S1E8: Cause to Pause: Considering Downtime in the AI Era (ft. Christine Baran, MaineHealth)

 

 

 


Healthy Uptime Podcast Christine Baran (MaineHealth) and Jordan Cooper (Rackspace)-20261001_110240-Meeting Recording
October 1, 2026, 3:02PM
17m 51s

Jordan Cooper started transcription

Jordan Cooper   0:03
here today with Christine Barron, the Mountain Region IT Director at Maine Health. Christine, thank you for joining us today.

Baran, Christine A   0:10
Thank you for having me. It was great connecting with you at Becker's in this follow-up discussion.

Jordan Cooper   0:15
So for our listeners, Maine Health is a health system headquartered in Portland, Maine, with 1300 beds across 10 hospitals, serviced by 1400 physicians, serving roughly 1.1 million residents across Maine and northern New Hampshire. It's a mouthful. So today I will be discussing resiliency and AI, making downtime preparedness part of operational readiness. So Christine, I'd like to kick us off in this conversation.
by saying, of course, as all our listeners know, health systems have always had downtime procedures like paper charting and manual med administration. How is the AI era changing what downtime means? And why is now the moment to rethink readiness?

Baran, Christine A   0:57
Thank you for that. Yeah, I think you're correct. I think the goal of every healthcare organization is to be prepared with manual processes, with their EHR down, any other systems that are critical to their operations. However, what we find in reality is that downtime is not correct.
practice necessarily. It is not as kept up with that should be. You may have a binder sitting in a room and then processes change and those binders don't get updated. So having a robust resiliency process is critical to anything we're doing today.
But now with AI, as we look to agentic workflows that will not necessarily replace people, but maybe diminish their ability to work manually. So as we move away from the initial use of AI for certain workflows,
18 months later, two years later, do we still have the expertise in house readily available should those agents no longer function? Oftentimes they're in the cloud, they rely on our network connectivity. And I know, I think I'm not speaking out of turn here, but our cyber folks are quite worried about the ability to hack into any AI agentic processes. So
I do think we need to be a little bit more cognizant of preparedness as we roll out at a very rapid pace. We are rolling out AI technology at a very rapid pace. And I think getting it live is sometimes more important than thinking and stopping for a moment and saying, are we resilient if this is no longer available to us?

Jordan Cooper   2:40
So Christine, you just mentioned the idea of a physical three ring binder sitting somewhere in the hospital with manual downtime workflows. Sometimes processes change and the binder isn't updated. I'm wondering if you might be able to speak to what you perceive as the gap between legacy downtime plans like that described in the binder.
in today's AI embedded workflows with ambient documentation, triaging, scheduling, imaging, revenue cycle. How do you address that gap? What are your thoughts about that gap?

Baran, Christine A   3:12
I think during our thought processes about downtime in general, we need to identify critical functions. Some things can go a few hours without being minded. So I know this won't be a popular answer, but revenue cycle can often wait. If it is down and it comes back in a few hours or even the next day, we will keep up with

Jordan Cooper   3:18
Yeah.

Baran, Christine A   3:33
billing in the way that we need to. However, critical processes, things that rely on safety, patient safety, need to be thought of immediately, as soon as it goes down, even if it's down for 15 minutes sometimes. So as we think about these things, it's going to be really hard to maintain a binder.
But we also can't store this data on our network because the network might be down. Our power might be out. There are operational considerations about continuing to provide service for non-urgent workflows. So that sometimes in a power outage, we say, we're closing the practice. We can't safely take care of a patient anymore until that power comes back on.
However, for a hospital, acute care, you need to think about this. And we need to have documents that are updated, available to us, possibly on our cell phones or something that can connect to data, even if our network is down. And I think that's one gap that we could fill if we just haven't figured out exactly what the best solution is.
that for us. We don't give cell phones that are, you know, company provided to every single person who works in our organization. People might need to use their personal phones and that creates a whole open, another set of dilemmas for us and our cybersecurity team.

Jordan Cooper   4:52
So you speak about cybersecurity. I like to bring up kind of an analogy that we've discussed previously where you've described downtime preparedness somewhat akin to a cyber insurance policy. How do you make the case to leadership and clinicians to invest time and money in something that frankly, you hope you'll never have to use?

