HIPAA Tip: Disaster Recovery Plan Testing
The Importance of Testing Your Disaster Recovery Plan
Remember when you were a kid and your schools conducted fire drills? Imagine if the drills were not tested or the procedures on the steps to be taken were not planned out. Now imagine there was a real fire – how would this have been handled and what would have been the outcome?
- HIPAA requires DRP under Security Rule § 164.308(a)(7)(ii)(B)
- Testing is crucial – a plan that hasn’t been tested may not work in real disasters
- Run paper drills: Simulate no EMR access for one day with all staff
- Meet with DRP Team 3-4 times annually with “what if” scenarios
- Key questions: What systems are critical? Can you access patient records? How to continue care?
- Resources: NIST, CISA, and HHS Cyber Gateway provide guidance and tools
HIPAA Security Rule Requirements for Disaster Recovery
The Disaster Recovery Plan is a requirement under the HIPAA Security Rule § 164.308(a)(7)(ii)(B): “Establish (and implement as needed) procedures to restore any loss of data.” Without this plan you cannot continue business as usual on any level. Ask yourself what are the most critical systems and applications needed to care for patients? Will the organization be able to access them in a disaster? How can the business continue to stay up and running when there is limited or no access to patient records?
All of these questions must be answered and documented for the Disaster Recovery Plan (DRP). Next crucial step is to test the plan to see if it actually works.
Essential Steps for Testing Your Disaster Recovery Plan
Conduct Paper Drills with All Staff
Run through the DRP with all staff. Go back to using paper for one day, pretending there is no access to the EMR or any other electronic system. Document the steps taken with the paper notes once they are able to be submitted into the respective systems and applications.
Hold Regular DRP Team Meetings
When meeting with your DRP Team (at least three or four times annually), request each member bring a “what if” scenario to the table to work through with the team how the organization would handle this particular disaster.
Leverage Federal Resources and Guidance
Look to National Institute of Standards and Technology (NIST), Cybersecurity and Infrastructure Security Agency (CISA), and Health and Human Services Cyber Gateway for guidance, tips, training, tools and resources to assist your organization with the DRP and successful testing.
Ongoing HIPAA Compliance Support
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.