An eMAR downtime procedure must keep medication work safe when staff cannot reliably view current orders or record administrations in the normal system. It also must bring every downtime event back into the electronic record without duplicate doses, missing entries, backdating, or loss of the original paper or offline evidence.
This guide addresses operational and software design, not clinical decisions. It was reviewed on August 8, 2026. Adult Family Home providers should verify current Washington requirements and align the procedure with resident orders, assessment and care plans, delegation, emergency planning, privacy obligations, vendor capabilities, and qualified professional guidance.
Define what counts as eMAR downtime
Downtime is more than a total vendor outage. Start the procedure when staff cannot safely access or update the medication record because of:
- Internet or network failure
- Power loss
- Vendor or cloud service outage
- Login or identity-provider failure
- Device failure
- Local application error
- Cybersecurity event
- Failed integration that makes orders or administrations unreliable
- Planned maintenance
- Facility-specific data access problem
Create clear authority for declaring downtime, naming the operational lead, notifying staff, choosing the approved fallback, and ending downtime. A partially working screen should not remain in routine use if its data freshness or write confirmation cannot be trusted.
The federal Health IT Playbook points organizations to a well-designed paper method for documentation and medication orders during EHR unavailability. The current ONC Contingency Planning SAFER Guide addresses safety practices for planned and unplanned EHR downtime.
Prepare a current downtime packet
Staff need an approved, accessible source of resident medication information. Depending on the home's validated process, the packet may be securely generated paper, a protected read-only local view, or another vendor-supported method.
For each resident, it should identify:
- Full name and another approved identifier
- Photograph when policy uses it
- Facility and room context
- Current medication orders and effective versions
- Medication name, strength, dose, form, route, and frequency
- Scheduled administration times
- PRN indication and follow-up direction
- Hold parameters and special directions
- Allergies and relevant alerts
- Prescriber and pharmacy contacts
- Delegation or assistance context needed for the workflow
- Packet generation time and data-through time
A static screenshot is a poor source of truth because it may omit fields, lose pagination context, hide an alert, or become stale without a visible version. Generate a purpose-built downtime report with page numbers, resident identity on every page, and an expiration or freshness warning.
Control access to fallback records
Availability does not eliminate confidentiality. Store paper packets in a defined locked location accessible to authorized staff during downtime. Protect offline electronic records with encryption, authentication, automatic locking, device management, and remote revocation where available.
Track:
- Packet or device identifier
- Generation and replacement time
- Person who accessed or issued it
- Facility and resident scope
- Number of pages or records
- Return, reconciliation, and destruction
- Missing or compromised materials
WAC 388-76-10315 requires resident records to be confidential and protected from loss, destruction, unauthorized use, and alteration. A downtime clipboard left in a public area does not meet the purpose of a secure fallback.
Mark the start of downtime precisely
Create a downtime incident record even if the outage is brief. Include:
- Facility
- Start date and time
- Detection source
- Systems and functions affected
- Last confirmed successful synchronization or transaction
- Person declaring downtime
- Fallback method activated
- Staff notified and channel
- Vendor or technical case number
- Update cadence
- Operational and technical leads
Display one clear status across devices: normal operation, degraded service, downtime, recovery, or resolved. If writes are queued locally, tell staff whether the entry is merely saved on the device or confirmed by the server.
Do not show a normal success message before durable confirmation. An ambiguous spinner or automatic retry can lead a caregiver to repeat an administration or signature.
Preserve the medication schedule during the outage
The fallback record should present scheduled opportunities rather than only a list of medications. Staff need to distinguish:
- Scheduled dose due during downtime
- Dose completed before downtime
- Dose recorded electronically but awaiting confirmation
- PRN opportunity and related effectiveness follow-up
- Held, refused, unavailable, missed, late, or resident-away outcome
- New or changed order received during downtime
WAC 388-76-10470 requires Washington Adult Family Homes to follow practitioner-ordered times and directions. WAC 388-76-10475 requires an up-to-date daily medication log with resident, medication, dosage, frequency, approximate time, staff initials, refusal, and medication-change information.
