HIPAA Tip: Business Continuity / Disaster Recovery Plan
An important part of an effective Business Continuity Plan is identifying your organization’s mission-critical systems, prioritizing restoration, and conducting a Risk Analysis to determine key risk factors that can disrupt processes.
So, what is a Disaster Recovery Plan (DRP)? A DRP is a group of policies, tools, and procedures for the recovery and continuation of business within the technology infrastructure and systems used after a natural or man-made disaster. The Business Continuity Plan (BCP) would outline how the organization will continue operating after an incident (ransomware or cybersecurity attack) and would be included in the DRP. Although both plans go hand in hand it is best to combine, covering all key areas to resume business operations after a disruption.
- Identify risks to the organization
- Assemble a team that will jump into action
- Develop a plan that addresses how critical data is handled during a disaster
- Outline who will have access to critical data in the event of an emergency
- Plan for recovering information systems and processing critical applications
- Data backup recovery and redundancy plan
- Regular testing with DRP team as well as the staff
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.
Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP