The First Warning Was the Size
I was checking the backups at a dental office that used Eaglesoft.
The backup drive held about 4 GB of data. The server held about 160 GB.
The backup was missing most of the practice’s data.
The X-rays were missing
The backup had run every night for about two years. It saved the main Eaglesoft database to an external Seagate drive.
But it did not save the X-rays or scanned documents attached to each patient.
If the server had failed, the office could have restored patient names, appointments, and treatment codes. The X-rays and scanned files would have been gone.
The backup drive stayed beside the server
The external drive stayed plugged into the server all day and night.
That could help if a hard drive inside the server failed. But a fire, theft, lightning strike, or ransomware attack could damage both the server and its backup.
Every copy was in the same room.
Someone had told the office that the setup was fine. I do not blame the person who set it up. The problem had gone unseen for two years because no one had tested a full restore.
We fixed both problems
First, we changed the backup so it saved the X-rays and scanned documents along with the Eaglesoft database.
We also changed where the copies were kept. The external drive now leaves the office each night. We added an encrypted copy in another location too.
A problem at the office can no longer destroy every copy at once.
We tested the restore
A backup should be tested before anyone has to depend on it.
Before the next backup ran, I added a test appointment to the schedule. After the backup finished, I restored the offsite copy to another computer.
The test appointment was there. That showed me the restored database was current.
I also checked the file sizes. The restored copy included the full 160 GB of X-rays and documents.
Three questions every owner should ask
Ask the person who handles your technology these questions:
- What is being backed up?
Ask for a list of the databases, folders, and online services included in the backup. - Where are the copies kept?
Make sure at least one copy is away from the office and disconnected from the server. - When was the last full restore test?
Ask what was restored, where it was restored, and how they checked that the data was current.
Clear answers can help you catch a bad backup before a failed server, fire, or attack turns it into a much bigger problem.