45 CFR § 164.308(a)(7)
Addresses data backup, disaster recovery, and emergency-mode operations to ensure ePHI remains available during and after an emergency. Covers the three required implementation specifications: backup plan, recovery plan, and emergency mode operations.
Sample Preview
Version 1.0·Effective [EFFECTIVE DATE]·Approved by [PRIVACY/SECURITY OFFICER NAME]
This policy establishes the contingency plan for [PRACTICE NAME] to ensure the availability, integrity, and security of ePHI during and after emergencies, disasters, or system failures. It addresses the three required implementation specifications (data backup plan, disaster recovery plan, and emergency mode operation plan) and two addressable specifications (testing and revision procedures, and applications and data criticality analysis).
This policy applies to all information systems, applications, and data repositories that create, receive, maintain, or transmit ePHI at [PRACTICE NAME]. It covers emergencies of all types, including natural disasters, power outages, cyberattacks, hardware failures, software failures, and any event that disrupts normal business operations or threatens the availability of ePHI.
[PRACTICE NAME] shall establish and implement a contingency plan for responding to emergencies or other occurrences that damage systems containing ePHI, as required by 45 CFR § 164.308(a)(7). The plan shall include data backup procedures, disaster recovery procedures, and an emergency mode operation plan. The plan shall be tested, revised as necessary, and supported by an analysis of the criticality of applications and data.
Contingency Plan: A comprehensive strategy for ensuring business continuity and the protection of ePHI during and after an emergency or disaster.
Data Backup: The process of creating retrievable, exact copies of ePHI to protect against data loss.
Disaster Recovery: The process of restoring information systems, data, and operations after a disaster or major disruption.
Emergency Mode Operation: The procedures for maintaining critical business processes and protecting ePHI during and immediately after a crisis.
Recovery Point Objective (RPO): The maximum acceptable amount of data loss measured in time (i.e., the maximum age of the data that must be recovered for operations to resume — equivalently, the longest period for which recently created or changed data may be lost in a disruption).
Recovery Time Objective (RTO): The maximum acceptable time to restore systems and resume operations after a disruption.
Applications and Data Criticality Analysis: An assessment that identifies the relative importance of applications and data to the practice's operations and patient care.
while we’re in beta
A professional, CFR-referenced policy template, ready to customize for your practice. Free during the beta.
Free while we’re in beta
Need more than one?
The Complete HIPAA Policy Library — every policy, checklist, and review template. Free while we’re in beta.
Free while we’re in beta
Templates require customization and legal review before adoption. Not legal advice. See full disclaimer.