On May 8, Ascension, a Catholic health system with around 140 hospitals in 19 states, detected unusual activity on its network and took systems offline. Within a day, its electronic health record, the systems used to order tests and medications, the phone systems in some markets and the patient portal were unavailable across the organization. Some emergency departments diverted ambulances. Clinicians went back to paper orders, paper medication administration records and phone calls to the lab. Ascension has since confirmed the event was a ransomware attack. As we write this, nine days later, most of those systems are still down, and Ascension has not said when they will return.
If your practice is independent, it is tempting to read this as a hospital problem. It is not. Independent practices in Ascension markets order imaging at Ascension facilities, receive results from Ascension labs, admit patients to Ascension hospitals and get discharge summaries from them. Every one of those hand-offs is broken right now. And the bigger lesson is uncomfortable: the Change Healthcare outage in February and this one in May were three months apart, and most practices still do not have a written plan for the day their own system goes dark.
Key takeaways
- A hospital system outage reaches a referring practice through orders, results, discharge notifications and facility-tied prior authorizations, and each needs a manual workaround today.
- Plan for four weeks without your primary systems, not four hours. Ransomware recoveries are measured in weeks and the backup may be encrypted too.
- A downtime plan has three sides: clinical (paper forms, printed schedules, medication lists), revenue (superbills, an encounter log, eligibility by phone) and recovery (who back-enters what, in what order).
- Back-entry is where the revenue leaks. Log every paper encounter with a number and reconcile the log to claims when the system returns.
- The security basics that stop most of these attacks are not exotic: a second factor on remote logins, filtered email, an offline tested backup and staff who know what a suspicious file looks like.
What is actually broken for a referring practice
Practices in affected markets are telling us the same things. Electronic orders sent to Ascension imaging and lab sites are not being received, so staff are faxing or hand-carrying paper orders. Results are arriving by fax or phone, days late, and are not landing in the patient chart automatically. Patients admitted through an Ascension emergency department are being discharged with paper instructions and no electronic notification to their primary care office, so transitional care management (99495, 99496) contact windows are being missed because nobody knows the patient was in the hospital. Prior authorizations that were approved for a procedure at an Ascension facility may need to be moved to a different site, which means a new authorization for many payers.
Ascension employed physician groups have a different set of problems: charge capture on paper, held claims, and the same unapplied-cash mess that Change created for everyone in March. Some of those groups are already asking payers about timely filing relief, and we would expect the answers to look like the ones given after Change: relief from most payers, on different terms, in writing if you ask.
What to do if you refer to Ascension
- Pull a list of every open order sent to an Ascension facility since May 8. Call the site to confirm receipt, or redirect the order to another facility and document why.
- Assign one person to log every faxed or phoned result, scan it into the chart the same day and route it to the ordering provider. Late results are a patient safety issue before they are a billing issue.
- Ask Ascension case management for a daily list of your patients admitted or discharged. Some markets are providing this by fax on request.
- For scheduled procedures with a prior authorization tied to an Ascension site, call the payer before moving the case. Some payers will transfer the authorization; others require a new one.
- Tell patients what to expect. A short script for the front desk ("the hospital's computer systems are down, results may take longer, we will call you") saves a hundred anxious phone calls.
The downtime plan your own practice needs
A downtime plan is a written document that says what the practice does when the EHR, the practice management system, the clearinghouse or the internet is unavailable for more than an hour. We have read many of these. Most were written for a power outage and assume the system will be back by lunch. Ransomware is different: expect weeks, not hours, and expect that the backup may also be encrypted. Expect, too, that your phones may go with the network, because most practices now run phones over the same connection.
Clinical side
Paper encounter forms for your top 20 visit types, with the fields your coders need (chief complaint, history, exam, assessment, plan, time). A printed daily schedule pulled every evening for the next two days. Printed medication lists and allergy lists for scheduled patients, or a read-only copy of the chart on a device that is not joined to your network. A paper prescription pad process, including the controlled substance rules in your state, and a plan for the patients whose electronic prescriptions cannot be sent.
Revenue side
Paper superbills with your fee schedule and the most common ICD-10-CM codes, stored where the front desk can find them. A log of every encounter with patient name, date, provider and superbill number, so nothing disappears when the system returns. A plan for eligibility: payer portals still work if the internet works, and a phone IVR works if it does not. A decision, made in advance, about copays: collect them on paper receipts, and reconcile them when the system is back. And a list of which payers accept claims through their own portals, so that if the clearinghouse is the thing that is down, the largest payers can still be billed.
