It’s 8:52 on a Tuesday. Your first patient is at nine, there are fourteen more behind them, and the practice management system won’t load. Not slow — nothing. The receptionist refreshes it four times. Someone suggests turning the router off and on again.
Now what?
Most independents have never sat down and answered that question properly. We ask vendors about clinical records, stock control and how the GOS claims module behaves. We rarely ask the far less comfortable question: what happens on the day this stops working, and how long will I be standing in reception apologising?
Every system goes down eventually. Cloud, desktop, server in the back room — all of them. The difference between practices isn’t whether it happens. It’s whether the fifteen minutes after it happens are managed or chaotic. This is the part of a software comparison almost nobody runs, and it’s the part that costs the most when it goes wrong.
Three failures that feel identical from the front desk
When the screen goes blank, your receptionist can’t tell you why. But the cause changes what you should do, and it changes which vendor questions matter.
Your connection has dropped
The software is fine. Your broadband isn’t. This is by far the most common cause and the one you have most control over — a 4G/5G backup router costs less than a month of most PMS subscriptions and switches over automatically. UK SMEs averaged three to four connectivity failures and around 19 hours of downtime in a year, and internet failures cost UK businesses an estimated £3.7 billion annually. If you’re cloud-based with no failover connection, you’ve built a single point of failure for about £25 a month of avoidable risk.
The vendor is having a bad day
Their servers, their problem, your patients. You can do nothing except wait and communicate. What matters here is entirely down to what you agreed when you signed: how fast they tell you, how fast they fix it, and whether anyone answers the phone.
Something local has broken
The server in the cupboard, the machine the database lives on, a failed drive, a power cut, a flood in the room above. This is the failure mode that historically hurt independents most, because recovery depended on whether somebody had actually been checking the backups. Usually nobody had. It’s one of the strongest arguments for moving off a local server — you’re not eliminating the risk, you’re handing it to somebody whose full-time job is managing it.
What an uptime percentage actually buys you
Every vendor website says something about uptime. The number is only useful if you convert it into hours, so do that before you’re impressed by it.
- 99.5% — about 43 hours a year. That’s more than a full working week of your practice being unable to see records.
- 99.9% — about 8 hours 45 minutes a year. Roughly one working day.
- 99.95% — about 4 hours 20 minutes a year.
- 99.99% — about 53 minutes a year.
The gap between 99.5% and 99.9% sounds like rounding. In practice it’s the difference between one bad day a year and one bad week a year.
Three follow-up questions separate a real commitment from marketing copy. Is that figure contractual, or aspirational? Does it exclude planned maintenance — because a vendor who takes the system down for four hours every month and calls it “planned” can advertise 99.9% honestly and still ruin six Saturday mornings a year. And what are the actual published figures for the last twelve months, not the target?
Be sceptical of SLA credits. A vendor offering to refund a day’s subscription for a day of downtime is offering you about £5. The outage cost you a morning’s clinic. Credits are not compensation; they’re a signal of how seriously the vendor takes availability, and that’s the only thing to read them for.
The two numbers that matter more than uptime
Uptime tells you how often things break. These two tell you what breaking actually costs you.
Recovery Time Objective (RTO) — how long until you’re working again. Ask for it in hours, in writing. “As quickly as possible” is not an RTO.
Recovery Point Objective (RPO) — how much work you lose. If backups run nightly, your RPO is up to 24 hours, meaning a Thursday afternoon failure could wipe every record, order and payment entered since Wednesday night. If backups are continuous, your RPO is measured in minutes.
Consider what a 24-hour RPO means concretely: a full day of sight tests re-entered from memory and paper scraps, dispensing orders that may or may not have reached the lab, payments taken that no longer exist in the system. Reconstructing a day of clinical records after the fact is not just tedious — it’s a records-integrity problem you’d struggle to defend if anyone asked.
Worth knowing: 92% of UK businesses take 24 hours or longer to recover from a significant outage. If your vendor’s RTO is materially better than that, ask them to prove it.
Backups, and the restore test nobody runs
Every vendor backs up. Backing up is easy. Restoring is the hard part, and an untested backup is a guess.
What to ask, in order:
- How often do backups run, and are they continuous or scheduled?
- How long is each backup kept — days, weeks, or months? This matters enormously for ransomware, where the damage may sit undetected for a fortnight before it triggers.
- Are backups stored somewhere geographically separate from the live system?
- When did you last perform a full restore test, and what was the measured restore time?
- Can I request a restore of my practice’s data alone, or only the whole platform?
Question four is the one that separates serious vendors from the rest. A vendor who can tell you the date of their last restore test and the time it took has a continuity plan. A vendor who says “we back up nightly to the cloud” and stops there has a backup job, which isn’t the same thing.
What can you still do when the system is unreachable?
This is the practical question, and most comparison exercises skip it entirely. Sit with each vendor and walk through a normal Tuesday with the system unavailable.
Can anyone see today’s appointment list? A system that emails or prints the day’s schedule automatically each morning turns a catastrophe into an inconvenience — you at least know who’s coming and roughly why. Can clinicians access a patient’s last prescription and clinical history in any form? Can you take payment? Card terminals independent of the PMS keep working; fully integrated ones may not.
And what’s the re-entry process? If your team writes on paper for three hours, how does that get back into the system afterwards, and does the software make that straightforward or punishing?
