The short answer
When a pharmacy's phone system drops at 4:45 pm, first confirm whether callers actually cannot get through by calling the published number. If they cannot, treat it as P1 until closing and P2 after. Tell staff at once, update patients with pre-approved wording that contains no health information, and decide on call-outs from a written runbook.
This case study is an illustrative scenario. The business is a composite and the numbers are worked examples to show the method, not results from a named client.
What happens when a pharmacy's phone system drops at 4:45 pm?
At 4:45 pm on a weekday, a small community pharmacy's on-site phone system drops off the network. The pharmacy closes at 6. For the next 75 minutes, patients calling about refills, transfers and questions may hear nothing or a busy signal, while staff at the counter have no idea anything is wrong.
The composite business is an independent pharmacy with a small attached clinic room in a Canadian town: one pharmacist on the late shift, two assistants, a phone system in a back-room cabinet next to the internet router, and one published number that patients, doctors' offices and the local care home all use. Late afternoon is busy on the phone: refill requests before the weekend, doctors' offices calling in prescriptions, and people asking whether their order is ready.
Without monitoring, the outage is found the way most are. A patient walks in at 5:20 and says, "I've been calling for half an hour." An assistant tries the number from her own mobile and hears nothing. The pharmacist phones the IT contractor, who is on another job and suggests restarting the cabinet. That does not work. The contractor offers to come out after 6 at the after-hours rate. Meanwhile the care home has been trying to reach the pharmacy about a resident's medication change.
Here is how the same afternoon runs with MapleMonitor Respond in place. The rest of this article walks through each step and the reasoning behind it.
How do you tell lost contact from callers who cannot get through?
Lost contact means your monitoring can no longer see the phone system. Callers cannot get through means a real call to your published number fails. They are different problems with different urgency. The only reliable way to know whether patients are affected is to place a real call to the number they dial.
Monitoring that only watches the phone system's network connection can be wrong in both directions. The system can drop off the monitoring view because of a network hiccup while calls still ring through normally. Or the system can look reachable while calls fail somewhere between the carrier and the handsets. Neither tells you what a patient hears.
MapleMonitor checks on-site phone systems by calling the published number. In the scenario, two signals arrive within a couple of minutes of 4:45:
- Lost contact. The phone system stops answering its network check. On its own, this is a warning: something changed in the back-room cabinet.
- Test call fails. A call to the pharmacy's published number does not connect. This confirms patients are affected.
If only the first signal fires and test calls still connect, the right response is a lower-priority check during business hours, not an emergency. If both fire, it is a patient-facing outage. Separating the two avoids the two classic mistakes: ignoring a real outage because "the monitor is flaky", and dragging someone out at night for a monitoring blip.
How is priority set, and why does it change at 6 pm?
Priority reflects how much of the business is affected and when. Phones down during opening hours at a pharmacy is P1: serious, patient-facing, but the doors are open. Outside business hours, MapleMonitor drops P1 to P3 by one level, so at 6 pm the same outage becomes P2. A P0 never drops.
MapleMonitor uses five levels, from P0 Critical, where the business is at a halt and all hands work it until it is back to P2, down to P4 Informational. For the pharmacy, a written rule of thumb helps:
- P0: the pharmacy cannot operate at all, for example the dispensing system and the phones are both down while the store is open.
- P1: patients cannot reach the pharmacy by phone during opening hours.
- P2: the same fault after closing, or a partial fault during hours, such as one line down out of two.
- P3 and P4: lost contact with test calls still connecting, or a warning that needs a look this week.
NIST's current incident response guidance, revised in 2025, treats response as part of everyday risk management: preparing in advance reduces both how often incidents happen and how much they hurt [1]. The Cyber Centre's guidance on incident response plans follows the same order: once an incident is detected, analyzed and prioritized, the team notifies the people who need to be involved [2]. Setting priority rules before the outage is that preparation.
With Respond, the MapleMonitor agent sets the priority from the signals and your rules, and runs the runbook you agreed at setup. At 4:47 pm the incident is P1. At 6:00 pm, with the phones still down, it becomes P2 automatically, and the runbook's after-hours branch takes over.
What does the war room look like during the outage?
Every outage opens a war room: one timeline showing when each signal fired, the priority, every message sent and every action taken, kept in a tamper-proof audit trail. With Respond, each war room also gets a conference line, so the pharmacist, the owner and the IT contractor can talk without a chain of separate calls.
In the scenario, the timeline reads roughly like this. At 4:45, lost contact with the phone system. At 4:46, a test call to the published number fails. At 4:47, P1 is set and the runbook starts: a voice call to the pharmacist's mobile, texts to the owner and the IT contractor, and the conference line number shared with all three. At 4:55, the contractor joins the line, asks the assistant to read the lights on the router and phone system, and finds the phone system has lost its network connection after a power blip in the back room.
Keeping everything on one timeline matters after the event as much as during it. The Cyber Centre recommends reviewing each incident afterwards and writing a lessons learned document [2]. Respond includes a written outage summary, and the war room record is the raw material: when it started, what was tried, who was told, and when it was fixed.
