The EHR migration: export, parallel-run, cut over
Summary
Switching EHRs is a project with a fixed order: pull your data out on your terms before you cancel, verify the export is complete and still shows who signed each note, run both systems in parallel for a short window, then cut over on a planned day. Sign a BAA with the new vendor, redo your security risk analysis, and keep patient access working throughout. Plan around the contract, not the sales demo.
By Gale Editorial · Updated 2026-07-27. Every figure cited to a dated source. How we write.
What a complete export actually contains
A complete export is not one file; it is three kinds of data, and capturing only one will haunt you. You want the structured clinical record as a C-CDA, the tabular data such as demographics and ledgers as CSV, and the human-readable chart as PDF. A PDF-only export is a filing cabinet, not a live record: it preserves what a note said but drops the problem list, medication list, and allergy data your new system needs.
The structured layer is the C-CDA (Consolidated Clinical Document Architecture), the standard format your new EHR can ingest as discrete fields rather than flat text. Ask for C-CDA, CSV, and PDF together, so the structured, tabular, and human-readable needs are all covered. Then test the import on a handful of charts before you trust the whole batch, checking that the discrete fields actually landed in the right places and did not collapse into a note body.
One detail solos miss until an audit: the export must preserve who authored and signed each note, and when. Medicare requires that services be authenticated by a handwritten or electronic signature, and a reviewer can treat an unauthenticated entry as unsupported 2Ref 2Centers for Medicare & Medicaid Services (2023).Complying with Medicare Signature Requirements.That migrated records must preserve the authenticated signature and authorship Medicare requires, so an export that strips them reads as unsupported.. If your migration flattens signed, dated notes into anonymous PDFs, you have kept the words and lost the authentication. Confirm the exported record still shows the original author, credential, and signature date, and that a note signed in the old system does not reappear as an unsigned draft in the new one.
Run both systems in parallel before you trust the new one
A parallel-run is the safety margin between exporting your data and depending on it: for a short window you keep the old system live and read-only while you book new work in the new one. A common convention among solo practices is to overlap for a few weeks — long enough to confirm the import held, reconcile active patients by hand, and catch the fields that did not map — before you rely on the new record for care.
Reconcile the data that carries clinical risk first. For every active patient, check that the problem list, medication list, and allergy data survived the move and match the old chart. Those three fields are where a mapping error becomes a safety event, so verify them by hand rather than trusting a row count. Leave the old system read-only during the overlap and resist the urge to double-enter — one system is the live record, the other is reference only.
Watch the seams the import tends to mangle: free-text allergies that did not map to coded entries, discontinued medications that came across as active, and appointment history that shifted by a time zone. Keep a running list of what you find and fix it before go-live, not after. The overlap exists precisely so these surface while you still have the original to check against.
- Book new visits in the new system from day one of the overlap.
- Keep the old system read-only so nothing new is written there.
- Reconcile active charts by hand, not by trusting the import summary.
The cutover: a planned sequence, not a leap
Cut over on a date you choose, at the quietest point in your week, and treat it as planned downtime rather than an event that happens to you. The sequence matters: freeze new entries in the old system, run the final export, import and verify it, then flip scheduling and billing to the new system. A written cutover checklist turns a frightening switch into a series of small, reversible steps you can pause if a check fails.
| Phase | What you do | Why it matters |
|---|---|---|
| Freeze | Stop new entries in the old system; finish and sign open notes | A moving target cannot be exported cleanly |
| Export | Run the final C-CDA, CSV, and PDF export | This stays your system of record until the import is verified |
| Import and verify | Load into the new system; spot-check charts, problem lists, and ledgers | Catch mapping errors while you can still re-run |
| Flip | Point scheduling, billing, and the patient portal at the new system | The new system goes live only after verification |
| Keep read-only | Retain access to the old system for the contracted window | Your safety net if a gap surfaces later |
Plan the human side of the downtime too. Tell patients scheduled that week that a brief slowdown is possible, give your front desk a paper fallback for check-in and payment, and pick a go-live moment you can supervise end to end. The technical cutover is minutes; the verification around it is the part that protects the record. Build in a rollback rule as well — a plain statement of what would make you stop and stay on the old system another day — so a failed check triggers a decision you already made rather than a panic at the keyboard.
The new EHR is a business associate — the paperwork you owe
Before go-live, sign a business associate agreement with the new vendor and redo your security risk analysis — a migration is exactly the change that triggers both. Any vendor that creates, receives, maintains, or transmits protected health information on your behalf is a business associate, and the law requires a signed BAA describing how they safeguard the data before it ever touches their servers 3Ref 3HHS Office for Civil Rights (2026).Business Associates.That the new EHR vendor and any migration helper are business associates requiring a signed BAA before PHI moves..
The Security Rule scales its administrative, physical, and technical safeguards to the size of your practice, but it anchors all of them in a risk analysis you keep current 4Ref 4HHS Office for Civil Rights (2026).Summary of the HIPAA Security Rule.That the Security Rule requires safeguards anchored in a current risk analysis, which a system migration changes.. Moving your whole record to a new platform changes that picture — new access controls, new backups, new people with logins — so the analysis you ran on the old system no longer describes your risk. ONC and OCR publish a free Security Risk Assessment Tool sized for small practices, which walks a solo through the same analysis a consultant would run 5Ref 5Office of the National Coordinator / ASTP (2026).Security Risk Assessment Tool.That ONC/OCR's free Security Risk Assessment Tool lets a solo practice run the required risk analysis on the new system.. Do it after the migration, not before, because your risk is defined by the system you actually use.
- Sign the BAA before any data moves, including with any migration consultant.
- Re-run the risk analysis on the new system, and keep the dated file.