You should also write down, on actual paper, kept in a drawer that doesn’t need electricity: the vendor’s support number, your account reference, the mobile number of whoever in your team makes decisions, and a two-line script for reception. Sounds unnecessary. Isn’t. The one time you need it, the number will be in an email you can’t open.
The regulatory clock doesn’t pause for your outage
This is where downtime stops being an operational irritation and becomes a compliance problem.
GOS claims have a hard window. In England, GOS1, GOS5 and GOS6 claims are valid for three months from the date of the sight test, and GOS3 and GOS4 for three months from the date the appliance is supplied or collected — and that window covers submission, processing and payment, not just submission. Lose a fortnight of claim data at the wrong end of a quarter and you’re not chasing an admin backlog, you’re writing off income. Any system handling eGOS claims should let you see exactly what’s submitted, what’s pending and what’s at risk, and that view has to survive an outage.
Records must be kept for years. NHS patient records are retained for seven years, and GOC expectations sit at a similar minimum — longer where a limitation period might run beyond that. A backup retention policy of thirty days doesn’t meet a seven-year obligation. Understand which of the two your vendor is actually offering.
UK GDPR requires restorability, not just security. Article 32 asks for the ability to restore the availability and access to personal data in a timely manner after an incident. That’s a legal requirement to have a working restore process, sitting on you as the data controller — not only on your vendor. And if data is lost or exposed, the reporting clock to the ICO is 72 hours. The health sector self-reported 3,820 personal-data breaches to the ICO across 2023 to early 2025, more than any other sector. We’re already the most-reported group; the regulator isn’t going to be surprised by an optician’s breach report, but they will ask what your restore arrangements were.
Ransomware is a continuity problem wearing a security costume
Practices tend to file ransomware under security and stop thinking about it. But the damage is almost entirely a continuity failure: your data still exists, you just can’t reach it, and how long that lasts depends on your backups rather than your firewall.
The Synnovis attack in June 2024 is the case study worth knowing. Pathology services across several south-east London hospitals were crippled, more than 10,000 outpatient appointments and over 1,700 elective procedures were postponed, and in June 2025 a trust confirmed a patient death partly attributed to a delayed blood test caused by the attack. That was a large, well-resourced organisation with a dedicated IT function.
The lesson for a three-site independent isn’t to panic. It’s that recovery capability, not prevention alone, decides how bad the incident gets. Offline or immutable backups that ransomware can’t reach and encrypt are the single most valuable thing here — worth far more than another security badge on a vendor’s homepage. We covered the wider ground in our piece on data security and GDPR in optician PMS.
Continuity beyond the vendor: your exit rights
The longest possible outage is the one where the vendor stops trading, gets acquired and sunsets your product, or you simply decide to leave and can’t get your data out in a usable state.
Read the contract before you sign, specifically for:
- Export format. “We’ll provide your data” is meaningless. CSV per table, or a documented database dump, is meaningful. A locked PDF of ten thousand patient records is not.
- Scope. Does export include clinical notes, images, OCT scans, attached documents and audit trails — or just the demographic fields?
- Cost. Is export free, or is there an extraction fee that appears only when you try to leave?
- Timescale. How many days from request to data in hand?
- Insolvency. What happens to your data if the vendor fails? Is there an escrow arrangement, or does your patient list become an asset in an administration?
Ask for a sample export during the trial, not after you’ve signed. A vendor confident in their openness will hand one over. A vendor who hesitates has told you something useful. This is the same discipline we recommended around switching systems — the time to check the exit is at the entrance.
Ten questions to put to every vendor
- What was your actual measured uptime for the last twelve months?
- Is your uptime commitment contractual, and does it exclude planned maintenance?
- What is your RTO, in hours?
- What is your RPO — how much of my work could I lose?
- How often do backups run and how long are they retained?
- When did you last run a full restore test, and how long did it take?
- How will you notify me of an outage, and how quickly?
- What support is available on a Saturday morning?
- What can my practice still do while the system is unreachable?
- Show me a full data export, in the format I’d get if I left.
Print that list. Take it to every demo. The answers will tell you more about a vendor than an hour of feature walkthrough, because these questions are hard to bluff and easy to verify.
Where Raven Vision sits on this
Raven Vision was built by Shaukat, an optometrist with 35+ years in practice who runs three of his own, which means the continuity questions weren’t theoretical when we designed it. Losing a morning’s clinic is a thing he’d personally experienced.
Practically: it’s cloud-hosted with managed, geographically separated backups, so there’s no server in your cupboard to fail and no member of staff quietly responsible for a task nobody checks. The patient record and the appointment diary reach any device with a browser, so a broadband failure at the practice doesn’t stop a clinician working from a phone on 4G. Your data is yours and exportable — ask us for a sample export during the trial and we’ll send one.
What we won’t tell you is that we’ll never have an outage. Anyone who says that is either inexperienced or not being straight with you.
It’s £149 a month per location, with free data migration, no setup fee and no lock-in — which is easy to offer when you’re not relying on trapped data to keep customers.
If you want to put the ten questions above to us directly, book a walkthrough and bring the list. Ask us the awkward ones first. And whatever you decide, run this exercise with whoever you’re using now — because the honest answer to “what happens when it goes down” is worth knowing before 8:52 on a Tuesday, not after.



