Back to Columns
Healthcare Security14 min read

A BCP for Cyberattacks: How It Differs from Disaster Planning, and Prioritising Clinical Continuity

September 14, 2026

A BCP for Cyberattacks: How It Differs from Disaster Planning, and Prioritising Clinical Continuity
Share this article

Most hospitals already hold a disaster BCP: assembly criteria, stockpiles, emergency power, written around earthquakes, flooding, and outages. Apply that plan to a cyberattack, though, and several of its premises fail.

The biggest difference is that the time to recovery cannot be estimated. After an earthquake, surveying the damage gives you a rough horizon. After a cyberattack, you must identify the intrusion path, find an uncompromised backup, and restore in stages while verifying safety — and on day one you cannot say how long that takes. Meanwhile, care continues on paper.

The second difference is that help does not shorten it much. In a disaster, people and supplies accelerate recovery. With a cyberattack, bringing in specialists does not change the fact that investigation and verification set the pace.

Japan's FY2026 fee revision made developing and drilling a cyberattack BCP a tier-1 requirement of the new coordinated electronic clinical information add-on. The cyber BCP is now a document the system expects you to hold.

Disclaimer: This article is general information. Reimbursement requirements and guideline obligations are governed by MHLW notices and Q&A and by the Guidelines for the Safe Management of Medical Information Systems.

How It Differs from Disaster Planning

Building on the existing BCP is sensible, but unless the differences are stated explicitly the result is unusable.

AspectDisaster BCPCyber BCP
Assessing damageVisible; an early horizonScope takes time to establish; no horizon on day one
Recovery timeBroadly estimableUnknown — days to months
Buildings and staffAffectedIntact. You have people; you just have no systems
Outside helpPeople and supplies move it forwardInvestigation is the bottleneck; more hands help little
BackupsSafe if held remotelyEncrypted with everything else if on the same network
CommunicationTelecoms damageInternal systems unusable; the call tree may be lost too
Deciding to resumeRestore once safety is confirmedNothing restores until the cause is closed
Legal workstreamLimitedBreach reporting, disclosure, and police liaison run in parallel

"People but no systems" is the condition disaster plans do not model. Staff arrive, the building and power are fine, and the EHR will not open. How to run care in that state is the heart of a cyber BCP.

See Reporting a Personal Data Breach and First Response to Ransomware.

Prioritising Clinical Functions

The body of the BCP is the ordered list of what cannot stop. Because a cyberattack halts everything at once, without a pre-agreed order departmental demands collide.

FunctionPatient impact if stoppedFallbackPriority reasoning
Emergency intakeLife-criticalDiversion to neighbours (loads the whole region)Highest. Pre-agree intake criteria
Surgery and obstetricsLife-criticalElective can defer; emergency cannotSecure a means to continue emergencies
DialysisLife-critical within daysReferral, paper ordersAssume continuation; design paper flow
Inpatient careMedium–highPaper order books and prescriptionsStockpiled forms essential
Booked outpatientsMediumReduce, deferDecide to scale down early
Labs and imagingMediumExternal referral, handwritten requestsAlternative request and result paths
PharmacyHighPaper prescriptionsDesign the checking process too
Billing and claimsLow at firstSettle laterBites later — delayed claims hit cash flow

Billing looks unimportant on day one and becomes critical at week three. Include how claims are handled during an extended outage.

Setting RTO and RPO in Numbers

MetricMeaningThe question in a hospital
RTO (recovery time objective)How quickly operations resume"How many days without the EHR can we tolerate?"
RPO (recovery point objective)How much data loss is acceptable"How many hours of records can we lose and still treat safely?"

RPO is fixed by backup frequency: daily backups mean accepting the loss of a day of clinical records in the worst case. If that is unacceptable, shorten the interval or decide in advance how paper records will fill the gap. RTO turns on whether recovery procedures are documented and tested — a procedure that lives in one person's head collapses the moment they are away.

The FY2026 tier-1 backup requirement reads naturally in this light.

Tier-1 backup requirementMethods stated to satisfy it
Backups by multiple methods, with some held offline① Removable media (e.g. RDX), with generation management<br>② Automated transfer to NAS or similar, kept disconnected from the network at all times<br>③ Within a cloud service, to a logically separated area, where prompt recovery is possible

For daily backups, retaining at least three generations is indicated; weekly and monthly retention is not stated uniformly because it depends on hospital size and method. See Backup Design: the 3-2-1 Rule.

