Disaster Recovery for Enterprise Imaging
What Is Disaster Recovery?
Disaster recovery (DR) includes best practices and strategies for preventing or minimizing data loss and business disruptions should catastrophic events occur—equipment malfunctions, power outages, cybersecurity breaches, war or military attacks, natural disasters, or other significantly disruptive events occur. A recent ESG survey stated nine out of ten respondents reported that their organization could not withstand more than an hour’s worth of lost data before experiencing significant business impact.
Infrastructure failure can cost as much as USD 100,000 per hour, and critical application failure costs can range from USD 500,000 to USD 1 million per hour. More than 40% of small businesses will not reopen after experiencing a disaster, and among those that do, an additional 25% will fail within the first year after the crisis.
Disaster recovery planning involves strategizing, deploying technology, and implementing continuous testing. In addition, maintaining backups of data is a critical component, however, a backup and recovery process alone does not constitute a disaster recovery plan. It also includes ensuring that adequate storage and computing are available to maintain robust failover and failback procedures. Failover is the ability to switch automatically and seamlessly to a reliable backup system. When a component or primary healthcare infrastructure system fails, either a standby operational mode or redundancy should achieve failover. Failback involves switching back to the original primary systems. Failback is the second stage of a two-part system for safeguarding information in a crisis mode during natural disasters or other events that can compromise an IT operation.
The Most Common Types of Disaster Threats to Healthcare:
Natural Disasters
Winter storms, floods, tornados, hurricanes, wildfires, earthquakes, and other severe weather that pose a significant threat to human health and safety, property, critical infrastructure, and homeland security are considered natural disasters. These occur seasonally and without warning, causing periods of insecurity, disruption, and economic loss. How healthcare organizations care for patients during these circumstances has become complicated, especially if they must close or evacuate unexpectedly.

Two examples of the devastating impact natural disasters inflicted upon healthcare organizations are Hurricane Katrina and Hurricane Sandy. During the investigation of the preparation and response to Hurricane Katrina, the Select Bipartisan Committee found that nearly all disaster response issues arose from information gaps. Leaders acted hastily or without proper intelligence and analysis due to numerous communication failures and information-sharing gaps. The communication infrastructure was also damaged once the hurricane hit, and backup systems were unavailable.

Ariel View of Memorial Medical Center after Hurricane Katrina. Source: Nurse Labs
To further complicate matters, during both hurricanes, evacuation and transportation of medical patients occurred and created more confusion. During Hurricane Katrina, 65 hospitals across the country took in evacuated patients. However, many facilities needed electronic medical records (EMRs), and sending patients with paper records could have been more efficient and workable. As a result, many patients arrived at new locations with incomplete medical records.
Cyber Attacks

By 2031, global ransomware damages will surge past $265 billion, with a new attack hitting every two seconds.
Data breaches in healthcare have climbed for the past five years, rising a massive 42% in 2020 when the pandemic started. Of the total ransomware attacks reported in 2020, 60% targeted the healthcare sector.
The Biggest Healthcare Cybersecurity Attacks
In October 2009, the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) started publishing summaries of healthcare data breaches on its website.
Between October 21, 2009, when OCR first began publishing summaries of data breach reports on its “Wall of Shame,” and December 31, 2023, 5,887 significant healthcare data breaches have been reported. According to The HIPAA Journal, healthcare data breaches have become increasingly severe over the past few years, with 2021 recording 45.9 million records breached, followed by a rise to 51.9 million in 2022. However, 2023 has set a new alarming precedent, with 133 million records exposed, stolen, or improperly disclosed.
Change Healthcare Ransomware Attack 2024
Change Healthcare processes billing and insurance for hundreds of thousands of hospitals, pharmacies, and medical practices across the U.S. healthcare sector. As such, it collects and stores vast amounts of highly sensitive medical data on patients in the United States. The 2024 ransomware attack on Change Healthcare has resulted in the theft of the protected health information of up to 1 in 3 Americans. In early 2025, UnitedHealth Group has publicly confirmed that the breach involved the data of approximately 190,000,000 individuals.
Ascension Cyberattack 2024
A May 8, 2024, cyber attack caused Ascension system outages, disrupting operations at numerous Ascension hospitals nationwide. Ascension operates 140 hospitals in 18 states and the District of Columbia. Outages interrupted Hospital EHR access, Ascension pharmacy processing, and patient access to portals. The Black Basta ransomware gang, known for targeting healthcare organizations, carried out the attack.
Accellion Data Breach
Hackers exploited a zero-day vulnerability in Accellion’s (known as Kiteworks) 20-year-old File Transfer Appliance system in late 2020, leading to a significant data breach. This attack, the largest healthcare-related hack of 2021, impacted over 3.51 million people and affected at least 10 healthcare organizations, including hospitals, medical schools, and clinics.
Florida Healthy Kids Corporation
A Florida-based healthcare facility found in February 2021 that its web hosting provider had failed to patch over seven years’ worth of vulnerabilities, affecting over 3.5 million patients, making it one of the most significant healthcare-related data breaches ever. Unauthorized users gained access to the unsecured system and tampered with the data of thousands of applicants to the facility.
Power Outages

