Digitplus
Guides

Designing IT Infrastructure for Continuity of Care in Clinics With Frequent Power Cuts

How to design clinic IT so care continues through power cuts: where the records live, which loads need UPS and for how long, signing in without the cloud, and the modes staff switch between.

Digitplus Editorial Team9 min read
Branded cover: the article title "Designing IT Infrastructure for Continuity of Care in Clinics With Frequent Power Cuts" set in white on a dark green gradient, labelled Guides, with the Digitplus Technology wordmark.

A power cut in a clinic is a clinical problem before it is an IT one.

A nurse at triage loses the screen with the allergy list. A doctor cannot open the notes from the last visit. A lab result sits in a system nobody can reach. The outage did not cause any of that. IT designed as if the outage would not happen did. Designing IT infrastructure for continuity of care means starting from the power cut and working back.

This piece covers that design: where the records live, what has to stay powered and for how long, and what staff do when the systems go partial. The basics of a clinic build are in our IT setup guide for hospitals and clinics. The support side, including downtime forms and who tests the backups, is in hospital IT support in Abuja.

Decide what has to keep working

Start with the clinical steps, not the equipment. During an outage, clinicians need to read the records that already exist. They need to record what happens during the outage, somewhere it will not be lost. And the desks that print patient cards, lab slips and prescriptions need to keep printing.

Each of those fails differently, so write them down separately and decide how each one is kept alive.

Uptime is the wrong target. A clinic that cannot control its own power supply will not reach five nines, and money spent chasing that figure is money wasted. The right target is a known fallback for each failure, practised by staff, with every record made during the outage back in the system afterwards.

Where the records live

This is the decision everything else follows from.

A cloud-only EMR works well while the clinic's power, its router and its internet link are all up. Lose any one of them and the screen is empty. The cloud did not fail. The path to it did.

An offline-first setup keeps a working copy of the records on a server inside the clinic. Workstations read and write to it over the local network. The internet link is only needed to sync with the central system. When the link drops, care carries on and changes queue. When it returns, they sync.

That design has a cost. A local server is one more machine to power, back up, secure and eventually replace. And two people editing the same record while disconnected creates a conflict. Ask the EMR vendor two questions before you choose:

  1. Does the system work with no internet connection at all, and which functions stop?
  2. When two offline edits clash, does it show the conflict to a person with an audit trail of who changed what, or does it quietly keep one version?

If the answer to the first is "it needs the internet", the clinic needs two internet links on different providers, and enough backup power to keep the router and the links running. That is a valid design. It is harder to make reliable than it looks.

Offline-first is not automatically the answer. A small single-site clinic with two good links and a well-protected router can run a hosted system safely. A clinic on one link in an area with long outages should not.

Where patient data sits under the NDPA

Health data is sensitive personal data under the Nigeria Data Protection Act 2023. A local server keeps records on site, but it also adds a place where records live, and each place has to be secured. Encrypt the server's disks, lock the room it sits in and log who signs in.

Records hosted outside Nigeria are a cross-border transfer, which the Act permits only on the conditions it sets out. Either way, section 40(2) requires a controller to notify the Nigeria Data Protection Commission within 72 hours of becoming aware of a breach likely to put patients at risk.

Sizing power by the gap it has to bridge

Split the load into tiers by what stops when it goes dark.

  1. The server and core network. The local EMR host, the router and the switches. These must not drop at all, because every desk depends on them.
  2. Point-of-care workstations, at triage, consulting rooms, pharmacy and the lab, with the printers those desks use.
  3. Administration, which can wait for the generator.

Then work out the runtime from the gap you actually have. Time your changeover. With an automatic transfer switch and a generator that starts first time, the gap is under a minute. With manual changeover, someone has to notice, walk to the generator and switch it. At night that can take ten minutes or more.

Size tier 1 to that real gap, plus a margin for the night the generator does not start, plus enough time to shut the server down cleanly if it never does. Tier 2 needs to cover the gap and save open work. Tier 3 may need nothing beyond surge protection.

Read the nameplate or measure the draw. Do not guess. Then add headroom, because a battery gives its best runtime on the day it is installed and less every year after. Several changeovers a day, in a warm room, age a battery faster than the datasheet assumes.

The server belongs on an online double-conversion UPS, which runs the load from its inverter all the time, so the changeover never reaches the server. Point-of-care desktops can sit on line-interactive units. The UPS types are compared in our guide to power protection and UPS planning.

Do not over-buy. A clinic with an automatic transfer switch does not need two hours of battery on every desk. That money does more as a second internet link or a spare workstation. Batteries are also a consumable, imported and priced in dollars at replacement time, so every kVA you buy now is a kVA you will replace later. Size for the load you have.

Signing in when the cloud is gone

One failure catches clinics that did everything else right. Staff sign in against a cloud directory. The link drops. The local EMR is running, and nobody can sign in to reach it.

Check two things. Workstations should allow cached sign-in for the people who normally use them. The local EMR should have its own accounts, or a local directory it can check without the internet.

Then test it. Unplug the internet link on a quiet afternoon and ask a nurse to log in and open a record. If they cannot, you found the problem on a good day.

A group with more than one site

A clinic group with sites in more than one city adds one rule. Each site must be able to treat patients with its link to head office down. No site should depend on another site's server, or on a single internet provider, to open a record.

Central backups still matter, because a local server can fail or be encrypted by ransomware. Keep encrypted copies off site, restore one on a schedule, and write down how long the restore took. That time is your real recovery time, whatever the plan says. Recovery planning across sites, with power as the main risk, is covered in building an IT disaster recovery plan when the primary risk is power.

The modes staff switch between

Write down the modes the clinic can run in, and what triggers each one.

  • Normal. Everything is up and syncing.
  • Local only. The internet link is down. The clinic runs on its local server and changes queue for sync.
  • Paper. The local system is down too. Staff use printed downtime forms laid out like the EMR screens, so the notes go back in quickly.

A named person on each shift declares a change of mode. When systems return, someone owns entering the paper notes and checking that none were missed. Practise the switch on a quiet day, at least twice a year, so the first time is not the real time.

The infrastructure work behind this, from the server room to the UPS at each desk, is part of our infrastructure solutions. How it fits a wider clinical setup is on our healthcare page.

Frequently asked questions

Is an offline-first EMR always better for a clinic with frequent power cuts?

No. It is better where the internet link is the weak point. A single-site clinic with two internet links on different providers, and a router on a UPS that outlasts the changeover, can run a hosted EMR safely. What matters is whether clinicians can open a record when the link is down, and the vendor should answer that in writing.

How much UPS runtime does a clinic need?

It depends on the changeover gap. Time how long the clinic goes from mains failing to the generator carrying the load, including at night. Size the server and network UPS to that gap plus a margin and a clean shutdown. Workstations need enough to cover the gap and save open work.

What should a clinic test before relying on its continuity design?

Three things, on a quiet day. Unplug the internet link and confirm staff can still sign in and open records. Switch off the mains and time the changeover with the server running on its UPS. Restore a backup to spare hardware and note how long it took. Write down each result and repeat after any significant change.

Next step

Start with two facts: how long your changeover takes, and what is plugged into each UPS. Send us that list and we will tell you where the gaps are. Contact us to arrange it.

Related to this: Healthcare.

Have a project that needs this thinking?

Tell us what you’re planning. We’ll come back with practical next steps and a clear, line-itemised proposal, no obligation.