Free HIPAA procedures template · v1.0 · Applies to covered entities & business associates · Companion: Policy →
Adopting this document means committing to these HIPAA controls, the 45 CFR §164 requirements it helps satisfy, by area:
Common threats (NIST SP 800-30 classes) that the controls behind this document defend against:
Exploits: Unpatched systems; no tested backups · 164.308(a)(7) Contingency; 164.308(a)(5)(ii)(B) Malware
Exploits: No line of succession; key-person risk · 164.308(a)(7) Contingency Plan
Exploits: No tested backups; single copy · 164.308(a)(7)(ii)(A) Backup
Template. These procedures operationalize the Contingency Planning Policy. Replace
[bracketed]items with your specifics and adjust steps to match your tools and team size.
To provide repeatable, auditable steps for backing up and restoring ePHI, recovering systems after a disaster, operating in emergency mode, maintaining the applications/data criticality register, and testing and revising the contingency plans (implementing the Contingency Planning Policy).
[Security Official], with system/data owners, inventories each application and data store that creates, receives, maintains, or transmits ePHI, plus the infrastructure they depend on.[compliance tracking system]:| Asset / system | Handles ePHI? | Criticality | Recovery priority |
|---|
See where your organization stands on the controls this template cites.
Join Us| RPO (max data loss) |
|---|
| RTO (restore target) |
|---|
| Backup method |
|---|
| Restore owner |
|---|
[production app / DB] | Yes | Critical | 1 | [24 hours] | [48 hours] | [automated daily snapshot] | [role] |
[ePHI document store] | Yes | Critical | 2 | [24 hours] | [48 hours] | [versioning + backup] | [role] |
[internal tooling] | No | Non-critical | 3 | [7 days] | [5 days] | [periodic backup] | [role] |
Backups
[cloud infrastructure provider] and [cloud productivity & storage suite] services.[Security Official] (or delegate) investigates and remediates within [1 business day] and records the outcome.Restore test (run at least [quarterly] for Critical systems, and after any major backup change)
Phase A: Notification & activation
[Security Official] with all known details (what failed, when, suspected cause, systems affected).[Security Official] assesses impact and decides whether to activate the plan. Activate when, for example, Critical systems or ePHI access are unavailable beyond [24 hours], or sooner if the impact clearly warrants it. If the [Security Official] is unavailable, the documented line of succession assumes this authority.Phase B: Recovery (restore in the priority order from the criticality register, §1)
[cloud infrastructure provider].Phase C: Reconstitution
[5 business days] of recovery, hold a root-cause/lessons-learned review and feed improvements into the plans and the Risk Analysis & Risk Management Policy.[Security Official], [Privacy Officer], or designated leadership member) may declare emergency mode; record who declared it and when.[phone], [SMS], [internal messaging tool], videoconference, or in-person) when primary channels are down; notify workforce, patients/clients, and critical vendors of the disruption and provide periodic updates.[Security Official] formally stands down emergency mode once normal operations resume and records the time.[Security Official] (and [Privacy Officer] where ePHI is involved) within [15 business days] of the test.[30 days]; bump the plan version and note the change in its change log.Applications/data criticality register · backup configuration & job-monitoring records · restore-test logs (date, asset, result, time vs. RTO, gap vs. RPO) · disaster-recovery activation and after-action reports · emergency-mode declarations and communication logs · contingency-test reports with sign-off and corrective actions · plan change logs. These are the artifacts an auditor will request to confirm the controls operate.
| Citation | Requirement | Addressed in |
|---|---|---|
| 164.308(a)(7)(ii)(E) | Applications and Data Criticality Analysis | §1 |
| 164.308(a)(7)(ii)(A) | Data Backup Plan | §2 |
| 164.308(a)(7)(ii)(D) | Testing and Revision Procedures | §2, §5 |
| 164.308(a)(7)(ii)(B) | Disaster Recovery Plan | §3 |
| 164.308(a)(7)(ii)(C) | Emergency Mode Operation Plan | §3, §4 |
Reviewed at least annually by the [Security Official]. v1.0.