News & Events

The Day the Systems Went Down: Why Law Firms, Medical Practices, and Accounting Firms Need a Real Business Continuity Plan

Deadlines approaching.
Patients waiting.
Tax filings due.
Client files inaccessible.
Email unavailable.
Phones ringing with no answers.

Then someone says:

“Don’t worry. I’m sure it will be back up soon.”

That is not a business continuity plan.

It is hope.

For law firms, medical practices, accounting firms, and other organizations handling confidential or regulated information, an outage is more than an inconvenience. A ransomware attack, failed server, cloud disruption, power loss, or compromised account can interrupt revenue, damage trust, create compliance obligations, and put your clients or patients at risk.

A real business continuity and disaster recovery strategy gives you a controlled path forward when normal operations stop.

Business Continuity Is More Than Backups

Short-term thinking creates long-term risk.

Many firms believe they are prepared because their data is backed up. Backups matter, but they are only one part of the picture.

Business continuity answers:

  • How will you continue serving clients or patients while systems are unavailable?
  • How will staff communicate if email and internal chat are down?
  • How will you access critical information?
  • Who is authorized to make emergency decisions?
  • How will you handle court deadlines, patient care, payroll, or tax filings?

Disaster recovery focuses more specifically on restoring technology, applications, systems, and data after a disruptive event.

You need both.

A backup may restore a database. It does not automatically tell your receptionist how to check in patients, your attorneys how to identify urgent deadlines, or your accounting staff how to communicate securely with clients.

Think of it like medical care.

A backup is similar to having a medical record. Important, certainly. But if something goes wrong, you also need an emergency procedure, trained professionals, clear responsibilities, and a way to keep the patient stable while treatment takes place.

Your business needs the same level of preparation.

The “I Got a Guy” Problem

“I got a guy.”

He knows the server.
He set up the Wi-Fi.
He can usually fix things.
He says the backups are working.

This is the technology version of “Hey Margaret!”: a familiar person informally handling something that requires documented processes, accountability, and specialized expertise.

The problem is not necessarily that your IT person is unqualified. The problem is that one person, working reactively, cannot be your entire continuity strategy.

Temporary fixes fail because they usually lack:

  1. Documentation
    No one knows the full recovery process if the usual person is unavailable.

  2. Testing
    Backups may exist but have never been restored in a realistic scenario.

  3. Prioritization
    There is no agreement about which systems must be restored first.

  4. Communication planning
    Staff do not know how to work or communicate during an outage.

  5. Security controls
    Restoring systems without addressing the original compromise can invite the attacker back in.

A professional managed services provider approaches continuity differently. The objective is not merely to repair a system. It is to reduce downtime, protect data, and help your organization continue operating under pressure.

Why Regulated Firms Face Higher Stakes

For regulated and high-trust organizations, downtime can quickly become a security and compliance incident.

Law firms

Your firm may need access to:

  • Active matter files
  • Court calendars and filing deadlines
  • Client communications
  • Trust accounting systems
  • Billing and timekeeping platforms
  • Confidential discovery materials

A prolonged outage can affect client confidentiality, professional obligations, court deadlines, and the firm’s reputation.

The American Bar Association’s disaster planning resources emphasize the importance of preparedness, continuity planning, and practical recovery procedures for legal practices.

Medical practices

A medical practice cannot simply stop operating because its electronic health record or scheduling platform is unavailable.

Your plan should address:

  • Emergency access to patient information
  • Appointment and registration workflows
  • Medication and treatment documentation
  • Communication with patients and providers
  • Restoration of systems containing electronic protected health information

Under the HIPAA Security Rule, contingency planning includes a data backup plan, disaster recovery plan, and emergency mode operation plan. HHS also emphasizes criticality analysis and periodic testing in its ransomware guidance.

HIPAA compliance is not achieved by purchasing a backup product. You must be able to demonstrate that your safeguards and procedures support the confidentiality, integrity, and availability of ePHI.

Accounting and financial firms

Accounting firms, tax preparation businesses, financial advisors, and similar organizations may handle sensitive customer information subject to GLBA compliance and the FTC Safeguards Rule, depending on their activities and regulatory status.

The FTC requires covered financial institutions to maintain a written information security program. The program includes risk assessments, access controls, multifactor authentication, encryption, service provider oversight, testing, employee training, and a written incident response plan.

The FTC’s Safeguards Rule compliance guide specifically calls for a plan covering response and recovery goals, roles, communications, remediation, documentation, and post-incident review.

For certain notification events involving at least 500 consumers’ unencrypted information, the FTC requires notification as soon as possible and no later than 30 days after discovery.

That timeline is difficult to meet if your firm is still trying to determine who is responsible, what data exists, or whether your backups are usable.

What a Real Continuity Plan Includes

A useful plan is specific to your business. It is not a generic document copied from the internet and saved in a folder no one opens.

At a minimum, your plan should include:

1. A business impact analysis

Identify the systems, applications, and workflows your organization depends on.

For a law firm, that may be case management, document management, email, billing, and court filing tools.

For a medical practice, it may be the EHR, practice management platform, phones, scheduling, and payment systems.