Recovery side
Who enters the paper encounters when the system returns, in what order, and how you confirm every logged encounter became a claim. In the practices we have seen recover from an outage, this back-entry step is where revenue leaks. Two weeks of paper is 1,500 encounters for a mid-size practice, and the temptation to "catch up later" is strong.
A worked example: the back-entry reconciliation
Take a fictional five-provider family practice that loses its EHR and practice management system for 12 business days. It sees about 130 patients a day on paper, which is 1,560 encounters, each with a numbered superbill and a line in the encounter log. When the system returns, two medical assistants and one biller are assigned to back-entry in the evenings, oldest date of service first, so that the timely filing clock is respected. Each evening the billing lead compares the count of log lines for a date against the count of encounters entered and the count of claims generated for that date.
| Date of service | Log lines | Encounters entered | Claims created | Gap to work |
|---|---|---|---|---|
| Day 1 | 128 | 128 | 126 | 2 encounters missing a diagnosis |
| Day 2 | 134 | 131 | 131 | 3 superbills not found; pull the paper schedule |
| Day 3 | 127 | 127 | 119 | 8 held for eligibility never checked |
| Days 4 to 12 | 1,171 | in progress | in progress | Nightly count |
Without the log, the 3 missing superbills on day 2 and the 8 held encounters on day 3 are simply gone: nobody would know they existed. Across 12 days, a 2% loss on a $150 average charge is about $4,700 of visits that were performed, documented on paper and never billed. That is a small practice's entire month of profit on those days. The log costs a clipboard.
| Downtime item | Where it lives | Reviewed |
|---|---|---|
| Printed schedule, next 2 days | Front desk binder, printed nightly | Weekly |
| Paper encounter forms and superbills | Front desk and each exam pod | Quarterly |
| Payer phone numbers and portal logins (in a password manager, not a sticky note) | Billing office | Quarterly |
| Vendor contacts: EHR, PM, clearinghouse, IT, cyber insurer | Practice manager, printed copy off site | Quarterly |
| Offline backup tested by restoring a file | IT vendor report | Monthly |
| Encounter log and back-entry procedure | Billing office | Annually, and after every drill |
The security basics, again
Ascension has not yet said how the attackers got in, and we would not guess. What we can say is how most of these incidents start: a credential that was phished or bought, a remote access path without a second factor, or an employee who opened a file that looked routine. Multifactor authentication on every remote login, email filtering, a backup that is stored offline and tested, and staff who know not to open the invoice from the vendor they have never heard of. None of this is exotic. The practices that have it are the ones that treat an outage as a bad month rather than a catastrophe. A HIPAA security risk analysis, which you are already required to do, is the place to write down what you found and what you decided.
One more item that belongs in the plan: your cyber insurance policy, if you have one, almost certainly requires notice to the carrier within a set number of hours and may require you to use the carrier's forensic firm. Read that section now and put the phone number in the binder. Practices that call their own IT vendor first and the carrier three days later have, in some cases, complicated their claim.
Questions we hear
How long should we plan for?
Plan for four weeks without your primary systems. If the real outage is shorter, good. Change Healthcare took more than a month to restore its main clearinghouse functions, and Ascension is past a week with no announced date. A plan that assumes a weekend is not a plan.
Can we bill during a downtime?
Yes, if you have a second path. Some payers accept claims through their own portals. Some clearinghouses can be set up quickly as a backup if your enrollment paperwork is already on file. The practice that discovers this on the day of the outage is two weeks behind the one that set it up in advance.
Should we run a drill?
Yes, once a year, for half a day. Turn the screens off for a morning session, see patients on paper, and then back-enter the encounters that afternoon. The drill shows you which forms are missing and which staff have never seen a superbill. If you want a second pair of eyes on your billing continuity, book a call with our team, and our RCM training courses include a session on downtime charge capture.
What to do this week
- If you refer to Ascension, reconcile every open order and authorization tied to an Ascension site and assign one person to log incoming paper results.
- Print tomorrow's and the next day's schedules tonight, and keep doing it until you have a written plan that says otherwise.
- Build the paper packet: encounter forms for your top 20 visit types, superbills with your fee schedule, and a numbered encounter log.
- Write down which payers accept portal claims and whether your practice management vendor can route to a second clearinghouse.
- Ask your IT vendor for the date of the last successful restore test from an offline backup, and for confirmation that every remote login has a second factor.
- Find your cyber insurance notice requirements and put the carrier's number in the downtime binder.
