How to HIPAA: Resilience & Continuity
Free HIPAA guide · 8 controls · 9 templates
Withstand and recover: contingency planning, backups, disaster recovery, and incident response. The sections below are assembled from the same control catalog, threat library, and enforcement mapping our free assessment runs on.
The controls in this area
The 45 CFR §164 requirements HIPAA places here: 8 of the 103 controls in our catalog. Our free templates and assessment track each one:
164.308(a)(7)(i) · 164.308(a)(7)(ii)(A) · 164.308(a)(7)(ii)(B) · 164.308(a)(7)(ii)(C) · 164.308(a)(7)(ii)(D) · 164.308(a)(7)(ii)(E) · 164.308(a)(6)(i) · 164.308(a)(6)(ii)
What enforcement looks like here
Breach causes reported to HHS that implicate these controls: Hacking/IT
Related threat scenarios
Common threats (NIST SP 800-30 classes) that this area's controls defend against:
- AdversarialRansomware
Exploits: Unpatched systems; no tested backups · 164.308(a)(7) Contingency; 164.308(a)(5)(ii)(B) Malware
- EnvironmentalStaffing loss / pandemic
Exploits: No line of succession; key-person risk · 164.308(a)(7) Contingency Plan
- StructuralHardware / storage failure
Exploits: No tested backups; single copy · 164.308(a)(7)(ii)(A) Backup
- StructuralSoftware / system outage
Exploits: No DR plan; no RTO · 164.308(a)(7)(ii)(B) Disaster Recovery
Free templates for this area
De-branded policy and procedures templates mapped to this area's controls. Read the full text free, then adapt them to your organization:
See where your organization stands on the 8 controls in this area.
Join Us