Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: Disaster Recovery Plan

Did you know that in the HIPAA Rules a Disaster Recovery Plan is a requirement? The HIPAA Security Rule requires healthcare organizations to implement a Disaster Recovery Plan (DR) as part of their contingency plans under § 164.308(a)(7)(ii)(B).

A Disaster Recovery Plan is a set of policies and procedures that businesses can follow to restore assets and protect sensitive healthcare data in the event of a disaster. Specifically, it covers details and the processes for restoring any data loss resulting from a disaster and how an organization can get itself back up and running – time is of the essence!

Two key factors in your DRP are the critical systems and length of downtime. Which systems or applications need to be recoverable as soon as possible in order to continue business? How long can the organization be without these before the company comes to a dead halt? As part of the DRP these questions must be addressed.

Do not look at the DRP as a daunting project that can be put at the bottom of the list, and do not put a blanket “policy” in place that does not relate to the organization and how a disaster to the environment will be handled.

  • Who are the key players in putting the organization back together? Is all staff aware of whom to contact in the event of an emergency or disaster?
  • Is there an emergency mode operation plan? Has the organization established and implemented procedures to enable continuation of critical business processes?
  • What is the data backup plan? Will backups be easily retrievable if needed?
  • Which data needs to be restored first in the event of a disaster? Is there an outlined priority for data restoration?

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


Author:

Dawn Meglino

HIPAA Compliance Specialist, CHPSE, CCSA, CCAP