The 15-Minute Meeting Every Salt Lake City Medical Practice Should Have This Month

September 2026 | HIPAA-Compliant IT Services Salt Lake City | National Preparedness Month | Medical Practice Continuity

If your EHR went down in the middle of a fully booked clinic day tomorrow, would your Salt Lake City medical practice handle it with confidence?

You may assume the answer is yes. But many practices don't discover gaps in communication, decision-making and downtime procedures until they're responding to a disruption with patients in the waiting room — which is the most expensive possible moment to learn, for the practice and for patient care.

September is National Preparedness Month, making this the perfect time to take a hard look at your practice's readiness. The good news: you don't need an all-day planning session or a full HIPAA risk assessment to get started. You need 15 minutes, the right people in the room — practice administrator, clinical lead, front desk lead — and five direct questions.

Question 1: If Our Systems Stopped Working Tomorrow, What Needs to Be Restored First?

You already know which tools your practice relies on every day. But recovery planning requires a more specific answer. If systems stopped tomorrow, your clinical staff would need to know which functions protect patients, revenue and daily operations first.

For most practices, that means the EHR — whether you run Epic, Cerner, Athenahealth or eClinicalWorks — followed by scheduling, e-prescribing, patient records access and billing platforms like AdvancedMD. The answer varies by practice, but the goal stays the same: identify what can't sit idle while patients are being seen.

When you define those priorities early, your team can focus on restoring what matters most to patient care instead of trying to restore everything at once.

Question 2: Who Makes Decisions During a Disruption?

Pressure has a way of quickly exposing unclear ownership — especially at 9:15 a.m. with a full schedule and providers who can't pull up charts.

When people don't know who can make the call, they wait for approval, duplicate work or pull physicians out of exam rooms to weigh in. Your team should know who starts the response, who moves the front desk team to paper workflows, who updates clinical staff, who communicates with patients, and who works with your EHR vendor, billing vendor or IT support partner.

These roles don't need a complicated chain of command. They need to remove confusion when timing matters. And if the disruption involves patient records, someone must own the HIPAA side: determining whether PHI was exposed, documenting the incident and starting breach-notification procedures if required. Clear decision-making roles help people act with confidence when normal routines break down.

Question 3: How Would We Communicate If Our Normal Tools Weren't Available?

Practice phones, the patient portal and email feel dependable until they stop working. Then even simple communication — confirming appointments, answering prescription questions, reaching on-call providers — becomes harder than it should be.

If your front desk team couldn't access email, would they know where to look for instructions? If your phone system failed, how would patients reach the practice to confirm or reschedule? If the portal went down, how would you notify patients about telehealth visits scheduled through Doxy.me?

A backup communication plan doesn't need to be complex. It needs to give staff and patients a dependable place to turn when the usual channels aren't available — and it needs to protect PHI on whatever backup channel you use. Clear communication reduces confusion exactly when patients need direction most.

Question 4: What's Our Biggest Operational Dependency?

Some risks hide in plain sight because they support the practice every day without drawing attention.

For most medical practices, the biggest dependency is the EHR itself — or the internet connection and vendor infrastructure it rides on. But it may also be your clearinghouse, your intake platform like Phreesia, or the one staff member who knows how the billing system actually works.

If your practice depends heavily on one system, one vendor or one person, it's critical to understand what happens when that dependency suddenly isn't available. This clarity helps you decide where documentation, downtime procedures, PHI backup verification or outside IT support for medical practices in Salt Lake City could reduce avoidable risk.

Question 5: If a Disruption Hit Tomorrow, What Would We Wish We'd Prepared Today?

This question cuts through assumptions because it puts leadership inside the moment they're trying to avoid.

Your team may wish it had documented downtime procedures for the front desk, tested patient record backups, updated vendor and on-call contact lists, or agreed on the order in which systems come back online. And because healthcare is the number one target for ransomware, your team may also wish it had rehearsed a HIPAA breach response before one was required.

None of those tasks sound dramatic during a normal week — which is exactly why practices push them aside. Preparation gives you room to respond instead of react. The best recovery plans answer questions before anyone has to ask them, and long before a patient is affected.

Where a HIPAA-Compliant IT Partner Comes In

After working through these five questions, you'll know which answers feel solid and which rely on assumptions.

That's where the right IT provider makes the difference. A partner that delivers HIPAA-compliant IT services in Salt Lake City helps identify risks to patient records, test recovery processes, verify PHI backups, document key systems and connect technology planning to how your practice actually delivers care.

The point isn't to make preparedness feel technical. It's to help you understand how systems, people and processes work together when pressure hits — so patient care doesn't stop when the technology does.

Frequently Asked Questions

Do you offer HIPAA-compliant IT services for medical practices in Salt Lake City?

Yes. Qual IT provides HIPAA-compliant IT services for Salt Lake City medical practices, including safeguards required under the HIPAA Security Rule: access controls, encryption, PHI backup and recovery, audit logging and staff security awareness. We sign business associate agreements and help practices document compliance.

What should a medical practice restore first after an outage?

Start with the systems that directly affect patient care: the EHR, scheduling and e-prescribing. Billing and administrative tools typically follow. A documented, tested restoration order keeps your clinical staff focused instead of improvising while patients wait.

How does Qual IT help medical practices with preparedness planning?

Qual IT works with Salt Lake City practices to identify operational risks, test PHI backup and recovery processes, document critical systems and downtime procedures, and build response plans your front desk team and clinical staff can actually execute mid-clinic-day.

Put This Meeting on Your Calendar

Don't wait to schedule this 15-minute conversation. If your leadership team can answer all five questions clearly, you have a strong sense of how your practice would respond under pressure. If some answers feel uncertain, you've found gaps worth addressing before they affect patient care.

We work with Salt Lake City medical practices to protect patient data and maintain HIPAA compliance.

Schedule a 10-minute discovery call with Qual IT to identify potential gaps, strengthen your preparedness strategy and build a recovery plan that protects your patients before you need it. Book your discovery call here.