The downtime form should include those core fields plus actual administration time, outcome, notes required by the situation, and a unique event identifier that can support later reconciliation.
Document in real time on the approved fallback
Staff should sign or initial the fallback record when the medication event occurs, not pre-sign a future dose or wait until service returns. Capture:
- Resident
- Medication and scheduled opportunity
- Actual dose and route
- Actual date and time
- Outcome
- Required reason or observation
- Staff signature or attributable identity
- Witness or second check when required
- Related PRN, vital, glucose, or follow-up reference
- Unique downtime event number
Use indelible, legible corrections on paper under facility policy. Do not erase, obscure, or rewrite the original entry. For an offline electronic form, changes should produce additive audit events.
Never use a screenshot annotation, text message, or personal notes application as the official fallback record. If urgent communication uses another approved channel, copy the relevant facts into the authorized record and preserve the source according to policy.
Handle new and changed orders during downtime
An outage does not make an unverified instruction an active order. The downtime process should record:
- Resident and medication affected
- Practitioner or authorized source
- Date and time received
- Exact instruction
- Recipient
- Read-back or verification under policy
- Effective time
- Scheduled opportunities affected
- Request for written verification
- Written document received
- Pharmacy receipt status when applicable
Attach or reference the source without altering the last generated downtime packet. Add a clearly identified interim order sheet so staff can see both the prior order and the authorized change.
When service returns, create the new order version with the original effective time and an explicit late-entry timestamp. Do not backdate the electronic creation event or make the order appear available before it was received.
Prevent duplicate medication administration
The highest-risk recovery failure is treating an undocumented-looking electronic slot as evidence that the dose was not given. Before any late or catch-up administration, staff must check the approved downtime record and follow the resident-specific safety process.
Software can reduce duplicate risk by:
- Assigning a stable identifier to each scheduled opportunity
- Assigning a unique identifier to every offline or paper event
- Showing a prominent downtime interval on the MAR
- Blocking routine “give” action while reconciliation is pending
- Matching by resident, medication, order version, scheduled time, and actual event time
- Flagging possible duplicates for human review
- Preserving uncertain conflicts rather than choosing automatically
An offline client should use idempotent submission: retrying the same event sends the same identifier, so the server accepts it once. A second device's competing record should become a visible conflict, not silently overwrite the first.
Reconcile in a controlled recovery phase
Restored service is not the same as completed recovery. Keep the eMAR in a recovery state until designated staff compare all sources.
Reconciliation should proceed resident by resident and scheduled opportunity by scheduled opportunity:
- Confirm the outage interval and last trustworthy electronic transaction.
- Collect every paper and offline record.
- Confirm resident, medication, order version, schedule, and actual time.
- Match events already present electronically.
- Enter missing events as late downtime entries.
- Resolve duplicates and conflicting outcomes without deleting history.
- Enter new orders and discontinuations with true source and effective times.
- Reconnect related vitals, PRN follow-up, inventory, incidents, and notifications.
- Review unresolved due, missed, or held alerts.
- Obtain authorized reconciliation sign-off.
Each transcribed entry should identify the original author, downtime source, transcribing user, original event time, transcription time, and source-page or event number. The original record remains evidence after transcription.
Resolve conflicts without overwriting either account
Examples include paper showing “given” while an offline device shows “missed,” two different actual times, or different doses. The system should open a reconciliation case with:
- Both original records
- Users and timestamps
- Order and schedule context
- Supporting supply, vital, or communication evidence
- Reviewer
- Determination and reason
- Resident response and notifications
- Corrected MAR presentation
- Linked safety or incident review when applicable
Do not select the later entry automatically. Do not erase the earlier record. The missed medication correction guide explains why amendments should preserve the original outcome and attribution.
Restore alerts from underlying events
After synchronization, medication alerts should recalculate from reconciled data. A scheduled dose that was given on paper and accurately transcribed should not continue to show as unrecorded. A missed dose should not disappear because the system merely came online.
