Downtime & Business Continuity Procedure

Template for hospital adaptation  •  Caresoft eICU  •  Version: 1.1  •  Effective: 01/04/2026

This is a template, not a finished procedure. Caresoft supplies it so that no site has to start from a blank page. The hospital must adapt every bracketed item, approve it through its own clinical governance process, and issue it as a hospital document. A completed, approved and issued downtime procedure is a condition of go-live under the Master Services Agreement §4.

Print it. A downtime procedure that only exists inside the system that is down is not a downtime procedure.

THE GOVERNING PRINCIPLE: bedside monitors, ventilators and their alarms are unaffected by any eICU platform outage.

Patient safety during downtime is maintained by bedside monitoring, bedside alarms and direct clinical assessment — exactly as it was before the Platform existed. Care must be able to continue safely and indefinitely without it.

Contents
  1. Purpose and scope
  2. Roles and contacts
  3. Classifying the outage
  4. Immediate actions — first 5 minutes
  5. Scenario playbooks
  6. Operating during downtime
  7. Command centre during downtime
  8. Documentation during downtime
  9. Communication
  10. Recovery and return to service
  11. Reviewing the outage period
  12. Planned maintenance
  13. Extended outage
  14. Downtime kit
  15. Rehearsal and training
  16. Downtime log

1. Purpose and scope

This procedure sets out what staff do when the Caresoft eICU platform, its data feeds, or the connectivity supporting them becomes unavailable, degraded or unreliable. It applies to all clinical, command centre, IT and biomedical staff in [units] at [hospital], at all hours.

It covers loss of the Platform. It does not replace the hospital's procedures for loss of bedside monitoring, loss of power, loss of the HIS, or major incident response, which remain in force alongside it.

2. Roles and contacts

Complete before issuing. Print and display in every clinical area and in the command centre.
RoleNameContactHours
Clinical Owner (accountable for clinical use)[ ][ ][ ]
Technical Owner (infrastructure, devices)[ ][ ][ ]
Charge nurse / shift in charge — [ICU name][ ][ ]24×7
Command centre lead[ ][ ][ ]
Hospital IT on-call[ ][ ]24×7
Biomedical engineering on-call[ ][ ][ ]
Duty intensivist[ ][ ]24×7
Caresoft support — S1 critical[24×7 phone]24×7
Caresoft — patient safety (S0)[24×7 phone] + [email protected] 24×7
Caresoft status page[status URL]

3. Classifying the outage

TypeWhat you seeData at risk?
A — Platform unreachableCannot sign in; portal not loading, all usersNo — edge agents keep buffering
B — Site network / internet downPlatform unreachable from the hospital; devices and edge agents runningNo, while buffer capacity lasts
C — Edge agent / gateway downOne or more beds show no sync; others normalYes — data from those beds is not being captured
D — Single device interface downOne bed or one parameter missingYes — for that device
E — ADT feed downNew admissions not appearing; rising quarantined countNo, but attribution is degraded
F — Degraded / unreliableSlow, partial, stale values, or values that look wrongTreat as most serious — see below
G — Command centre unavailableRemote oversight lost; bedside unaffectedNo

Type F is the most dangerous. A system that is clearly down is safe, because nobody trusts it. A system that is up but showing stale, partial or wrong data invites reliance.

If you suspect the Platform is displaying unreliable data, declare a downtime immediately and tell the unit to disregard the Platform. Do not wait for confirmation. It is always safer to run on the bedside unnecessarily than to trust a display that may be wrong.

4. Immediate actions — first 5 minutes

Any staff member noticing an outage

  1. Confirm bedside monitoring is intact at every affected bed — display live, alarms enabled and audible, limits set. This comes before anything else.
  2. Tell the charge nurse.
  3. Do not attempt to fix the Platform yourself.

Charge nurse / shift in charge

  1. Declare downtime verbally to the unit: "eICU is down — bedside monitoring and paper documentation from now."
  2. Confirm every bed has working bedside monitoring with alarms enabled. Escalate any bed that does not as a clinical emergency under the hospital's monitoring failure procedure.
  3. Confirm staffing. If remote oversight contributed to the staffing model, request additional bedside cover from [name/role] now.
  4. Open the downtime kit (Section 14). Start paper observation charts.
  5. Note the time downtime was declared. Start the downtime log (Section 16).
  6. Notify: hospital IT on-call, command centre lead, duty intensivist, Clinical Owner.