Designing the Paper Fallback

Paper is where unpreparedness shows. "We'll use paper if it comes to that" usually means no forms exist, nobody knows how to complete them, and there is no plan for getting the records back into the system.

  • Pre-printed forms — prescriptions, orders, test requests, nursing records, consent, admission and discharge. Physical stock, not PDFs: with no network you cannot print
  • Reference information — inpatient lists, allergies and contraindications, the day's surgical and test schedule. Decide what is exported regularly and held offline
  • Completion rules — how patients are identified when IDs cannot be looked up, who recorded what, and times
  • Physical handling — paper moves around the hospital. Handover records and departmental files prevent loss and mix-ups
  • Getting back to electronic — who re-enters what, when, and in what order; whether scanning suffices or keying is required

Aim to be able to answer "how many days can we run on paper?" with a number. Stock levels, storage space, and the staff hours needed afterwards give you the ceiling.

Holding reference data offline creates its own leak risk — decide storage and disposal. See Endpoint Management and Managing Removable Media.

Drill, Then Revise the Plan

The tier-1 requirement covers drills, not just the document. Beyond compliance, an undrilled plan does not work.

StageFormatDurationWhat it tests
1Read-through~1 hourAre roles and contacts current? Is the vocabulary shared?
2Tabletop scenarioHalf a dayDecision order, authority, information flow
3Partial live degraded operationHalf to full dayCan people actually complete the paper forms, and how long does it take?
4Restoration testScheduledCan you actually restore from backup, and how long does it take?

Do not skip stage 4. Taking backups and being able to restore from them are different claims. Restoration is often automated in the taking and never once tested in the restoring. The measured result becomes the evidence for your RTO.

See Designing Staff Training and Drills, Incident Response Planning, and Key Points of the FY2026 Fee Revision.

Conclusion

  1. The decisive differences are the unknowable recovery horizon and the "people but no systems" state
  2. Rank clinical functions; billing is low priority on day one and critical in a long outage
  3. Set RTO and RPO numerically. RPO follows backup frequency; RTO follows documented, tested procedures
  4. Tier 1 requires backups by multiple methods with some offline — removable media, disconnected automated transfer, or a logically separated cloud area
  5. Design the paper fallback down to physical stock and the route back to electronic
  6. Escalate drills in stages and always include a restoration test

A cyber BCP is your existing disaster plan plus the premises that are specific to attacks. Prioritisation and restoration testing are hard to finish without system-side understanding. Pottech advises from that standpoint — contact us. For assessing a supplier's continuity posture, see What Is an ISMS (ISO/IEC 27001)?.

References and Sources

Note: reimbursement requirements are given concrete form by notices and Q&A and are subject to change. Confirm the current text with MHLW publications.

Share this article

Related Articles

Healthcare Security

Access Control and Privileged ID Management: What Is Realistic in a Hospital

Role-based permissions, least privilege, offboarding and transfer reviews, vendor maintenance accounts, and what to do where shared IDs genuinely cannot be eliminated. Access design that actually limits blast radius within the constraints of clinical work.

September 14, 2026
Healthcare Security

Antivirus and EDR: What a Hospital Should Decide Before Buying

How EDR differs from conventional antivirus, why it is not a product that protects you simply by being installed, how to choose an operating model for the alerts it produces, what to do about devices it cannot be installed on, and what to settle before you buy.

September 14, 2026
Healthcare Security

Logging and Audit Trails: Getting Past 'We Collect It but Nobody Looks'

What to log, how long to retain it, and the real problem — logs collected but never read. Which logs actually matter during an incident, and how to make review a sustainable routine in a hospital with limited staff.

September 14, 2026
Healthcare Security

Backup Design for Hospitals: The 3-2-1 Rule and the Tier 1 Requirement

Japan's FY2026 revision makes multi-method backup with part of it held offline a tier 1 requirement. We cover the three methods accepted as meeting it — external media, automated transfer to a permanently detached NAS, and a logically separated area within a cloud service — plus generation management and why an untested backup does not count.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.