What would happen if you woke up at 2 a.m. with chest pains but the area hospitals were closed due to a smallpox outbreak? What would happen if you couldnt get lifesaving blood work because the labs couldnt process the results or your health insurance provider couldnt process the authorization? What would happen if you were scheduled for surgery but the computer network containing your patient records was down due to a computer virus?
These are just a few of the scenarios that keep business continuity planners at hospitals and healthcare organizations across the country up at night and focused on the task at hand. Healthcare is the one thing you hope you will never need, but when the time comes, the availability of healthcare in this country is often taken for granted. Business continuity planning (BCP) professionals in the healthcare industry want to keep it that way.
The Heart of the Matter
At the heart of every hospital is the basic desire to care for the sick and injured who walk through the door. To do this, every hospital must be prepared to assist the public regardless of the circumstances. Though a hospital is essentially a business, in a disaster the primary focus lies in providing lifesaving care rather than keeping an eye on the bottom line. This fact is the backbone of every health organizations BCP.
When initiating business continuity into a health system, you must keep in mind that patients are number one. You have to understand that, says Kathy Lee Patterson, Disaster Recovery Specialist for Affiliated Computer Services, the nationwide corporation that oversees Information Technology for numerous hospitals throughout the country including the University of Pennsylvania Health System.
Patterson goes on to explain that this focus on patients extends to all aspects of continuity planning. When you are conducting a business impact analysis and interviews, you need to talk to the clinicians in terms patients and patient care instead of clients or customers or you are going to turn them off quickly, she says. You cant just talk to them with the typical DR/BCP language speaking only of business processes or profits and losses. Patients are the first priority to the clinical staff so you have to listen carefully to their concerns and speak to them from a patient caring aspect in order to obtain operational and financial impacts.
Angela Devlen, Team Lead of Corporate Disaster Recovery Planning for Boston-based Partners HealthCare which includes Brigham and Womens/Faulkner Hospitals, Dana-Farber/Partners CancerCare, and Massachusetts General Hospital, came to BCP in 1995. Prior to that, Devlen worked as an Emergency Medical Technician (EMT) in ambulances and emergency rooms throughout Canada. While an EMT, Devlen took part in the mass casualty disaster planning drills as required by the Joint Commission on the Accreditation of Healthcare Organizations (JCAHO). This regulation dictates that all hospitals must, have an emergency management program so that patient care can be continued effectively in the event of a disaster.
My background helps me in the day-to-day communication with the clinical staff, says Devlen. I have enough of a fundamental medical background that I find I have a better understanding of a specific departments needs.
Not every BCP professional in the healthcare industry has a history of working in trauma centers or emergency rooms. Skip Skivington worked in several of Kaiser Permanentes medical centers as an environmental health and safety director before becoming Department Director of Healthcare Continuity for the entire enterprise. Currently, his job responsibilities include creating in excess of 30,000 plans that cover every one of Kaiser Permanentes departments and business units. As the nations largest not-for-profit health maintenance organization serving more than 8 million people in nine states, these plans contain the means and methods for the continuation of healthcare for both the patients and the communities we serve.
Skivington explains that serving the local community is central in Kaiser Permanentes social mission. We have a strong belief that were not just a healthcare provider but that we have to give back to the communities we serve. In the past we have spearheaded a large number of outreach and involvement programs in addition to providing medical services to the communities.
The importance of supporting the local community was recently emphasized when President Bush signed a $4.6-billion bill requiring public health organizations to bolster their ability to respond to a terrorist attack. Health facilities are now mandated to have bioterror advisory committees that review potential risks and create failsafe emergency restoration plans.
The Technology Factor
If patients and the local community are number one, then technology is a close second in the healthcare industry. In just the past five to seven years, hospitals and clinicians have become considerably more dependent on computer systems to assist with the daily business operations. This presents both an opportunity and a challenge to business continuity planners.
