Backup and disaster recovery attested by every PHI vendor, platform backup on file, a criticality analysis recorded, and a recovery test within the last twelve months.
Contingency planning is where a clinic discovers, at the worst possible moment, that the backup nobody tested does not restore.
Your contingency policy covers data backup, disaster recovery, and emergency mode operation, plus your recorded decisions on testing and revision procedures and on applications and data criticality analysis. Clinics with natural disaster exposure get a clause addressing it. Clinics with an alternate facility arrangement get a clause on facility model and continuity.
Eight requirements:
The vendor requirement reconciles against your actual PHI vendor list, so adding a vendor without a contingency attestation drops the control rather than passing unnoticed.
A recorded test is an attestation that a test happened, with a date. The system does not perform a restore, and it cannot tell you whether your recovery would actually succeed. The same is true of vendor attestations: they are statements your vendors made, not observations of their infrastructure.
The twelve-month test window is the useful discipline. Without it, “we have backups” ages indefinitely without anyone ever attempting a restore.
Backup and disaster recovery attestations from every PHI vendor. A dated criticality analysis. A recorded recovery test within the year. A policy shaped to your actual facility and exposure. For the standard that only matters on the worst day, evidence that someone prepared before it.
The regulation: read the rule behind this control.
No pressure, no pitch. Book a 20-minute call, or just email a question and we'll point you the right way.