HIPAA Tip: Disaster Recovery Plan Testing
How many times have you heard from your compliance expert or IT team that you must conduct Disaster Recovery Plan (DRP) testing? And you think – are they nuts?
On the contrary, one of the most important areas to focus on with cybersecurity is testing (at least bi-annually) your DRP. The last place you want to be in a disaster is not knowing what to do and testing not only allows you the run through before the “storm”, it also uncovers areas that may have been overlooked when writing the plan.
- Run through the DRP with all staff. Go back to using paper for one day, pretending there is no access to the EMR or any other electronic system. Document the steps taken with the paper notes once they are able to be submitted into the respective systems and applications. Designate team members to manage certain tasks.
- When meeting with your DRP Team (at least three or four times annually), request each member bring a “what if” scenario to the table to work through with the team how the organization would handle this particular disaster. Enlist all team members – there is strength in numbers!
- Look to the National Institute of Standards and Technology (NIST), Cybersecurity and Infrastructure Security Agency (CISA), and Health and Human Services Cyber Gateway for guidance, tips, training, tools and resources to assist your organization with the DRP and successful testing. Don’t forget regular Cybersecurity Training for all staff.
Compliance Is Ongoing
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.