In many cases, the increased reliance on computers has been the driving force behind the creation of comprehensive BCP plans within hospitals. For hospitals operating during a regional disaster, continuity of operations becomes even more critical because the patient load increases dramatically. Therefore, it is important that the technical infrastructure and critical applications the clinicians rely on to deliver service are uninterrupted. In 1996, the Health Insurance Portability and Accountability Act (HIPAA) was created requiring healthcare organizations to produce documented recovery plans for all computer systems, software applications, and advanced medical technology.
When selling senior management of a hospital on incorporating BCP into their mission, I always hope that there are some clinicians in the conference room, says Affiliated Computer Services Patterson. I ask them what they would do if they didnt have those systems for an extended period of time, and all of the sudden they realize that they couldnt enter patient menu requests electronically, couldnt schedule appointments electronically, the pharmacy couldnt dispense drugs as efficiently, they couldnt see x-rays as easily, or get blood results as quickly. And thats just the beginning. Once you get the clinicians thinking about how their patient care is related to computers, youll have their undivided attention and support.
However, unlike a typical business entity, different hospital departments may work on separate computer networks or systems. In many cases, departments will purchase their own equipment without informing Information System management or the business continuity planners. These systems, therefore, are not backed up by Information Systems nor incorporated into the Information Systems BCP. These independent systems and applications may be extremely critical to the departments mission and would be revealed upon performing a BIA, explains Patterson.
Multiple computer systems arent the only technology BCP professionals must take into consideration. Hospitals rely daily on a multitude of highly specialized equipment from bone density scanners to electrocardiogram machines all of which business continuity planners must take into account.
Technology is helping to drive this industry, says Skivington of Kaiser Permanente. Everyone wants more advanced technological procedures because that equates to living longer, better lives. As consumers, were driving that technological need. But being on the other side trying to plan for that is incredibly complex.
The Start of a Healthy Plan
Determining risks in an organization that has hundreds of unique departments, thousands of employees, and countless patients and visitors in the facility at any one time is no easy task.
At Kaiser Permanente weve developed three tiers of potential risks, explains Skivington. At the uppermost level we look at the overall risk of something like a bioterrorism attack that will affect the entire nation. Then we evaluate our risks by region. Finally, we look at it from a local perspective which includes the department level through a business impact analysis.
Patterson says that she prefers to start the BCP process for every hospital she works with by conducting a business impact analysis. A BIA is one of the best tools for uncovering risks, impacts and critical applications because important dependencies will be revealed once you start asking questions, she says. It is also an excellent method of initiating the training and awareness process within the hospital regarding BCP.
While healthcare organizations and typical business corporations use many of the same BCP methodologies to determine and mitigate risk, there is a slightly different twist in the healthcare industry. Unless a BCP professional starts pulling up patient records to learn the exact cost of specific procedures for every individual, it is almost impossible to ascertain the financial impact of a department being down. More important is how that departments unavailability is going to impact patient care.
Many BCP professionals integrate a walk-through into the BIA process to determine which departments have documented work-around procedures that explain how to continue providing care without computers, telephones, or vital medical machines. Some departments like the Emergency Room typically have comprehensive, up-to-date work-around procedures in place because of the numerous walk-ins, drive-ins, and ambulances arriving at their door every day. A department without work-around procedures could potentially disrupt patient care throughout the hospital. For example, a laboratory that is responsible for providing results to key departments could easily disrupt hospital operations if its computers go down and there are no documented work-around procedures.
The Price of Planning
Even though hospitals and senior management within the hospitals have long been focused on contingency planning, finding the money to support a continuity program is a tough task. According to a joint survey conducted by Contingency Planning & Management magazineand Strohl Systems, a provider of business continuity software and services, 46 percent of hospitals spend between $100,000 to $500,000 per year on business continuity planning. Frequently the team responsible for developing and updating the plans is significantly smaller than those found in other industries. The same survey indicates that two-thirds of hospitals and healthcare organizations employ less than 10 full-time BCP professionals and only three percent have more than 50 planners on staff. In contrast, 50 percent of companies across all industries have more than 10 full-time planners, 18 percent of which employ more than 50 planners.
