In a modern hospital the network is a life-safety-adjacent utility: nurse call, telemetry, electronic health records (EHR), barcode medication administration, real-time location, physiologic monitoring, imaging, and increasingly the building's own fire, security, and clinical-engineering systems all ride on the same converged IP fabric. This Article covers how that fabric — and the spaces and circuits that feed it — are made to survive component failures, cable cuts, room losses, and utility outages. It addresses three intertwined disciplines: logical/physical network redundancy, diverse and protected cabling pathways, and resilient power for ICT loads. The data-center spaces, network-core topology, and wireless/DAS coverage that this resilience protects are described in the sibling Article on Data Center, Network Core & Wireless/DAS Coverage; the room/riser/distribution geometry is covered under Telecom/Equipment Rooms, Risers & Distribution Topology. Here the focus is the resilience overlay on top of those.

Why ICT resilience is a clinical-continuity issue, not just an IT issue

Downtime of the network in a hospital is not a productivity inconvenience — it can interrupt care. Loss of the EHR forces clinicians into downtime procedures and paper charting; loss of nurse call or middleware breaks the communication chain between a patient in distress and the responding caregiver; loss of monitoring or telemetry gateways can mean alarms do not reach anyone. Because so many clinical workflows are now network-dependent, owners increasingly treat ICT resilience with the same seriousness historically reserved for normal/emergency electrical power and medical gas.

Several drivers push ICT redundancy into the design program:

The practical consequence: the resilience target for each ICT system should be risk-tiered to its clinical criticality, not applied uniformly. A telemetry gateway or nurse-call server deserves a higher availability target than a digital-signage controller.

Establish availability tiers and a resilience matrix

Good ICT resilience design starts with a deliberate classification of systems and spaces by criticality, agreed among the owner, clinical leadership, IT, and the design team. A common approach borrows the data-center "tier" mindset but applies it system-by-system rather than to a single building rating.

A typical (illustrative) tiering for healthcare ICT:

Tier Description Representative systems Typical resilience posture
Tier 1 — Life-critical Failure can directly threaten patient safety Nurse call, code/alarm middleware, physiologic monitoring/telemetry gateways, clinical-alarm notification, fire alarm network links Redundant power (UPS + generator-backed), redundant network paths, fast/automatic failover, no single point of failure
Tier 2 — Care-critical Failure disrupts care delivery within minutes EHR access, PACS/imaging, lab and pharmacy systems, RTLS for clinical workflow, VoIP/clinical communications Redundant power and dual-homed network; rapid failover; downtime procedures as backstop
Tier 3 — Operationally important Failure degrades operations but care continues Access control, CCTV, building automation network, food service, materials management UPS ride-through, generator backup where practical, single-path acceptable with monitoring
Tier 4 — Convenience/ancillary Minimal clinical impact Digital signage, guest Wi-Fi, public AV Normal power, best-effort, no redundancy mandate

The deliverable is a resilience/redundancy matrix that, for every major ICT system and every telecom space, records the assigned tier, the required power source (normal / UPS / generator branch), the path-diversity requirement, the failover behavior (automatic vs. manual), and the recovery-time and recovery-point expectations. This matrix becomes the contract that the electrical, structured-cabling, and network designs must satisfy, and it anchors the integrated testing and commissioning effort at the end of the project.

Levels of redundancy: from component to geographic

Redundancy is layered. Each layer addresses a different failure mode, and a high-tier system generally needs several layers working together.