Free HIPAA reference template · v1.0 · Applies to covered entities & business associates
Adopting this document means committing to these HIPAA controls, the 45 CFR §164 requirements it helps satisfy, by area:
Common threats (NIST SP 800-30 classes) that the controls behind this document defend against:
Exploits: Unpatched systems; no tested backups · 164.308(a)(7) Contingency; 164.308(a)(5)(ii)(B) Malware
Exploits: Endpoint not encrypted · 164.312(a)(2)(iv) Encryption; 164.310(d) Device Controls
Exploits: No tested backups; single copy · 164.308(a)(7)(ii)(A) Backup
Template. The specific, fillable plan for creating and maintaining retrievable exact copies of ePHI: the annex your Contingency Planning Policy points to. Replace
[bracketed]items. Satisfies the Data Backup Plan at 45 CFR § 164.308(a)(7)(ii)(A) and data backup/storage at § 164.310(d)(2)(iv).
| System / data store | Contains ePHI? | Backup method | Frequency | Retention | Encrypted? |
|---|---|---|---|---|---|
| [EHR] | Yes | [vendor-managed + export] | [continuous / daily] | [X days/years] | [AES-256] |
| [File storage] | Yes | [cloud snapshot] | [daily] | [30 days] | [yes] |
Backups are stored [off-site / in a separate cloud region], isolated from primary systems, and encrypted at rest and in transit. Access is restricted to [roles].
See where your organization stands on the controls this template cites.
Join Us[24 hours][4 hours]Backups are monitored for success daily; a restore is tested at least [quarterly] and logged in the Contingency Plan Test Record. A failed backup is alerted to [owner] and remediated within [timeframe].
[Security Official / IT] owns this plan; [backup operator] runs and verifies it. Reviewed at least annually and after any change to the ePHI environment. v1.0.