Baran, Christine A   5:13
Yeah, it's the insurance mentality. It's providing peace of mind in an inevitable situation. I am not aware of any organization who hasn't had a significant dime time, not always associated with cybersecurity, but, you know, we may have a rodent who chews through a fiber cable.
Someone might cut a line out on the street that disconnects us from our internet world where many of our workflows are, AI or not. And we need to be prepared for that. And I think similar to a disaster drill that you want your ED folks to be ready for, using emergency labels to identify patients, calling in people, extra people to work. We need to practice this. And I think
My advocation is to practice it beyond the tabletop. It's easy for leaders to say in a tabletop environment, we're going to do this. But when you actually go to execute those steps in a real world environment, it is really challenging. I will tell you that the state of Maine has recently passed a rule
about hospitals having preparedness, downtime preparedness. It specifically is referring to cyber events, but truthfully, it really needs to be preparedness in all aspects of downtime. And that will really push the envelope. It isn't going to be me or someone else like me arguing about spending the money.
It's going to be, this is something we have to do to provide a patient safe environment in our community. The state of New Hampshire has not passed a similar law that I am aware of, but this is a recent development in the state of Maine and that's where our home base is. So I'm sure we're going to take this very seriously.

Jordan Cooper   6:51
So maybe a lot of our listeners are, this may be resonating with them. They may be people who are being pitched to with this kind of argument. It may be helpful to them to hear if you or anyone at Maine Health has taken the time to try to quantify the value
of this kind of downtime to your CIO, CTO, CISO, how do you quantify the ROI? And, you know, obviously there's slim margins, so where do you prioritize budget?

Baran, Christine A   7:24
So the preparedness, no doubt will cost money. Like it will require us to either bring in additional resources, slow down for a bit in order to handle more manual workflows. I think that the industry is sort of speaking for us. It is difficult to create an ROI. So there's two different ones, right, that you need to
expressed to executive leadership. One is the cost of doing the downtime drills, and the other is the cost of not doing them. So I think that there is well-published literature about how many millions, sometimes billions, of dollars are lost in a significant event to any large healthcare organization.
And I think if you point them to those events, things that have happened in the state of Vermont or elsewhere with United Healthcare, I don't want to speak out of turn, but there's been plenty of healthcare organizations who have had downtimes and have publicized what their losses were. When you look at that and you weigh it against the cost of doing a downtime, I don't think they're equivalent.

Jordan Cooper   8:22
Mm.

Baran, Christine A   8:28
And it is probably something that we should invest in.

Jordan Cooper   8:31
So you mentioned that on the topic of prioritization, you know, when you're designing a manual workflow that works even when AI is unavailable, you mentioned that, for example, RevCycle is something where billing could be pushed off a day or two. Do you have any recommended
kind of metrics by which organizations can rank their priorities, deciding which workflows get a fallback. How do you keep clinicians proficient at it? Which use cases are critical? Are we going to prioritize, you know, the IV bags being administered without the electronics? What are your, do you have any
metrics or workflows there.

Baran, Christine A   9:15
Yeah, I think we have used a rating system to identify our critical systems. And that way we help not only pay for downtime, but for backup and recovery. You know, things that are hotly available, like we have a hot option to fall over to, to fail over to, to having something that may not be available for 24 hours.
So I think we've already designed it around our systems. Now designing it around the workflows is really up to operations and far less an IT initiative. We can make recommendations, of course, but really our operational counterparts need to identify in their minds what needs to be on the critical path. And I do think you need to marry each workflow
up with the time, it can sort of be okay with being down for a bit of time. I saw this broken down recently, a 30 minute down versus an hour versus 4 hours versus 12 hours versus a day, a week, and up to 30 days. I think most organizations, once you are down for over 30 days, you have to really think what you're going to
move forward-looking like in a different way. You know, if you're down for that long, that really can be difficult to overcome. So I think that that to me is we need to talk to operations. Operations needs to be in charge, whether you start with your EDs, which obviously are going to get your most critical patients in the moment.

Jordan Cooper   10:25
So...

Baran, Christine A   10:36
OR, active cases going on while a downtime occurs, your ICU, your med surg, you know, kind of work backwards into what the acuity of the patients that we're dealing with. Ambulatory services are a different story. You know, we may not be seeing, unless it's an urgent care, we may not be seeing critical patients at that time.
So they need to make a call. Are they going to continue to see patients on paper, which the downtime recovery is something we could talk about a little bit, but that also costs money. It takes longer to enter things after the fact than it does, and you have to wait for steps. I have to check in the patient first before I can put their clinical note in.
in the ambulatory setting. This is true for inpatient as well. You have to register the patient. If it's been down for several hours, you can't chart on a patient that doesn't exist in the EMR. So there's an order of operations. It's very complicated. We actually, at our organization, we actually have a project manager who's working on this.
who's helping operations organize their thoughts around how long they're down, what critical operations, and the order of operations that needs to occur once you're back up in order to get that data into the EHR.