For an accounting firm, it may be tax software, client portals, financial databases, email, and secure file transfer systems.

Then determine the business impact if each system is unavailable.

2. Recovery time and recovery point objectives

Your recovery time objective, or RTO, defines how quickly a system must be restored.

Your recovery point objective, or RPO, defines how much data loss is acceptable.

A system that can be offline for four hours has a different recovery requirement from one that cannot be unavailable during patient care or a court filing deadline.

These decisions should be based on business impact: not on what happens to be convenient for your current technology provider.

3. Layered backup and data protection

A strong backup strategy typically includes:

  • Multiple copies of critical data
  • Separate storage locations
  • Encryption
  • Access controls that prevent attackers from deleting backups
  • Offline or immutable backup protections
  • Regular restore testing
  • Documented retention and disposal procedures

Ransomware protection depends on more than detecting malicious files. If an attacker can encrypt your production data and delete your backups, recovery becomes far more difficult.

4. Endpoint security and identity controls

Every laptop, desktop, server, and mobile device is a potential entry point.

Your continuity plan should work alongside:

  • Multifactor authentication
  • Conditional access
  • Least-privilege permissions
  • Managed endpoint security
  • Patch management
  • Email security
  • Device encryption
  • Security monitoring
  • Segmented networks

A clean recovery without secure endpoints simply resets the clock until the next compromise.

5. An incident response playbook

During a ransomware event, people make poor decisions when they are improvising.

Your playbook should identify:

  1. Who receives the initial alert
  2. Who can isolate affected devices
  3. Who contacts legal counsel, cyber insurance, and law enforcement
  4. Who communicates with employees, clients, patients, or regulators
  5. How evidence and logs will be preserved
  6. How clean backups will be validated
  7. How systems will be restored and monitored
  8. How the event will be documented afterward

Do not assume everyone knows what to do. Write it down. Assign owners. Test it.

Law, medical, and accounting professionals participating in a business continuity tabletop exercise with an IT consultant

Should You Handle Continuity Internally? Pros and Cons

Internal ownership is possible. But it requires an honest assessment of your resources.

Potential advantages

  • Your employees understand your workflows
  • Internal staff may respond quickly
  • You retain direct control over decisions
  • Existing systems may reduce short-term costs

Potential disadvantages

  • Training and staffing costs can be significant
  • A small IT team may lack specialized security expertise
  • Employee turnover can remove critical institutional knowledge
  • Testing and documentation often get postponed
  • After-hours response may be limited
  • Compliance reporting and vendor coordination may overwhelm internal staff

The question is not whether internal staff are capable. The question is whether they have the time, tools, redundancy, and experience to manage a major disruption while the organization is under pressure.

For many firms with fewer than 150 employees, outsourced IT and managed services create practical economies of scale. You gain access to a broader team, standardized processes, security expertise, monitoring, and recovery capabilities without hiring every role internally.

How a Managed Services Provider Strengthens Recovery

A capable provider should help you move from reactive IT support to operational resilience.

That may include:

  • A documented IT assessment
  • Business impact and risk analysis
  • Backup and disaster recovery design
  • Microsoft 365 and cloud recovery planning
  • Intune device management
  • Endpoint security and ransomware protection
  • Identity governance and MFA enforcement
  • Incident response planning
  • Vendor and cyber insurance coordination
  • Tabletop exercises and restore testing
  • Ongoing IT consulting and strategic roadmapping

A provider should also help you understand the limits of your current environment.

Can your systems be restored within the time your business requires?
Are backups protected from administrative compromise?
Can staff work securely if the primary office is inaccessible?
Can you prove that your recovery procedures were tested?
Do your contracts with technology vendors support your compliance obligations?

If the answers are unclear, you do not yet have certainty. You have exposure.

IT cybersecurity specialist and accounting firm manager reviewing backup recovery status in a secure operations room

Start With These Five Questions

You do not need to solve everything in one meeting. Start with a structured review.

  1. What are the five systems we cannot operate without?
  2. How long can each system be unavailable before the financial or operational impact becomes unacceptable?
  3. When was the last successful backup restoration test?
  4. What is our first-hour response if ransomware is detected?
  5. Who is responsible for communications, legal review, technical recovery, and compliance decisions?

An experienced provider can turn those answers into an actionable plan through an IT assessment, prioritized remediation, and ongoing management.

Medical practice team and IT support professional using secure paper workflows during a planned systems downtime drill

Final Word

A business continuity plan is not a binder on a shelf.

It is a tested operating model for the day your normal systems stop working.

For law firms, medical practices, and accounting firms, the stakes are too high for informal arrangements, untested backups, or “I got a guy” support. Your clients, patients, employees, and regulators expect you to protect sensitive information and continue operating responsibly when something goes wrong.

The right next step is a documented IT assessment that evaluates your infrastructure, endpoint security, backup architecture, identity controls, compliance obligations, and recovery capabilities.

With the right managed services provider, your technology becomes more than a collection of tools. It becomes a reliable foundation for continuity, data protection, risk mitigation, and long-term growth.

Do not wait for the day the systems go down to discover what your business continuity plan was missing.