- Fix what the analysis surfaces — access controls, encryption, backup — as your first tasks in the new EHR.
The breach you can cause by migrating
Export files are protected health information in motion, and the migration is the moment that data is most exposed: sitting on a laptop, in an email, or in a shared folder. Encrypt every export, move it over channels your BAA covers, and delete the working copies once the import is verified. If a migration file is lost or exposed, the Breach Notification Rule sets the clock: individual notice without unreasonable delay, and no later than 60 days 6Ref 6HHS Office for Civil Rights (2026).Breach Notification Rule.The Breach Notification Rule timeline for a lost or exposed migration file — individual notice within 60 days and the HHS/media thresholds..
The same rule scales the rest of the notice by size: breaches affecting fewer than 500 people are reported to HHS annually, while a breach affecting 500 or more triggers notice to HHS and to prominent media in the affected state 6Ref 6HHS Office for Civil Rights (2026).Breach Notification Rule.The Breach Notification Rule timeline for a lost or exposed migration file — individual notice within 60 days and the HHS/media thresholds.. None of that is a reason to fear switching — it is a reason to handle the export like the concentrated copy of everyone's record that it is. The most common way a careful clinician still trips here is convenience: emailing the export to a personal address to work on it at home, or dropping it in a consumer cloud folder that sits outside every agreement you signed.
- Encrypt the export at rest and in transit — never an unencrypted email attachment.
- Keep the working copies off personal devices and out of consumer cloud folders.
- Delete the staging copies once the import is verified, and note that you did.
Don't break patient access while you switch
You remain an actor under the information blocking rule during the switch, so a migration cannot become an excuse to stall a patient's access to their records. The 21st Century Cures Act prohibits practices that interfere with the access, exchange, or use of electronic health information, subject to eight defined exceptions 7Ref 7Office of the National Coordinator / ASTP (2026).Information Blocking.That the information blocking rule keeps patient access obligations in force during a migration, with its eight exceptions.. If a records request lands mid-migration, it runs on its own legal clock regardless of the switch. Keep the portal reachable and the request path open throughout.
Records retention runs on its own timeline as well. Your state's records-retention rule — often measured in years after the last date of service — governs how long the old data must stay retrievable, which is one more reason the read-only window you negotiated in the contract matters. Migrating does not reset that clock; it just changes which system holds the copy. Confirm, before you let the old contract lapse, that you can still reach every record you are legally required to keep, and that a request for an older chart does not fall into a gap between the two systems.
Negotiate your next exit before you sign the next contract
The best time to make your next migration painless is the day you sign the new contract, while you still have leverage. Read the same data-access and termination clauses you just fought through, and negotiate for a standard-format export at no extra charge, a defined post-termination read-only window, and clear language that the data is yours. A vendor that resists putting portability in writing is telling you how the next exit will go 1Ref 1Office of the National Coordinator (2016).EHR Contracts Untangled: Selecting Wisely, Negotiating Terms, and Understanding the Fine Print.Reading the EHR contract's data-access and termination clauses before switching — export rights, export fees, and post-termination read access..
This is where portability stops being a one-time scramble and becomes a standing practice. Before you sign, get three things in writing: the export format the vendor will provide on request, the fee — ideally none — for a full export, and how many days of read-only access you keep after the relationship ends. Ask what happens to your data if the vendor is acquired or shuts down, and whether the record can be shared through standard formats rather than a full export each time. None of this is exotic; it is the same fine print ONC's contracting guidance urges every small practice to read before signing 1Ref 1Office of the National Coordinator (2016).EHR Contracts Untangled: Selecting Wisely, Negotiating Terms, and Understanding the Fine Print.Reading the EHR contract's data-access and termination clauses before switching — export rights, export fees, and post-termination read access.. The solo who negotiates the exit up front never has to choose between a bad EHR and a brutal migration again, because the door is already unlocked.
Common questions
Run your practice on Gale
The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.
Start or manage a practice →References
- 1.Office of the National Coordinator (2016). EHR Contracts Untangled: Selecting Wisely, Negotiating Terms, and Understanding the Fine Print. HealthIT.gov (ONC). link ✓Reading the EHR contract's data-access and termination clauses before switching — export rights, export fees, and post-termination read access.
- 2.Centers for Medicare & Medicaid Services (2023). Complying with Medicare Signature Requirements. CMS Medicare Learning Network (MLN905364). link ✓That migrated records must preserve the authenticated signature and authorship Medicare requires, so an export that strips them reads as unsupported.
- 3.HHS Office for Civil Rights (2026). Business Associates. U.S. Department of Health and Human Services. linkThat the new EHR vendor and any migration helper are business associates requiring a signed BAA before PHI moves.
- 4.HHS Office for Civil Rights (2026). Summary of the HIPAA Security Rule. U.S. Department of Health and Human Services. linkThat the Security Rule requires safeguards anchored in a current risk analysis, which a system migration changes.
- 5.Office of the National Coordinator / ASTP (2026). Security Risk Assessment Tool. HealthIT.gov. link ✓That ONC/OCR's free Security Risk Assessment Tool lets a solo practice run the required risk analysis on the new system.
- 6.HHS Office for Civil Rights (2026). Breach Notification Rule. U.S. Department of Health and Human Services. linkThe Breach Notification Rule timeline for a lost or exposed migration file — individual notice within 60 days and the HHS/media thresholds.
- 7.Office of the National Coordinator / ASTP (2026). Information Blocking. HealthIT.gov. link ✓That the information blocking rule keeps patient access obligations in force during a migration, with its eight exceptions.
https://www.gale.care/for-providers/cde-ehr-migration-solo · 7 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.