top of page
Search

Hurricane Season and Your Practice's Patient Data — What Dental and Medical Practices in Palm Beach County Need to Know


Every June, South Florida prepares for hurricane season the same way — storm shutters go up, water gets stocked, generators get tested. Dental and medical practices do the same for their physical space. What most independent practices in Palm Beach County don't do is prepare their technology infrastructure with the same intentionality.


That gap is where the most preventable and most expensive damage happens.


I've been doing healthcare IT for dental and medical practices in Palm Beach Gardens, Jupiter, Stuart, and Port St. Lucie for 25 years. I've lived in Palm Beach Gardens since 2001. I've been through enough hurricane seasons to know exactly what happens to practice technology when a major storm hits — and what the difference looks like between practices that prepared and practices that didn't.


This article is the technology preparation conversation that most practices aren't having with their IT provider — and should be.


What actually happens to practice technology during a hurricane


The obvious scenario is physical destruction — a roof failure, flooding, a fallen tree through the wall. That happens. When it does, any technology in the affected space is likely destroyed or water-damaged beyond recovery. Servers, workstations, imaging systems, networking equipment — all of it.


But physical destruction isn't the most common technology casualty of a hurricane in South Florida. The most common scenario is extended power loss — days or weeks without reliable electricity across large portions of Palm Beach, Martin, and St. Lucie counties. What happens to a dental or medical practice during an extended power outage is a cascade:


The servers go down. The UPS batteries keep them running for minutes, not days. When the batteries drain, the servers shut down — sometimes cleanly, sometimes not. An unclean shutdown on a server running a Dentrix or Eaglesoft database can cause database corruption that requires significant recovery work even after power is restored.

The network goes down. No internet, no cloud access, no remote connectivity. Staff who attempt to work remotely — or physicians in a concierge practice who need to access patient records for after-hours calls — have no way to reach the systems they depend on.

The backup system goes down. If your backup runs to a local device — a NAS, an external drive, a server in the same building — that backup is offline. It's also in the same physical location as everything else being affected by the storm. If the building floods or loses power for two weeks, the backup is as unavailable as the primary data.


When power returns — which may be days or weeks later depending on the storm's severity and your location within the affected area — the practice attempts to restart. What happens next depends entirely on what backup infrastructure was in place before the storm.


The three backup scenarios and what they mean for your practice


Scenario 1: No offsite backup.


The practice has local backup only — a drive, a NAS, or a server in the same building as the primary systems. When the building is affected, the backup is affected simultaneously. If the primary data is damaged or destroyed, there is nothing to restore from. The practice loses patient records, imaging data, billing history, and scheduling information accumulated over years or decades.


This is the worst-case scenario — and it's more common than it should be among independent practices in South Florida. The cost of rebuilding from scratch, the HIPAA breach notification requirements triggered by permanent loss of patient records, and the operational disruption of months without complete patient histories make this a practice-ending event for some practices.


Scenario 2: Cloud backup — untested.


The practice has cloud backup — data is being copied to an offsite cloud location nightly. This is significantly better than local-only backup. After the storm, the data is retrievable. But if that backup has never been tested — if no one has ever actually restored from it — the recovery process is slower, more uncertain, and more expensive than it needs to be.


Untested cloud backup has failure modes that only become apparent during recovery. Files may be corrupted. The restoration process may be slower than expected. The EMR or practice management software may not restore cleanly from the backup format being used. These issues are solvable — but solving them after a storm, when your staff is displaced, your office may not be accessible, and patients are calling — is significantly harder than solving them in advance.


Scenario 3: Immutable offsite cloud backup — tested.


The practice has immutable cloud backup — data is encrypted and copied to a geographically separate cloud infrastructure nightly, and that backup is verified after every cycle. Restoration from backup has been tested — specific files and full system recovery have both been confirmed to work correctly. The recovery time objective is documented and has been validated.


When the storm passes and power returns, this practice calls its IT provider. The restoration process begins immediately, following a documented procedure that has already been verified. Within hours — not days — the practice is back online with complete, current patient data. The only limitation is the physical accessibility of the office and the restoration of power and internet connectivity.


The difference between Scenario 2 and Scenario 3 is not the backup technology — it's the testing. Immutable cloud backup that has never been tested is not meaningfully better than untested cloud backup. The testing is what converts a theoretical protection into a verified one.


The HIPAA dimension of hurricane-related data loss


A hurricane that destroys or permanently compromises patient records is not just an operational disaster — it's a HIPAA event.


The HIPAA Security Rule requires covered entities to implement contingency planning procedures — backup procedures, disaster recovery plans, emergency mode operation plans, and testing and revision procedures. These requirements exist specifically to address scenarios like natural disasters that threaten the availability and integrity of protected health information.


A practice that loses patient records in a hurricane and cannot recover them has a potential HIPAA breach — because the unavailability of ePHI following a natural disaster may constitute an impermissible disclosure under the Breach Notification Rule, depending on the circumstances. More directly, a practice that had inadequate backup and contingency planning in place is in a difficult position when HHS reviews its compliance posture following a significant weather event.


OCR has specifically addressed natural disaster scenarios in its HIPAA guidance. The expectation is that covered entities will have implemented the contingency planning requirements before a disaster occurs — not that they will attempt to implement them after the fact.


South Florida practices that do not have documented, tested backup and disaster recovery procedures are not fully compliant with the HIPAA Security Rule's contingency planning requirements — regardless of how well their other security controls are implemented.


