Contingency plan

Contingency planning, tested and attested per vendor

Backup and disaster recovery attested by every PHI vendor, platform backup on file, a criticality analysis recorded, and a recovery test within the last twelve months.

Contingency planning is where a clinic discovers, at the worst possible moment, that the backup nobody tested does not restore.

The policy is composed from your clinic’s facts

Your contingency policy covers data backup, disaster recovery, and emergency mode operation, plus your recorded decisions on testing and revision procedures and on applications and data criticality analysis. Clinics with natural disaster exposure get a clause addressing it. Clinics with an alternate facility arrangement get a clause on facility model and continuity.

What gets tracked after the policy exists

Eight requirements:

  • Every vendor touching PHI has attested to both data backup and disaster recovery.
  • Platform backup configuration is attested.
  • A criticality analysis is on file, ranking what has to come back first.
  • A recovery test has been recorded within the last twelve months.
  • The policy is present, adopted, reviewed within twelve months, with facts that have not drifted.

The vendor requirement reconciles against your actual PHI vendor list, so adding a vendor without a contingency attestation drops the control rather than passing unnoticed.

What this is, and what it is not

A recorded test is an attestation that a test happened, with a date. The system does not perform a restore, and it cannot tell you whether your recovery would actually succeed. The same is true of vendor attestations: they are statements your vendors made, not observations of their infrastructure.

The twelve-month test window is the useful discipline. Without it, “we have backups” ages indefinitely without anyone ever attempting a restore.

What an investigator gets

Backup and disaster recovery attestations from every PHI vendor. A dated criticality analysis. A recorded recovery test within the year. A policy shaped to your actual facility and exposure. For the standard that only matters on the worst day, evidence that someone prepared before it.

The regulation: read the rule behind this control.

Ready to get your HIPAA program in order?

No pressure, no pitch. Book a 20-minute call, or just email a question and we'll point you the right way.