Guide

After the disaster: records, payers, patients, and the temporary site

Summary

Work the reopening in order: confirm physical safety and document the damage, then determine whether lost or exposed records are a HIPAA breach, restore records from your backup, notify payers of your interruption and any temporary address, reach patients through your pre-agreed channel, and stand up a temporary site — often telehealth — so care continues while you rebuild. A written continuity plan turns weeks of chaos into a checklist.

By Gale Editorial · Updated 2026-07-27. Every figure cited to a dated source. How we write.

The reopening sequence, in order

Move through five stages in order, because doing them out of sequence creates the breach you then have to report. First, secure the site and your own safety; a fire or flood scene is a physical hazard before it is a practice problem. Second, assess your records. Third, notify payers and patients. Fourth, stand up a temporary way to see people. Fifth, rebuild toward a plan you will never again be without.

  • Secure and document. Photograph the damage before you move anything; your carrier and your landlord will both want it.
  • Assess records before you reconnect anything to the internet.
  • Notify payers and patients so claims and appointments do not silently lapse.
  • Stand up a temporary site, usually telehealth, to keep the panel in care.
  • Rebuild toward a plan. Ready.gov's business-continuity framework — a risk assessment, a written continuity plan, and an emergency-communications tree — is sized down cleanly for a practice of one 1.

Is your lost or exposed data a HIPAA breach?

A fire or flood that destroys the only copy of your records, or exposes them to salvage crews and strangers, can be a HIPAA breach even though no one hacked you. The Breach Notification Rule turns on unauthorized access to, or loss of, unsecured protected health information, not on bad intent. Run the four-factor risk assessment, document it, and let that document — not your gut — decide whether notice is owed.

If a cyber element rode in on the chaos — ransomware that landed while your defenses were down — HHS presumes the encryption of ePHI is a reportable breach unless a documented risk assessment shows a low probability of compromise 2. Treat that as its own track; the day-one response to ransomware moves faster than the physical cleanup.

When notice is owed, the clock is fixed: individuals without unreasonable delay and no later than 60 days, HHS on the annual log when fewer than 500 people are affected (or promptly at 500 or more), and the media only when a single breach reaches 500 residents of one state or jurisdiction 3. Encryption is the safe harbor — data that was properly encrypted and stayed encrypted is not 'unsecured,' so its loss may not trigger notice at all.

Reconstructing records and answering access requests

Rebuild from your most recent backup first, then reconcile the gap between the backup date and the disaster. Patients do not lose their rights because your office flooded. Under HIPAA's right of access, you still owe an individual a copy within 30 days — one 30-day extension is allowed if you notify them — for a reasonable, cost-based fee, in the form they ask for where you can produce it 4. Psychotherapy notes are the one carve-out from that access right.

For what the backup cannot restore, reconstruct from claims history, pharmacy records, and referring-provider correspondence, and mark reconstructed entries as such with the date you rebuilt them — never backdate. On retention, the APA's guideline example is seven years after the last service for an adult and longer for a minor, but that is a floor to compare against your state's rule, which controls 5. If your records lived only inside a cloud EHR and that vendor also failed, the sunset notice is its own emergency — the migration cannot wait for the building.

Notifying payers and keeping claims moving

Tell every payer you contract with, in writing, that you have had a service interruption, and give them any temporary address and the date you expect to resume. Medicare enrollment records must reflect your current practice location, so a change of address flows through your MAC and PECOS; commercial payers each have their own notice window in your contract. Do this early — a stale address quietly bounces electronic remittances and the payments you are owed.

  • Address and location. Update PECOS and each commercial payer so remittance advice and payments route to a working address.
  • Interruption notice. If the disaster will push claims past a timely-filing window, flag it to the payer in writing at once and keep the proof; many payers have a disaster or catastrophic-event exception, but only if you ask.
  • Continuity of care. Reach patients with authorizations or care plans in flight so nothing lapses mid-treatment.

Standing up a temporary site: telehealth first

Telehealth is usually the fastest way to keep your panel in care while the office is uninhabitable — no lease, no build-out, just a private space and a compliant platform. Before you bill it, confirm each service is payable that way: CMS publishes the definitive annual list of codes payable as Medicare telehealth, flagging which are permanent, which are temporary, and which allow audio-only 6. Commercial and Medicaid telehealth rules differ, so verify each payer's policy the same week you reopen.

A rented room, a colleague's spare office, or a co-working suite can bridge in-person needs. Wherever you land, redo the basics: a business-associate agreement with any new vendor that touches PHI, a locked space for paper, and a fresh security check on the temporary network. This is also the moment the solo emergency plan you drafted for illness earns its keep — the same coverage arrangements cover a disaster.