Track recovery alerts such as:
- Downtime administrations awaiting transcription
- Conflicting outcomes awaiting review
- New orders awaiting verification or pharmacy receipt
- PRN effectiveness follow-up incomplete
- Held dose follow-up incomplete
- Inventory reconciliation pending
- Paper packet not returned
- Facility recovery sign-off incomplete
Resolve each alert only from the linked evidence. Avoid a global “clear all” action that hides unresolved medication work.
Securely close and retain downtime materials
After reconciliation, record:
- Service restoration time
- Recovery validation results
- Number of events reconciled
- Conflicts and unresolved items
- Reviewer and sign-off time
- Paper or offline records retained
- Copies destroyed under policy
- Devices cleared or returned
- Vendor case resolution
- Lessons and corrective actions
Do not destroy the only original before record-retention requirements and investigation needs are satisfied. A scanned copy should be legible, complete, page-ordered, linked to the incident, and access controlled.
When HIPAA applies to a covered entity or business associate, the HHS Security Rule summary describes contingency planning that includes backup, data restoration, and continuation of critical processes protecting electronic protected health information in emergency mode. HIPAA applicability must be evaluated for the particular organization; it should not be assumed for every Adult Family Home.
Design downtime and recovery reports
A focused report should include:
- Facility and outage interval
- Affected residents and scheduled opportunities
- Events recorded on paper or offline
- Transcription and match status
- Duplicate or conflict cases
- New and changed orders
- Unresolved follow-up
- Packet custody
- Technical timeline and vendor references
- Recovery approval
Medication-level exports should remain separate from the technical incident report. Provide filters for resident, medication, date range, source type, reconciliation status, user, and exception. A PDF should be formatted, color independent, paginated, and suitable for review—not a printout of the application shell.
Test downtime as a complete operational exercise
Run scheduled drills with demonstration residents. Test:
- Planned maintenance with advance packet generation.
- Sudden internet and power failure.
- Vendor outage while a user is submitting an administration.
- Uncertain last successful transaction.
- Medication given on paper during downtime.
- Refusal, hold, missed dose, and PRN follow-up.
- New order received while the eMAR is unavailable.
- Two devices submitting the same offline event.
- Competing outcomes from paper and offline sources.
- Restoration with resident-by-resident reconciliation.
- Inventory and alert recalculation.
- Lost page or unavailable fallback device.
- Facility switch during a multi-home outage.
- Unauthorized user attempting to open another facility's cache.
- Report generation and paper custody closure.
Measure how long it takes staff to find the correct resident and order, how fresh the fallback data is, how many ambiguous entries occur, and whether every event reaches a final reconciled state. Revise the procedure after each exercise.
Frequently asked questions
Is a printed screenshot an adequate downtime MAR?
A purpose-built, versioned downtime report is safer because it can include required fields, page context, data-freshness time, resident identity, and reconciliation identifiers. Screenshots may omit or stale important information.
Should staff wait for the system to return before documenting?
No. Use the facility's approved fallback and document the medication event at the time it occurs. Transcribe and reconcile it later with both original and entry timestamps.
Can staff administer a dose because the restored eMAR looks blank?
The blank slot alone is not enough. Check the approved downtime record and complete the resident-specific safety review to prevent a duplicate dose.
When is downtime finished?
Technical service may be restored before operational recovery is complete. Close downtime only after records, orders, alerts, inventory effects, materials, and conflicts are reconciled and signed off.
Should paper records be destroyed after transcription?
Follow applicable retention and facility policy. Preserve the original or an authorized complete copy as required; do not destroy the only evidence before reconciliation and review are complete.
Make recovery part of the downtime design
A dependable eMAR downtime plan connects preparation, secure fallback access, real-time medication documentation, order changes, duplicate prevention, recovery reconciliation, alert recalculation, record retention, and tested accountability.
Explore AFH Manager to generate focused medication records, capture resilient event identifiers, reconcile offline work, preserve amendments, and produce medication and downtime reports. Validate the full procedure in drills before relying on it during an actual outage.