Uptime and offline operation
What happens when the internet drops
Honest current behavior versus the designed local-first behavior.
How to read status labels: In the pilot (v0.2.0, synthetic data) Simulated in the pilot Coming (Wave 2, rolling out) Designed, not yet built Open decision Not offered / no claim made Planned partner integration
C0198What happens in the pilot when the internet goes down?
The pilot runs on a cloud hub, so a network outage stops alerts and messaging. The app shows a red offline banner with a reconnect countdown and disables sending. Alerts and messages missed while offline are delivered on reconnect and flagged late.
C0199Will the production design work without internet?
Yes by design: the on-site server stays fully operational for care when the WAN is down, including local printing and local audit. This requirement is not met by the current pilot and is the top-priority build item.
C0200Can I open charts while offline in the pilot?
No. The pilot has no offline chart and no downtime reports. Offline chart access is part of the on-site backend package, which has not started.
C0201Is working offline safer from hackers?
The design states that being offline improves security against remote attack, which is why a limiter trip pauses only sync and leaves local care running.
C0202What is the safe-mode ladder?
Six levels from normal operation through WAN down, ledger down, partial server, server down and site lost. At each level care continues locally as far as possible, and cross-site features are reduced first.
C0203What is a downtime emergency data set?
A read-only set of current census, allergies, medications, code status, emergency contacts and last vitals refreshed to two encrypted local appliances, so an emergency department is never locked out when the server is down. Refresh interval and credential validity are example values.
C0204How long do cached credentials work offline?
The design example is at most 72 hours since last sync, logged locally and reconciled later. Example value, open for decision.
C0205Are paper downtime forms part of the plan?
Yes: sealed printed downtime reports refreshed per shift, paper forms, and back-entry afterwards. Printed reports are locked, tamper-sealed, logged and shredded on refresh.
C0206How often are downtime drills run?
The design calls for downtime drills with clinical staff twice a year per unit and quarterly restore drills. These are plans, not performed drills.
C0207What uptime percentage do you guarantee?
None. Availability figures in the specification are planning targets to be validated by measurement, and no service-level agreement is offered. The availability promise per tier is an open decision.
C0208Is there an uptime SLA for the small tier?
No. The small-tier support model is undecided; best-effort business-hours support is the working default and not a commitment.
C0209What is the weakest structural area?
Availability under attack. Systems coupled for security are also levers for denial of service, so the design uses quorums, local autonomy and a non-cryptographic emergency mode.
C0210What if the single cabinet fails?
At the small profile the cabinet, its power and its uplink are single points of failure. The mitigation is an uninterruptible power supply, printed downtime reports and the cloud replica, with no claim of high availability.
C0211Does a power cut stop care?
The reference profile includes an online UPS sized for at least an hour at small-clinic load and a generator interface where available. The clinic supplies its own electricity.
C0212What is the dead-man policy?
If the server loses contact with its key authority for a configured number of days it refuses to unseal after restart, with an emergency unseal by quorum so care is never endangered. Interval is an open value.
C0213What happens to queued messages after an outage?
Queues are persistent and drain in order on reconnect, with backpressure and an alert instead of silent drops.
C0214Are late alerts labelled?
Yes in the pilot: alerts delivered after reconnect carry a late flag so staff know they are not live.
C0215Can the local network work if the server is fine but the internet is down?
Yes: alerts, messaging and audit are designed to operate entirely on the local network with no cloud push in the alert path.
C0216How is a site rebuilt after total loss?
From the cloud replica or immutable vault into a clean-room environment, verified by signatures and chain, then promoted with dual authorization. A full-site rebuild drill annually is planned.
C0217How does the system behave during a cloud outage?
The clinic is unaffected because the local database is primary; sync resumes afterward.
C0218What happens when one server node fails?
Medium and large profiles use replicas with automatic failover. Small clinics run one cabinet, with a second downtime appliance recommended.
C0219How is the health of the system monitored?
Metrics, PHI-free logs, queue depth, backup age, certificate expiry and device health, with daily self-test pings and a shift-start device check. Designed, not built.
C0220Who is on call for the small tier?
Undecided. Severity-based support is planned: 24x7 for medium and large, business hours for small unless a fee is agreed.