Power outages affect communication infrastructure, technology, power station transformers, and transportation. Hospitals, long-term care facilities, primary care offices, clinics, and emergency medical services are the most vulnerable when a power outage occurs, as the healthcare providers’ ability to communicate with their patients is compromised. Power outages often concern refrigeration for certain medications or medical devices. If a power outage occurs due to flooding, it can prevent patients from traveling to receive necessary care, deliveries, and medical workers from getting to work. Lack of generator fuel can be connected to power outages, causing the inability of heating and life support systems to operate.
Third-Party Technology Outages
Third-party technology outages can significantly disrupt healthcare operations, as many healthcare systems rely on external providers for essential services like electronic health records, billing, and telehealth.
On July 19, 2024, CrowdStrike released an update to its Falcon product, a platform designed to provide cloud-based protection against cyberattacks using AI to detect network and endpoint intrusions. The update had a compatibility flaw that caused devices running on Microsoft’s Windows operating system to crash and go offline. Once the update was released, CrowdStrike customers, including many healthcare customers, immediately started to experience tech issues.
Microsoft estimated that CrowdStrike’s update affected 8.5 million Windows devices. Many of these devices were a part of the networks that health systems rely on to provide daily care, and the outage caused providers all over the country to lose access to their EHR. Some well-known health systems impacted by the outage include Kaiser Permanente, Providence, Henry Ford Health, Nationwide Children’s Hospital, and the Dana-Farber Cancer Institute.
While this outage was relatively brief, it highlights the need for healthcare organizations to prepare for third-party technology disruptions.

Paramedics move an injured person toward an ambulance during a terror attack. Source: The Telegraph
Healthcare organizations are targets for terrorist attacks. Such attacks have far-reaching consequences, including decreased accessibility, possible casualties, and fear. The extent, incidence, and characteristics of terrorist attacks against hospitals are unknown. The Global Terrorism Database (GTD) analyzed all terrorist attacks against hospitals from 1970-2019. Researchers analyzed temporal factors, location, attack and weapon types, and the number of casualties or hostages. This analysis of the GTD identified 454 terrorist attacks on hospitals over 50 years.
How do healthcare organizations deal with disasters?
Centers for Medicare & Medicaid Services issued a regulation in 2016 requiring adequate planning to mitigate the potential impact on patient care should a disaster occur. Drills, preparedness exercises, and training focusing on how the organization will continue to provide patient care during health IT downtime are all part of a disaster plan. For example, organizations use paper as a backup for patient intake during EHR system outages. Healthcare organizations must provide a strategy for resuming health IT operations after downtime and integrating data and orders generated during the blackout.
Resources are available to help healthcare organizations comply with HIPAA Security Rule as they plan their contingencies, backup protocols, and operations should a disaster occur. The Office of the National Coordinator for Health Information Technology (ONC), in concert with the HHS Office for Civil Rights (OCR), created a HIPAA security risk assessment tool. This tool contains a series of helpful questions for an organization, from a preparedness standpoint, to ensure the availability and integrity of electronic patient health information.
Another resource available to healthcare organizations is a series of ONC tools known as SAFER (Safety Assurance Factors for Electronic Health Record (EHR) Resilience) guides. These interactive guides help organizations self-assess their health IT systems to optimize them from a patient safety standpoint.
The importance of planning for disaster recovery
A healthcare organization must create a backup plan for various disasters. Delays in resuming normal operations after a disaster can significantly put patients at serious risk if medical devices or medications are affected.
There is a difference between backup and disaster recovery. Backup is making an extra copy (or multiple copies) of data to protect it. For example, restoring backup data if an accidental deletion occurs, database corruption, or a problem with a software upgrade.
After an outage, disaster recovery refers to the plan and processes for reestablishing access to applications, data, and IT resources. The plan might involve switching over to a redundant set of servers and storage systems until your primary data center is functional again. It is common for organizations to confuse backup with disaster recovery. However, as they may discover after a severe outage, simply having copies of data doesn’t mean you can keep your business running. A robust, tested disaster recovery plan is necessary to ensure business continuity.
Enterprise Imaging Disaster Recovery Terminology
A few key terms shape strategic decisions and enable evaluation backup and disaster recovery solutions.
- Availability is when a system is fully available for the business functions designed. For a PACS, for example, this would mean support of DICOM image management, archival, and visualization. All essential system functions must be operating to qualify as available. (For example, image management and archive, but not visualization, would not be eligible for a PACS as “available” in the proper sense.) Availability in IT systems is often measured in “nines,” using the availability percentage per unit of time as the basis.