According to Bill Rider, Manager of Data Security and Disaster Recovery at Johns Hopkins Hospital, his organization has always been seriously committed to BCP. Even with this commitment, Rider, who has 17 years of disaster recovery planning experience, says that he is always interested in garnering even more support from all areas of the hospital. One way he accomplishes this is by starting small and publicizing the results as he goes to create awareness about the program. What happens is that as you do work on the plans and communicate out your results, it becomes easier to look for funding and support, Rider says.
Running Tests
Assessing and compiling the data from a completed BIA into a plan can be a complicated process due to the size and complexity of healthcare organizations. Most large organizations today use automated BCP software to assist with the organization of information into a sound plan. This type of software is designed by top BCP experts and can reduce the amount of time and money required to build and maintain plans making it especially useful for organizations with limited resources to dedicate to BCP.
With business continuity plans in place, the next step is testing the plans. Fortunately, in the healthcare industry, testing is nothing new. To be in accordance with JCAHO, hospitals must conduct disaster drills a minimum of twice a year. Some organizations, like Kaiser Permanente, are planning on incorporating their BCP tests into those existing bi-annual tests. Other organizations perform tests during documented down times or planned events like a scheduled power shutdown.
Were taking a crawl walk run approach, says Johns Hopkins Rider. We started with a very basic eight-hour hotsite test. The next test was 16 hours and we restored a few applications and fine-tuned a few results. The most recent test was 24 hours long and we were able to successfully bring up several clinical applications and re-established our network connection.
While that was going on, Rider also developed a contingency plan in the event that Johns Hopkins data center had to be evacuated but not shut down in order to address things like biochemical alerts. We recognize the need for continued service and the currency of data so we created an alternate operations support center a dark site so that we can operate our data center remotely, he says. Now were looking at the possibility of mirroring and journaling to create localized redundant systems to help improve our recovery point objectives.
Insuring Against the Worst
According to the US Industry and Trade Outlook, more than 85 percent of employed adults in America rely on some form of health insurance to assist with medical expenses. This reliance makes BCP as important for healthcare insurance companies as it is for hospitals.
People want to make sure that the company insuring their health is going to be there when they need the help, says Jerald Ness, Corporate Data Security and Business Continuity Planner for Wellmark Blue Cross and Blue Shield, the largest provider of health insurance in Iowa and South Dakota. Healthcare is one of the most important things to each and every one of us. People want to make sure they dont have any issues regarding their health insurance. We cant afford to let our customers down.
Ness made the jump from audit services to business continuity planning more than 10 years ago because of the need he saw within the company. Shortly after he began work on the companys plans, Wellmarks corporate headquarters in Des Moines, Iowa was hit by heavy rainfall and floodwaters. Local rivers crested to 28 feet above normal and the city was left without safe drinking water. Though at that time many of the detailed plans werent yet written, Wellmark was able to provide uninterrupted service to their customers because they had taken the time to sit down and conceptualize what they would do in an emergency. The flooding disaster only intensified Wellmarks commitment to solid business continuity planning.
The New World Order
Although hospitals and health insurance companies across the country were already working on continuity plans in accordance with JCAHO and HIPAA, the events of September 11 and the ensuing anthrax attacks highlighted the importance of business continuity planning for the healthcare industry. Since then, there has been increased pressure to ensure that hospitals can withstand any attack, emergency, or disaster.
In the last year, Rider indicates that he has seen a significant increase in interest in how he is planning for the uninterrupted continuity of service for Johns Hopkins. In fact, Rider says that two other hospitals within the Johns Hopkins organization have approached him for more information about building comprehensive BCP programs for their facilities.
I think that there is just now beginning to be a recognition in the healthcare industry that there needs to be BCP/DR plans for every department in the enterprise, Rider says. Its a new and exciting evolution in both the healthcare and disaster recovery industries and I think were just at the tip of this iceberg.