What a hurricane-ready IT infrastructure looks like


A dental or medical practice in Palm Beach County or the Treasure Coast that is genuinely prepared for hurricane season has several specific things in place — and they need to be in place before the storm, not assembled during one.


Immutable offsite cloud backup with geographic separation.


The cloud infrastructure where your backup lives needs to be in a different geographic region — not a data center in West Palm Beach that faces the same storm as your office. Major cloud providers operate data centers in regions far removed from South Florida. Your backup should be replicated to one of these remote regions so that even a catastrophic storm affecting your entire service area doesn't compromise the backup infrastructure.


Immutability means the backup cannot be modified or deleted — by anyone, including an attacker or a misconfigured process. This matters because ransomware specifically targets backup systems. An immutable backup survives a ransomware attack that coincides with a storm-related vulnerability window — which is a real scenario, since attackers exploit disaster periods when IT providers are managing multiple emergencies simultaneously.


Tested recovery with a documented recovery time objective.


How long will it take your practice to be back online after a significant event? That question needs a specific, verified answer — not an estimate. The only way to know the answer is to have tested it.


Recovery testing for a dental or medical practice should include restoration of the practice management software database, restoration of imaging data, restoration of billing and scheduling information, and verification that each restored component functions correctly with the others. The test should be documented, and the results should inform a realistic recovery time objective that your practice can plan around.

A business continuity plan for partial operations.


Full recovery after a major storm may take days — even with excellent backup infrastructure, the physical office needs power, internet connectivity, and accessible roads before full operations can resume. A business continuity plan addresses what happens in the interim.


For a dental practice, this means: how do we handle patients who need emergency care during an extended closure? How do we communicate with patients about appointment status? How do we process billing and insurance while our primary systems are offline? For a concierge medical practice in Jupiter or Palm Beach Gardens, this means: how does the physician access patient records for after-hours calls during an extended outage?


These questions have answers — but the answers need to be worked out in advance, not improvised during a crisis.


An IT provider who understands South Florida specifically.


This is not a generic statement about choosing a local provider. It's specific to hurricane preparedness. An IT provider based in South Florida — who has been through multiple hurricane seasons in this market — knows what the actual failure modes look like. They know which infrastructure components are most vulnerable to extended power loss, which backup configurations perform best during regional internet outages, and what the realistic recovery timeline looks like for a practice in Palm Beach Gardens versus one in Stuart versus one in Port St. Lucie.


An IT provider based outside South Florida may have excellent technical capabilities but lack the specific, experiential knowledge of how a major storm affects the technology infrastructure of practices in this geography. That gap matters when the scenario goes from theoretical to real.


The timing question


Hurricane season runs from June 1 through November 30. The peak of the season — statistically the most active period — runs from mid-August through mid-October. The time to address backup and disaster recovery vulnerabilities is before that peak, not during it.


The reason timing matters is practical. Implementing a new backup system, testing recovery, and documenting a business continuity plan takes weeks, not days. An IT provider who is managing multiple client emergencies in the immediate aftermath of a storm is not available to implement new infrastructure for practices that didn't prepare. The practices that are back online fastest after a storm are the ones that were already prepared before it hit.


If you're reading this in hurricane season and you're not certain your practice's backup infrastructure is adequate — the window to address it is now, not after the first named storm of the season.


What to ask your IT provider before August


If you're a dental or medical practice in Palm Beach County or the Treasure Coast and you're evaluating whether your current backup and disaster recovery infrastructure is adequate for hurricane season, here are the specific questions to ask.

Where is our backup data stored — specifically, which geographic region is the cloud infrastructure located in? If the answer is somewhere in South Florida, that's a gap.

Is our backup immutable — can it be modified or deleted by anyone, including our own administrative accounts? If the answer is no, your backup is vulnerable to ransomware that coincides with a storm.


When was the last time we tested full recovery from backup? If the answer is never, or more than 12 months ago, you don't know whether your backup actually works.

What is our documented recovery time objective — how long will it actually take to be back online after a significant event? If the answer is "it depends" without a specific verified number, you haven't tested it.


Do we have a documented business continuity plan that addresses partial operations during an extended outage? If the answer is no, your plan for the period between the storm and full recovery is improvisation.


If your IT provider can answer all five of these questions specifically and confidently, your hurricane preparedness is in good shape. If the answers are vague, your infrastructure may not perform the way you're assuming it will.


Where to start


If you're a dental or medical practice in Palm Beach County or the Treasure Coast and you're not certain your backup and disaster recovery infrastructure is adequate for hurricane season, the right starting point is an honest assessment of where you actually stand — before the season peaks.


Skyline Technology offers a complimentary HIPAA IT Risk Assessment for dental and medical practices in Palm Beach Gardens, Jupiter, Stuart, and Port St. Lucie. It covers your backup and disaster recovery posture as part of a six-category review and produces a written summary with prioritized recommendations — yours to keep with no obligation.


Anthony Lauria is the founder of Skyline Technology, a Palm Beach Gardens-based managed IT provider serving dental and medical practices exclusively across Palm Beach, Martin, and St. Lucie counties. He has been in IT since 2000 and has lived in Palm Beach Gardens since 2001.


Request a complimentary HIPAA IT Risk Assessment at skyline.technology/hipaa-assessment or call or text (561) 316-8665.

 
 
bottom of page