- Disaster recovery as a service (DRaaS) is a managed approach to disaster recovery. A third party hosts and manages the infrastructure used for disaster recovery. Some DRaaS offerings might provide tools to manage the disaster recovery processes or enable organizations to have those processes managed for them.
- Failback refers to switching back to the original systems. A failback occurs once the disaster has passed and the primary data center is functioning.
- Failover automatically offloads tasks to backup systems seamlessly for users. For example, an organization could fail from the primary data center to a secondary site, with redundant systems ready to take over immediately.
- Recovery point objective (RPO) refers to the data you can lose in a disaster, including continuously copying data to a remote data center so that an outage will not result in data loss. Some organizations determine that losing five minutes or one hour of data is acceptable.
- Recovery time objective (RTO) is the time to resume normal business operations after an outage. When establishing RTO, consider how much time to lose—and the impact on patients and the bottom line. The RTO can vary significantly between different types of businesses. For example, a public library can operate manually for a few days if it loses its catalog system while waiting for restoration. In contrast, a major online retailer would face significant revenue loss with just 10 minutes of downtime if its inventory system fails.
- Restore is transferring backup data to your primary system or data center. The restore process is generally considered part of backup rather than disaster recovery.
Prioritizing Workloads: Disaster Recovery Policies and Processes
Once key disaster recovery concepts are understood, organizations can apply them to create workflows and protocols. Many organizations have multiple RTOs and RPOs that reflect the importance of each workload to their business.
A standard and generally accepted model for Disaster Recovery levels derives from the early work of SHARE, a consortium of mainframe users, to classify relative levels of Disaster Recovery Readiness defines seven potential tiers of readiness, ranging from no preparation to complete business integration of preparation, referred to as the “Seven Tier” model.
- Tier 0: No off-site data – Possibly no recovery
- Tier 1: Data backup with no hot site
- Tier 2: Data backup with a hot site
- Tier 3: Electronic vaulting
- Tier 4: Point-in-time copies
- Tier 5: Transaction integrity
- Tier 6: Zero or near-Zero data loss
- Tier 7: Highly automated, business-integrated solution
Disaster Recovery Policies, as distinct from Disaster Recovery processes, are formalizations and, in many cases, required by statute (e.g., HIPAA) of the plans and processes in place to deal with disaster events.
Evaluate deployment options
Designing a healthcare disaster recovery plan includes evaluating deployment options. When going through this process, some questions are, “Does the organization need to keep some disaster recovery functions or backup data on-premise?” and “Would the organization benefit from a public cloud or hybrid cloud approach?” Depending on which deployment options an organization chooses, it could combine several alternatives for the types of technologies and processes.

On-Premise Storage
In some cases, keeping backup or disaster recovery processes on-premises can help retrieve data and recover IT services quickly. Retaining sensitive data on-premises also helps comply with strict data privacy or data sovereignty regulations.
However, for disaster recovery, a plan that relies wholly on an on-premises environment would take a lot of work. The entire data center (primary and secondary systems) will be affected if a natural disaster or power outage strikes. Most disaster recovery strategies employ a secondary disaster recovery site separate from the primary data center. A disaster recovery site is a location used by an organization to restore its IT infrastructure and business-critical operations when a primary production center is affected by a natural or man-made disaster. Depending on the organization, its location might be across town, across the country, or around the globe. By setting up a disaster recovery site, the organization can maintain operations and deliver services without interruption until it restores the primary location. Some factors to consider when deciding on a secondary site are performance, regulatory compliance, and physical accessibility to the proposed secondary site. The disaster recovery site usually contains fully functional servers (mirrors of the production servers) with reduced capacity. In most cases, disaster recovery sites don’t have redundant servers, but some organizations choose to have a fully mirrored site as an insurance policy.
Cloud Storage and Disaster Recovery

