Map dependencies before something breaks

List the services needed for intake, clinical review, prescribing, fulfillment, payment, messaging and support. Record the vendor contact, escalation path, agreed support hours and any documented recovery commitment. Note dependencies shared by several services. Two tools can appear separate while relying on the same integration or care partner. Keep the contact list available through an approved route that does not depend solely on the system it is meant to rescue.

For each dependency, identify work that can continue and work that must pause. Distinguish a delayed status update from a service interruption. Ask vendors how to verify impact without retrying actions that could create duplicates. Use the order workflow map when the last completed step is unclear.

Assign business and clinical decisions separately

Name an incident coordinator to keep the timeline and decisions together. Give support a communication owner, finance a billing owner and the care partner a clinical escalation owner. The coordinator can organize the response without taking over clinical judgment. Have clinical partners define how pending and existing care is prioritized and which instructions support may use when patients report a health concern.

HHS's telehealth emergency-planning guidance recommends planning for disconnected appointments and alternate ways to reconnect. That patient emergency plan belongs with qualified care teams and is separate from a general vendor outage announcement. Make both plans accessible to the people who need them. Support should use approved escalation instructions rather than treating a technical incident as a reason to delay an urgent concern.

Source context: HHS Telehealth: Creating an Emergency Plan

Set explicit pause and fallback rules

Write down who may pause acquisition, checkout, renewal attempts or a program, and what evidence triggers the decision. For a clinical-service disruption, the care partner should determine the safe route for affected patients. For a pharmacy disruption, obtain the appropriate clinical, pharmacy and contractual review before routing elsewhere. A backup name in a spreadsheet is not a tested or authorized substitute.

For software or payment interruptions, agree on which actions may be queued and how they will be reconciled. Do not collect sensitive information in personal inboxes or unapproved forms to keep volume moving. Ask security and privacy owners to approve fallback tools and data handling beforehand. HHS describes contingency procedures for regulated entities' ePHI systems, including backup, restoration and protection during emergency operations.

Source context: HHS: Summary of the HIPAA Security Rule

Communicate confirmed impact and next steps

Use a short update with the affected function, what patients can do, an approved contact route and when the next update will arrive. State what is known and leave the restoration estimate unconfirmed unless the responsible vendor has supplied one. Keep public updates free of individual patient details. Have clinical owners approve any message that includes care instructions and finance approve messages about charges or refunds.

Give staff one current internal briefing so the call center and support inbox do not offer different answers. Record approved wording and the time it was issued. Update affected patients through permitted channels using the relevant queue, not a broad marketing audience. Use the patient support escalation guide to define who handles clinical concerns, billing questions and delivery issues during the disruption.

Recover by reconciling work, then improve the plan

A vendor saying service is restored starts recovery; it does not close every affected task. Reconcile submissions, charges, clinical handoffs, fulfillment events and messages against the approved source systems. Check for duplicates, missing work and notifications sent out of sequence. Let each responsible owner accept its queue before routine automation resumes. Record unresolved items with a person and next action.

Run a tabletop rehearsal before launch and after a material vendor change. Choose one failure, walk through contacts, permissions, patient communication and recovery, and record gaps. NIST's contingency planning guide provides a general framework for evaluating system priorities; it is not a telehealth legal checklist. Close incidents with a concise review of impact, decisions, root cause if confirmed and changes to the runbook. Avoid presenting an outage-free history as a future guarantee.

Source context: NIST SP 800-34 Revision 1: Contingency Planning Guide

Disruption decision matrix

Set thresholds with the responsible partners. Replace these prompts with approved actions, contacts and evidence for your stack.

On small screens, scroll the table sideways to view every column.

Disruption decision matrix
DependencyDecision ownerPause or fallback questionRecovery evidence
Clinical serviceCare partnerHow is affected care safely routed?Clinical queues accepted
PharmacyPharmacy and clinical ownersIs an alternative route approved?Outstanding fulfillment reconciled
PlatformTechnical and security ownersWhich approved processes can continue?Records and events validated
PaymentsFinance and processorWhich attempts stop to avoid duplicates?Charges and subscriptions reconciled
CommunicationsSupport and clinical ownersWhich channels and wording are approved?Affected users receive current instructions
Download this worksheet as CSV

Before you move forward

  • Keep vendor contacts and escalation hours current.
  • Assign clinical, technical, finance and communication authority.
  • Approve fallback systems and pause thresholds.
  • Rehearse a disruption with synthetic scenarios.
  • Reconcile queues and duplicate risk before closing an incident.

Sources and scope

Source check: October 10, 2026. Primary sources support the rules and vendor descriptions cited above. Worksheets are original planning tools, not provider commitments or forecasts. Requirements can change; confirm current terms for your program.

  1. HHS Telehealth: Creating an Emergency Plan

    Supports clinician-led planning for disconnections and alternate contact during telehealth emergencies. Not a founder clinical protocol. Checked October 10, 2026.

  2. HHS: Summary of the HIPAA Security Rule

    Supports contingency planning, backup, restoration and ePHI protection for regulated entities. Checked October 10, 2026.

  3. NIST SP 800-34 Revision 1: Contingency Planning Guide

    Updated November 11, 2010 version, with system priority and contingency planning framework. General federal systems guidance, not a telehealth compliance guarantee. Checked October 10, 2026.