Hospital IT on-call

  1. Check the Caresoft status page and whether the outage is site-wide or Platform-wide.
  2. Check hospital network, internet link, edge agent status and power.
  3. Call Caresoft support on the S1 number. Phone, not email. State: hospital, unit, beds affected, when it started, what was tried.
  4. If the Platform showed wrong or misattributed patient data, state that it is an S0 patient safety issue — this triggers a 15-minute response and evidence preservation.
  5. Give the charge nurse an estimated restoration time as soon as you have one, and update every [30] minutes.

5. Scenario playbooks

TypeClinical actionTechnical actionEscalate at
A Platform unreachableBedside monitoring + paper. Command centre stands down remote oversight and informs unitsStatus page; call Caresoft S1Immediately
B Network downAs A. Note buffer will hold data for approximately [x] hoursRestore link; confirm edge agents still running and bufferingImmediately; urgent if buffer limit is approaching
C Edge agent downAffected beds on bedside + paper. Other beds continue normallyCheck agent power, network, process; restart per runbook; call Caresoft if not resolved in [15] min[15] minutes
D Device interface downThat bed on bedside + paperCheck cable, port, device output setting; biomedical to attend; check whether firmware or the device was recently changed[30] minutes
E ADT feed downUse manual admission entry so new patients are still tracked. Verify patient identity on every screen before interpreting dataCheck HIS view/API; call Caresoft[1] hour
F Degraded / unreliableDeclare downtime at once. Instruct unit to disregard the Platform entirely until clearedCall Caresoft immediately; classify as S0 if any patient data may have been wrongImmediately
G Command centre unavailableUnits continue on bedside. Restore the pre-eICU escalation path to the duty intensivistRestore command centre access or relocate to [alternate location]Immediately

6. Operating during downtime

7. Command centre during downtime

Absence of alerts is not absence of events. Loss of data flow is itself an escalation trigger.

8. Documentation during downtime

9. Communication

WhenWho tells whomHow
On declarationCharge nurse → unit staffVerbal, whole unit
Within 5 minCharge nurse → IT on-call, command centre, duty intensivist, Clinical OwnerPhone
Within 10 minIT → Caresoft supportPhone, then ticket
Every [30] minIT → charge nurse, Clinical OwnerPhone / [channel]
At shift changeOutgoing → incoming charge nurseHandover, documented
On restorationIT → all abovePhone / [channel]
Within 24 hClinical Owner → clinical governanceWritten summary

Do not communicate patient identifiers over personal messaging during downtime. Use hospital-approved channels or the phone.

10. Recovery and return to service

Before standing down downtime, confirm all of the following:

Announce return to service to the whole unit and to the command centre. Record the time in the downtime log.

11. Reviewing the outage period

Buffered data arrives with its original timestamps and fills in the trend retrospectively. It may show deterioration that nobody saw live.

12. Planned maintenance

13. Extended outage

If downtime exceeds [4] hours, or is expected to:

14. Downtime kit

Kept in [location] in every clinical area and in the command centre. Checked [monthly] by [role]. Contents sealed and dated.

15. Rehearsal and training

16. Downtime log

Complete one per event. File with the unit's clinical governance records and send a copy to the Clinical Owner within [24] hours.
FieldEntry
Unit / beds affected 
Outage type (A–G) 
First noticed — date, time, by whom 
Downtime declared — time, by whom 
Bedside monitoring confirmed intact — time, by whom 
Caresoft notified — time, ticket ref, severity 
Additional staffing arranged? Details 
Service restored — time 
Return-to-service checks completed — time, by whom 
Total duration 
Data permanently lost? Which beds, which period 
Backfilled data reviewed — by whom, findings 
Paper records transcribed — by whom, when 
Any patient affected? Incident report raised? 
Problems with this procedure / kit 
Completed by — name, role, signature, date 
Home Book a Demo