With the growing adoption of cloud-based solutions, cloud computing enables greater integration and collaboration between hospitals, medical organizations, and healthcare providers. Cloud-based backup and disaster recovery solutions are becoming increasingly popular among healthcare organizations. Many cloud solutions provide the infrastructure for storing data and, in some cases, the tools for managing backup and disaster recovery processes.
By selecting a cloud-based backup or disaster recovery offering, you can avoid the capital investment for infrastructure and the costs of managing the environment. In addition, you gain rapid scalability plus the geographic distance necessary to keep data safe in the event of a regional disaster.
Cloud-based backup and disaster recovery solutions can support both on-premises and cloud-based production environments. An organization may decide, for example, to store only backed-up or replicated data in the cloud while keeping the production environment in its data center. With this hybrid approach, the organization would gain the advantages of scalability and geographic distance without moving its production environment. Production and disaster recovery are located in the cloud but at different sites to ensure enough physical separation in a cloud-to-cloud backup model. Healthcare organizations often use other cloud providers to achieve extra resilience against disasters.
Cloud agnosticism is becoming increasingly important for software vendors as organizations adopt mobile applications; storing and backing up clinical data in the cloud ensures users have complete access, and a third party protects confidential patient information by continuously updating firewall security and other protective measures to maintain HIPAA compliance.
Traditional tape backups
Traditional magnetic tape storage has been utilized since the 1950s and can still be a part of an organization’s backup plan. Organizations have used traditional magnetic tape storage since the 1950s, and it remains valuable in backup plans today. Tape solutions store large amounts of data reliably and cost-effectively. Unlike hard disk drives, which offer direct access storage, tape drives provide sequential access storage.
In 2022, IBM introduced the Diamondback Tape Library, reaffirming that magnetic tape is a form of data storage relevant today. According to IBM, magnetic tape provides physically air-gapped isolation to increase resiliency against cyber security threats like ransomware. IBM has introduced a new tape storage solution designed for organizations needing to securely store hundreds of petabytes of data. This offering targets traditional enterprises and “new wave” hyper scalers—global companies that collect and manage massive customer data sets.
Tape can be effective for backup but is rarely used for disaster recovery, which requires faster access times than disk-based storage provides. Retrieving a tape from an offsite vault can result in losing several hours or days of availability.
Snapshot-based replication
A snapshot-based backup captures the current state of an application or disk at a moment. By writing only the changed data since the last snapshot, this method can help protect data while conserving storage space. A snapshot copies the state of a system at a certain point in time, preserving a virtual picture of your server’s file system and settings.
Snapshot-based replication can be used for backup or disaster recovery. Of course, the data is only as complete as your most recent snapshot. If snapshots are taken every hour, an organization must be willing to lose an hour’s worth of data.
Organizations can use snapshot-based replication for backup or disaster recovery, but the data is only as complete as the latest snapshot. If snapshots occur hourly, the organization must accept the potential loss of up to an hour’s data.
Continuous replication
Many organizations are moving toward continuous replication for disaster recovery and backup. With this method, the latest copy of a disk or application is continuously replicated to another location or the cloud, minimizing downtime and providing more granular recovery points. As with snapshot-based replication, continuous replication solves the problem of the “backup window,” where organizations risk losing data created between two scheduled backups.
Securing Medical Images for disaster preparedness
An effective disaster recovery plan allows healthcare organizations to quickly restore all medical data and resume normal processes while minimizing downtime and data loss. Due to complex infrastructure requirements, radiology departments need specialized disaster preparedness protocols, particularly for natural disasters or other emergencies that increase the demand for and volume of imaging exams. For instance, after an earthquake, the number of casualties may require increased imaging for patient diagnostics and triage.
An effective medical imaging disaster recovery plan requires a solid data backup plan. This plan outlines which medical data to back up, how often to back it up, and how long to store it. These factors depend on the type of medical data and the storage capacity of backup sites. It’s best to back up mission-critical data like medical imaging as frequently as possible.
Benefits of disaster recovery in the cloud
Preparing for a disaster means recovering quickly after an emergency. Implementing a solid data backup system, ideally with off-site storage, helps your organization minimize losses, maintain patient trust, and improve patient outcomes. The faster you resume normal operations, the sooner your healthcare facility can assist the community in recovering from the disaster.
Migrating to the cloud allows medical imaging environments to ensure availability, performance, and security while reducing infrastructure complexity and cost. When access to on-prem systems becomes limited, such as during a natural disaster or a pandemic, a cloud-based health IT platform has a significant advantage as part of a disaster recovery response plan.
With this approach, production workloads remain on-premises while failover runs in the cloud, allowing the decommission of secondary data centers and reducing capital and operational costs. No matter what happens to your production systems after a disaster, your medical imaging data stays secure in the cloud. You can then rebuild your systems while clinicians focus on patient care.
Hot vs. Cold vs. Warm Storage
When adopting a cloud-based medical imaging environment, three cloud storage types are available: hot, warm, and cold. The choice depends on the data’s usage and importance.
Data accessed or updated daily, such as current patient images and records, requires high protection and rapid retrieval. In contrast, long-term backups of rarely accessed records should use less immediate access.
Hot storage refers to frequently used data, like documents on your hard drive, requiring faster and more expensive hardware for immediate and reliable access. Any data you need to access right away should go into hot storage, including data that is
- Known to change
- Used for clinician query purposes
- Used in any current projects
Hot storage is also essential for machine learning (ML) projects. Since ML projects frequently read data and need quick access to the ML model, you should place this data in hot storage.
Cold storage is for data you want to keep but rarely access. It has slower retrieval rates and response times than services managing active data. Cold storage companies include Amazon Glacier, which keeps your data accessible if needed. You may need to retain this data for legal or compliance reasons, with requirements varying by jurisdiction. For example, in the U.S., many regions mandate the retention of medical images for five to seven years, and some cases, like records of minors, require retention for over 20 years.
Cold storage is also suitable for no longer updated but still queried data, known as “dormant data.” It’s like investing in homeowner’s insurance: most healthcare organizations rarely need to restore files fully but might need to retrieve a few in case of a disaster. Since retrieval costs are the main expense, keeping copies of images as an insurance policy is often the most cost-effective choice.
Data that requires continuous access but doesn’t need the rapid retrieval speed of hot storage works well in warm storage. Warm storage is designed for data without immediate access and stored in a slightly slower, capacity-optimized environment.

