Free HIPAA reference template · v1.0 · Applies to covered entities & business associates
Adopting this document means committing to these HIPAA controls, the 45 CFR §164 requirements it helps satisfy, by area:
Common threats (NIST SP 800-30 classes) that the controls behind this document defend against:
Exploits: Unpatched systems; no tested backups · 164.308(a)(7) Contingency; 164.308(a)(5)(ii)(B) Malware
Exploits: No least-privilege; no access reviews · 164.308(a)(4) Access Mgmt; 164.312(a) Access Control
Exploits: No access controls on shares · 164.312(a) Access Control; 164.514(d)
Template. How you keep critical, PHI-protecting processes running while systems are down: the bridge between disaster and full recovery. Replace
[bracketed]items. Satisfies the Emergency Mode Operation Plan at 45 CFR § 164.308(a)(7)(ii)(C) and emergency access at § 164.312(a)(2)(ii).
Emergency mode is in effect when normal systems are unavailable but [Organization] must continue critical operations that protect ePHI or patient safety (e.g., delivering care, safeguarding records).
| Critical process | Normal system | Emergency fallback | Who runs it |
|---|---|---|---|
| [Access to essential records] | [EHR] | [read-only backup / secured paper] | [role] |
| [New record capture] | [EHR] | [paper form → reconcile later] | [role] |
Break-glass access to ePHI during emergencies is granted only to [named roles], is logged, and is reviewed after the event. Elevated access is revoked as soon as normal operations resume.
See where your organization stands on the controls this template cites.
Join UsEven in emergency mode, ePHI remains encrypted where feasible, physical documents are secured, and every emergency access and disclosure is recorded for later review.
When systems are restored (see the Disaster Recovery Plan), reconcile any emergency-captured data, revoke break-glass access, and log lessons learned. Reviewed at least annually. v1.0.