight typing, reconciling, rebilling and hunting the three items that never made it back in. Nobody budgets for that half and it is usually the larger half. Meanwhile the insurance application already asks about business interruption and recovery in questions that are representations rather than opinions, which is the argument our piece on the audit you already signed makes at length.
What Organizations Should Watch For
- A single circuit, or a second one you have never seen carry traffic. Untested failover is a belief, not a control.
- Two connections sharing a last mile. Ask each provider whose physical plant reaches the building. Two bills, one conduit is the most common false redundancy in small offices.
- Operations critical software that cannot function offline. The record, the schedule, the imaging, the payment terminal, the door locks. List which are hosted and what each does when the link is dark.
- A phone system that dies with the circuit. If the practice cannot take calls during an outage, people learn about the problem by driving there.
- Backups that live only in the same cloud as the thing they protect. The offsite copy works only if it is reachable by a route the outage does not also break.
- No paper fallback and nobody named to declare it. Somebody has to say the office is in emergency mode and what that means. Without an owner that call gets made slowly, at the front desk, in front of patients.
Recommended Actions
- Get a second internet connection that is genuinely a second path. Fiber and cable, fiber and fixed wireless, or fiber and cellular, with the last mile confirmed as separate. The point is to survive a physical event rather than a billing one.
- Automate the failover, then test the failover in daylight. It belongs at the firewall. Pick a slow afternoon, pull the primary, and watch what happens to the phones, the terminal and the practice management system.
- Move what is operations critical to where you can reach it without the internet. If the office cannot run an hour without a system, that system should not depend on somebody else's network to answer.
- Leave the supporting software hosted on purpose. Email, electronic signature, marketing, collaboration and the offsite backup copy belong in the cloud. Pretending otherwise wastes money the critical list needs.
- Where the vendor gives you no choice, write the day down. Which functions stop, what the paper version looks like, who fills it in, and how it gets back in without creating a second mess. That page is the emergency mode plan the rule asked for.
- Print what only exists on a screen, and drill it once a year. Tomorrow's schedule at close of business, the carrier and vendor numbers, the escalation contacts, because during an outage the list of who to call is usually inside the thing that is down. Two announced hours on a light day will find the three things nobody thought of.
The SecureLynx Perspective
Observe:
When we walk a medical practice, an accounting firm or a law office in Santa Clarita, the question is never which security product is installed. It is what still works with the internet unplugged. The answer is usually less than expected, and the surprises are consistent: the phones go, the schedule goes, the terminal goes, and the printed fallback everyone remembers making is four years old and names two people who left.
Adapt:
Then the work sorts into two piles. The operations critical pile moves where the practice can reach it without a working link, which is ordinary managed IT work, and the supporting pile stays in hosted services where it belongs and costs less. Around that sits a real second path with automatic failover, a restore that has actually been performed rather than described, which is disaster recovery and business continuity planning, and the written emergency mode plan filed with the compliance record. We run this way ourselves, self hosted, with nothing rented at runtime.
Protect:
The honest limits. Local is not automatically safer. Bringing a system in house means taking on the patching, the uptime, the backup and the physical risk, which in this valley includes fire and a planned power shutoff in the same season. You are choosing to own the failure rather than rent it, and that only pays if it is maintained. We cannot promise you will never have an outage either, because nobody on that list of nine could, and every one of them was better funded than your practice. What we can do is make it boring: shorter, smaller, planned for, survivable on paper. Our pricing is published and the agreements are readable before you call.
Common questions
Does a backup internet connection protect a small business during an outage?
Possibly not, and the detail that decides it is physical rather than contractual. Two circuits sold by two different companies often ride the same conduit to the same handoff, which makes them one circuit with two bills. When the backhoe finds that conduit, both go down together. A second path is only a second path if the last mile is genuinely different: fiber and cable, fiber and fixed wireless, or fiber and cellular. Then ask whether the failover happens without a person. If continuity depends on somebody locating a hotspot and remembering a password, it fails at 7:30 in the morning before that person arrives. Put it at the firewall and test it on a quiet afternoon.
Should a small practice keep its systems local or in the cloud?
Both, split on one line. The useful distinction is not cloud versus local, it is operations critical versus supporting. What the office cannot work without for an hour should run where staff can reach it without the internet: the record, the schedule, the imaging, the door. What merely supports the work is well suited to a hosted service, including email, electronic signature, marketing, document collaboration and the offsite copy of the backup. Local also costs something honest. You take on the patching, the uptime, the backup and the physical risk, which in this valley includes fire. You are choosing to own the failure rather than rent it, and that only pays if the thing is maintained. An unmaintained server in a closet is worse than a good hosted service.
What is an emergency mode operation plan under the HIPAA Security Rule?
You write down what the office does on the day that vendor is dark, which is the part almost nobody has done. That means knowing which functions stop, which can run on paper, what the paper looks like, who fills it in, and how it gets back into the system afterward without creating a second problem. Ask the vendor two questions in writing: what offline capability the product has, and what its availability history looks like. For a practice handling protected health information this is not housekeeping. The Security Rule requires an emergency mode operation plan as a required implementation specification, meaning procedures that let critical processes continue while you operate in emergency mode. A cloud only system does not remove that obligation, it makes the written plan the only thing between you and a closed office.