Comparison of different data storage types.
On-Premise, Cloud, or Hybrid Data Recovery Considerations
To determine the best location for data to ensure optimal availability for disaster recovery, assess the current workflow, and understand the final application. Data can be stored on-premises, in the cloud, or using a hybrid approach.
Considerations
- Radiologist and physician viewing workflow(s)
- HL7 and DICOM protocols behave differently with high latency
- Faster connections cost more but can increase data access
- Migrating to cloud storage demands security and typically an express route or encrypted end-to-end network.
- The workflow needs change and AI demands faster data access.
- AI algorithms may require increased investments in more performant storage.
- Data security is paramount.
- Enterprise Imaging vendors leveraging S3 or equivalent can gain security with data encrypted in flight and at rest (vendor dependent).

Enterprise imaging considerations before deploying on-premise, Cloud, or hybrid.
Dicom Systems Unifier Cloud Archive
When a healthcare system’s Picture Archiving and Communication System (PACS/MIMPS) experiences downtime, disaster recovery and business continuity must work together to keep mission-critical clinical workflows running. Unifier Cloud Archive ensures uninterrupted patient imaging operations, regardless of whether PACS/MIMPS downtime is planned or unplanned. This solution allows customers to store data in any chosen cloud in native DICOM format and enables querying, retrieving, and viewing DICOM objects using a zero-footprint viewer. The Unifier Cloud Archive is a real-time source for relevant prior images.
Dicom Systems Cloud Partners include AWS, Google Cloud, Azure, and Life Image. Collaborating with these partners allows us to deploy the Unifier platform as a bridge between on-premises systems and the cloud, allowing organizations to access data from a highly secure infrastructure.
In addition to our Cloud Partners, Dicom Systems solutions are also available on the AWS, Google Cloud, and Azure Marketplaces. Book time with one of our enterprise imaging workflow experts to learn more about Disaster Recovery solutions from Dicom Systems.