Jordan Cooper   11:48
So when you map your AI enabled workflows, so just going back to AI, that is a topic everyone wants to discuss. What do you do you find any, what do you find about hidden dependencies like cloud services or third party vendors or data pipelines, identity systems?

Baran, Christine A   11:53
Yep.

Jordan Cooper   12:07
And how does that shape your recovery priorities?

Baran, Christine A   12:11
I think it adds complexity, to be honest with you. I think sometimes when we have all on-premise solutions, we own the servers, we're connected to them within our own network. We're not going out to the internet, relying on internet service providers to provide us with the connectivity to it. So you're talking about so many points of failure.
You have your internet service provider that connects you to anything that's cloud-based. You have Azure or whatever the platform is running on up in the cloud. It could have its own attack, its own downtime for whatever reason. Many times they have redundancy built in and they'll advertise that to us before they host our systems or processes. But even then, the connectivity itself,
I think in sometimes with the cyber event, they voluntarily choose to shut off. I think that's another factor here. And it's just really becoming a partner with our business solutions and ensuring what their downtime processes are as well. Again, adding to the complexity, how much do we have to care if we have 40 workflows that are out in the cloud?
How many different business relationship conversations do we have to have in order to understand what their downtime processes are? I think it is, we are obligated ourselves to figure that out. If it's unavailable for whatever reason on their side, we have to just assume it's going to go down. I think that's the only really tact to take that's smart.

Jordan Cooper   13:32
So if you had access to unlimited resources to fund the implementation of 1 capability that could assist Maine Health before the next major incident, what would it be? And would you see your health system doing that internally or partnering with somebody externally to Maine Health?

Baran, Christine A   13:52
I think it would be probably naive to think that we could do it on our own. It's significant. Everything we've been talking about is storage and complexity and support. You don't want your downtime alternative. Say you have unlimited resources and you can completely replicate your system at another site.
whether that's a bunker somewhere in the Midwest, if it's offshore, not in the United States. If you have unlimited funds, you really want your entire system to be a hot swap over. That's what you want if you're really talking pie in the sky. But again, realistically, without unlimited resources, which we all know,
and all the conversations that we're in, as much as AI, we're talking about the headwinds that we're facing with the changes in our reimbursement model that are going to happen from the government. Maine is the oldest state. I found out that very recently that the county that our one main health hospital is in New Hampshire is the second oldest county in New Hampshire with 43%
of the population over 65. So, you know, we really have to think about everything when it comes to this, not just the tactical, the IT, the infrastructure, but what our patient population looks like. It matters. You know, our leaning on AI and technology is great.
But we also have to remember we have a subset of patients who aren't going to go there, right? They're not going to become part of this. It's a bad assumption to assume that not all of them will. I think we have a lot of folks that are, you know, in their retirement age that are using AI just fine. But we have to be ready for all of this. And I think, you know, without unlimited funds,
that we all know that we have. We have to do the prioritization that we were talking about earlier and really identify those critical systems that we should have as hot as available backup as we can, but we still have to have downtime procedures, even with ultra confidence that that backup situation will take over.

Jordan Cooper   15:56
So Christine, as we approach the end of this podcast episode, a final question. Do you have any advice for or any requests that you would like to make of the executive leadership team at Main Health, or if you were to speak on behalf of your peers, the executive leadership team at another health system somewhere in the United States on this topic?

Baran, Christine A   16:19
I guess what I would say is that similar to an EHR deployment, as we roll out other technology, third party, AI, it doesn't really matter, to have the project plan include downtime resiliency as a final stamp.
We want to get it live. We have a go-live date. That is the ultimate.
you know, success factor is getting it and turning it on, but both the support of it, the care and feeding of it while it's up, and the downtime resiliency of when it goes down should be part of the project plan before we switch the, you know, switch the, flip the switch. And I think sometimes we don't
want to think about that because it's overwhelming. It's A boil the ocean part of a project.
But if that, you know, six months after it goes live, it goes down and we don't know what to do, there are consequences to that. And I think we should pay up front instead of after the fact.

Jordan Cooper   17:15
Mm-hmm.
All right, well, for our listeners again, this has been Christine Baran, the Mountain Region IT Director at Maine Health. Christine, I'd like to thank you so much for joining us today.
Big.

Jordan Cooper stopped transcription