If the disaster pushed you across a state line

If you evacuated to another state and want to keep treating your existing patients, licensure follows the patient's location, not yours. You generally need authority in the state where the patient is physically sitting during the session, even by video. Interstate compacts can shorten that path: PSYPACT authorizes qualifying psychologists to practice telepsychology across member states and to provide temporary in-person services there 7. Check whether both your home state and your temporary state are members before you see anyone.

Non-psychologist disciplines have their own compacts and their own member lists, and not every state participates, so confirm the current roster rather than assuming. Where no compact reaches, some boards issue temporary or emergency practice permissions after a declared disaster — contact your board's licensing division and ask what a declared emergency unlocks. Document whatever authority you rely on in the chart.

Building the plan you wish you'd had

The difference between a two-week reopening and a two-month one is the contingency plan you made before the water rose. Ready.gov's business framework scales to a solo practice: a short risk assessment, a one-page continuity plan naming your backup location and who you call first, and an emergency-communications tree for patients and payers 1. Store a copy off-site and in the cloud so the plan itself survives the event it plans for.

Revisit it annually and after any near-miss. The plan is not paperwork for its own sake — it is the checklist that lets you spend disaster week on your patients instead of reconstructing your own operations from memory. Pair it with off-site, encrypted backups tested on a schedule, and you convert a catastrophe into an interruption.

Common questions

Not automatically, but often. Loss of, or unauthorized access to, unsecured protected health information can be a breach regardless of intent. Run and document the four-factor risk assessment; if it shows a low probability that the information was compromised, notice may not be owed. If the data was properly encrypted and stayed encrypted, it is not 'unsecured,' and the loss may fall outside the rule entirely.

Yes, if you are actually delivering care and documenting it. Telehealth lets you keep seeing patients from a temporary space; confirm each code is payable that way under Medicare's telehealth list and each commercial payer's policy. Update your practice address with every payer so payments route correctly, and flag any claims threatened by timely-filing deadlines to the payer in writing right away.

Yes. A disaster does not suspend a patient's right of access. You generally owe a copy within 30 days, with one 30-day extension if you notify the patient, for a reasonable cost-based fee. If records were destroyed, say so honestly, provide what you can reconstruct from backups and claims history, and document the reconstruction rather than backdating anything.

Licensure follows where the patient sits, not where you fled to. You need authority in the patient's state, even for video. Interstate compacts like PSYPACT can extend a qualifying psychologist's reach to member states, and some boards grant temporary permissions after a declared disaster. Confirm the current compact roster and contact your board before seeing anyone across a state line.

An off-site, encrypted backup tested on a schedule, plus a one-page continuity plan naming your backup location, your first calls, and how you reach patients. Ready.gov's business framework sizes this for a practice of one. The plan is what turns a catastrophe into a two-week interruption instead of a months-long rebuild from memory.

Run your practice on Gale

The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.

Start or manage a practice →

References

  1. 1.U.S. Department of Homeland Security (2026). Ready.gov Business. Ready.gov (DHS/FEMA). linkThe business-continuity framework — risk assessment, written continuity plan, emergency-communications tree — sized down for a practice of one to structure the reopening.
  2. 2.HHS Office for Civil Rights (2016). FACT SHEET: Ransomware and HIPAA. U.S. Department of Health and Human Services. linkThat ransomware encryption of ePHI is presumed a reportable breach unless a documented risk assessment shows a low probability of compromise.
  3. 3.HHS Office for Civil Rights (2026). Breach Notification Rule. U.S. Department of Health and Human Services. linkThe breach-notice timeline: individuals no later than 60 days, HHS annually if under 500 affected, media over 500.
  4. 4.HHS Office for Civil Rights (2026). Individuals' Right under HIPAA to Access their Health Information. U.S. Department of Health and Human Services. linkThat patients keep the right to obtain records within 30 days (one 30-day extension) for a cost-based fee, with psychotherapy notes excluded.
  5. 5.American Psychological Association (2007). Record Keeping Guidelines. American Psychological Association. linkThe retention guideline example (seven years after last service for adults, longer for minors) as a floor to compare against the controlling state rule.
  6. 6.Centers for Medicare & Medicaid Services (2026). List of Telehealth Services. Centers for Medicare & Medicaid Services (CMS). linkThat CMS publishes the annual list of codes payable as Medicare telehealth, including permanent vs temporary status and audio-only eligibility, for standing up a temporary site.
  7. 7.PSYPACT Commission (2026). PSYPACT. PSYPACT Commission. linkThat PSYPACT authorizes qualifying psychologists to practice telepsychology and provide temporary in-person services across member states when displaced across a state line.

https://www.gale.care/for-providers/ecc-disaster-reopening · 7 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.

Findability, by specialty

How practices like yours get found in local search and AI answers — the honest playbook, per specialty.

SEO for private practices · SEO for AI search / answer engines (all verticals)