How do you tell staff and patients without sharing health information?
Tell staff immediately and patients with short, pre-approved wording about service status only: the phone line is down, here is how else to reach us. Never include names, prescriptions or anything about a patient's health. MapleMonitor never sends patient information by SMS or email.
Health information is among the most sensitive personal information there is. The Privacy Commissioner's guidance on PIPEDA's safeguards principle says to protect personal information in a way appropriate to its sensitivity, and that health information would generally be considered sensitive [3]. Provincial health privacy laws are more specific. In New Brunswick, for example, the Personal Health Information Privacy and Access Act requires custodians to protect personal health information with reasonable administrative, technical and physical safeguards [4]. An outage message has no reason to carry any of it.
With Respond, customer updates go out by SMS, email or voice using only the wording you pre-approved at setup. For the pharmacy, that might be three messages:
- Staff: "Our phone line is down. Patients cannot call in. Use the counter mobile for urgent calls and the conference line for updates."
- Regular callers such as the care home and nearby doctors' offices: "Our phone line is temporarily down. Please use our fax or email for prescriptions, or visit the pharmacy. We will confirm when it is restored."
- Public status page: the same message, so anyone who checks online sees it.
There is also an optional outage status line add-on, which lets callers to your number hear about the outage and get a live update from a receptionist. Ask at setup how it would work with your line.
What about 9-1-1 when the phone system is down?
Do not assume desk phones can reach 9-1-1 while the on-site system is down. If they depend on it, an outage affects them too. Keep a charged mobile at the counter, tell staff to use it for emergencies during any phone outage, and ask your phone provider how 9-1-1 works on your line.
This belongs in the runbook, not in someone's memory. The staff message above mentions the counter mobile for exactly this reason. Also ask your provider which civic address is attached to your number for emergency calls, and update it if the pharmacy has moved or the system was set up somewhere else. That conversation takes ten minutes and is worth having before an outage, not during one.
Should you pay for an after-hours call-out or wait until morning?
Decide in advance. If the fault is P2 after closing, the pharmacist on call can be reached by mobile, and the phones can be fixed before opening, a morning fix is usually right. Pay for an overnight call-out only when the outage will still be patient-facing at opening time.
In the scenario, the runbook's after-hours branch says: at P2, no overnight call-out unless a remote fix fails and the contractor cannot be on site by 8 am. The contractor restores the network connection remotely at 6:20 pm after the assistant power-cycles the right device, test calls connect, and the war room closes. The next morning the owner reads the written outage summary and books a small battery backup for the back-room cabinet.
The table below is a worked example of the arithmetic. Replace each figure with your own call counts and rates.
| Item | Method | Without monitoring | With Respond |
|---|---|---|---|
| Minutes before staff know | Start of outage to first person aware | 35 minutes | 2 minutes |
| Calls missed before closing | Normal calls per hour x hours down while open (30 x 1.25) | about 38 calls | about 38 calls, but regular callers told another route |
| Prescriptions or transfers lost | Missed calls x share that go elsewhere (assume 10%) | about 4 | 1 to 2 |
| Staff time coordinating | People x hours on calls and workarounds | 2 x 1.5 = 3 staff-hours | 2 x 0.5 = 1 staff-hour |
| After-hours IT call-out | Hours at the contractor's after-hours rate | 3 hours | 0 hours, remote fix |
To turn the table into money, multiply lost prescriptions by your average gross margin per prescription, staff-hours by your loaded hourly cost, and call-out hours by your contractor's after-hours rate. The difference between the two columns is what one afternoon like this is worth. Compare it with the Respond price on the pricing page, and count how many afternoons like this you had last year.
Who does not need the Respond tier?
A single small clinic whose phone line already forwards to a mobile when the system fails, and whose staff notice problems within minutes, may be well served by Watch alerts alone. Respond is for businesses where outages land at busy times and nobody has spare hands to run the response.
Watch still tests the phone line, alerts your team by SMS, email or voice, keeps the war room timeline and gives you a status page. What it leaves to you is the response: setting priority, running the steps and telling patients. If you have a practice manager who is calm, reachable and happy to do that, Watch may be all you need. If you want someone on call 24/7 and remote repair before anyone drives in, that is the Managed tier, and it is more than most single-site pharmacies need.
What should you do this week?
Write a one-page phone outage runbook: how to confirm the outage with a real call, what counts as P1 during hours and P2 after, who gets told, the exact wording for staff and regular callers with no patient information, where the counter mobile is, and when an overnight call-out is justified.
Then test it. Near closing time on a quiet day, call your published number from a mobile on cellular data and time how long it takes to reach a person. Check who in the building would know if it did not ring. Find the phone system and router in the back room and label them, so an assistant can read the lights over the phone. The Cyber Centre's baseline controls for small organizations start with a written incident response plan that names who handles incidents and how to contact the people outside the business who need to know [5]. For a pharmacy, the phone outage page is a good first page to write.