Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: Disaster Recovery Plan Testing

How many times have you heard from your compliance expert or IT team that you must conduct Disaster Recovery Plan (DRP) testing? And you think – are they nuts?

On the contrary, one of the most important areas to focus on with cybersecurity is testing (at least bi-annually) your DRP. The last place you want to be in a disaster is not knowing what to do and testing not only allows you the run through before the “storm”, it also uncovers areas that may have been overlooked when writing the plan.

  • Run through the DRP with all staff. Go back to using paper for one day, pretending there is no access to the EMR or any other electronic system. Document the steps taken with the paper notes once they are able to be submitted into the respective systems and applications. Designate team members to manage certain tasks.
  • When meeting with your DRP Team (at least three or four times annually), request each member bring a “what if” scenario to the table to work through with the team how the organization would handle this particular disaster. Enlist all team members – there is strength in numbers!
  • Look to the National Institute of Standards and Technology (NIST), Cybersecurity and Infrastructure Security Agency (CISA), and Health and Human Services Cyber Gateway for guidance, tips, training, tools and resources to assist your organization with the DRP and successful testing. Don’t forget regular Cybersecurity Training for all staff.

Compliance Is Ongoing

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


About the Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP

Dawn Meglino is a certified HIPAA Compliance Specialist at Anatomy IT helping healthcare organizations navigate complex security and compliance requirements. She holds multiple cybersecurity and compliance certifications and regularly advises medical practices on breach prevention and HIPAA best practices.