When the Office for Civil Rights (OCR) opens an investigation after a breach report, its data request is predictable. It asks for the risk analysis, the risk management plan, the policies and procedures, the training records, the business associate agreements, and the contingency plan with evidence that it was tested. The entities that settle for six and seven figures are rarely the ones with no plan; they are the ones whose plan has no date on it, no test behind it, and no connection to the systems that actually failed. This checklist is written for the compliance officer who has to assemble that evidence file. It covers the five elements the current Security Rule requires at 45 CFR 164.308(a)(7), the measurable clauses the proposed update would add, and the artefact that proves each one.

The five elements the rule requires today

The contingency plan standard has five implementation specifications. Three are required under the current rule and two are addressable; the proposed rule would make all five required. Treat them all as required now.

ElementStatus todayWhat it must containEvidence
Data backup planRequiredProcedures to create and maintain retrievable exact copies of ePHIBackup policy; schedule per system; job history showing the age of the newest copy
Disaster recovery planRequiredProcedures to restore any loss of dataRunbooks per critical system; restoration order; roles and contacts
Emergency mode operation planRequiredProcedures to continue critical business processes that protect ePHI while operating in emergency modeDowntime procedures; manual workflows; how ePHI created during the outage is captured and re-entered
Testing and revisionAddressable (proposed: required, every 12 months)Procedures for periodic testing and revision of the plansDated test reports with timings, deviations, sign-off; revision history
Applications and data criticality analysisAddressable (proposed: required)Assessment of the relative criticality of applications and data in support of the other elementsRanked inventory with RPO and RTO per system and dependencies

The clocks the proposed rule adds

Four numbers from the proposal belong in the plan now, because each one is a question an investigator can ask whether or not it is yet in the regulation.

Our post on disaster recovery architecture for the 72-hour objective covers how the infrastructure meets the first two; this checklist is about the paper.

Section 1: inventory and criticality

Section 2: backup

Section 3: disaster recovery

Section 4: emergency mode operation

This is the element most often missing, because it is a clinical and operational document rather than an IT one.

Section 5: testing and revision

Section 6: business associates

How to use the checklist

Work through the six sections and mark each line green, amber or red: green has a dated artefact on file, amber has an artefact older than 12 months or without sign-off, red has nothing. Fix the reds in sections 1 and 2 first, because the criticality analysis and the backup evidence are what every other section depends on, and because they are the two items OCR's enforcement history shows it asks about most. Then schedule the rehearsal that turns section 5 green, since a single well-documented restoration test moves more lines than any other action.

For a health system that hosts its critical systems with MassiveGRID, most of sections 2, 3 and 5 arrive as part of the managed service: the backup job history, the runbooks, the off-site copy, the annual rehearsal report and the written attestation, all under a Business Associate Agreement. What stays with the covered entity is what should: the criticality decisions, the emergency mode procedures, and the sign-off.

Frequently Asked Questions

What are the five elements of a HIPAA contingency plan?

Under 45 CFR 164.308(a)(7): a data backup plan, a disaster recovery plan and an emergency mode operation plan, which are required, and testing and revision procedures and an applications and data criticality analysis, which are addressable today. The proposed Security Rule update would make all five required and add testing at least every 12 months.

Does HIPAA require a specific backup frequency or recovery time?

The current rule does not. The proposed update sets two measurable limits: retrievable exact copies of ePHI no more than 48 hours old, and written procedures to restore critical systems and data within 72 hours of a loss. Entities should set their own tighter RPO and RTO per system in the criticality analysis.

What does OCR ask for after a breach report?

Typically the most recent risk analysis and risk management plan, Security Rule policies and procedures, workforce training records, business associate agreements, the contingency plan with evidence of testing, and incident documentation for the event itself. Investigations frequently turn on whether these documents existed and were current before the incident.

Can a hosting provider's disaster recovery testing count as our test?

It can form part of the evidence if the provider is a business associate under a signed BAA, the test covers your systems and data, you receive the report, and someone from your organisation reviewed or observed it. The covered entity remains responsible for the plan as a whole, including the emergency mode procedures the provider cannot perform for you.

How long must contingency plan documents be retained?

Six years from the date of creation or the date the document was last in effect, under the Security Rule's documentation requirements. That includes superseded versions of the plans and past test reports.

Turn sections 2, 3 and 5 green

MassiveGRID hosts ePHI workloads under a Business Associate Agreement with daily encrypted backups on separate storage, immutable off-site copies in a second US datacenter, documented runbooks and an annual restoration rehearsal with a timed report. The evidence file writes itself.

Healthcare infrastructure

Further Reading