§164.308(a)(7)
Contingency Plan
HIPAA · 45 CFR Part 164 · Last verified August 2026
Objective
Establish and test plans for responding to emergencies that damage systems containing ePHI, including backup, disaster recovery, emergency operations, and criticality analysis.
Points of focus
- Maintain retrievable copies of ePHI
- Restore critical systems and continue essential operations
- Test plans and prioritize applications by criticality
Implementation notes
Define ePHI recovery objectives per service, isolate backup credentials, restore representative tenants into a clean environment, and exercise dependencies such as identity, keys, queues, and partner connectivity. Operationalize maintain retrievable copies of ephi in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain backup configuration and successful job reports with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that backups are provider-reported as successful but no complete ephi restore is attempted Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample backup configuration and successful job reports with dates and named reviewers. Be ready to walk through how you detect and correct: backups are provider-reported as successful but no complete ephi restore is attempted
Evidence auditors typically request:
- Backup configuration and successful job reports
- Dated restore test with measured recovery results
- Application criticality analysis and disaster-recovery exercise
Common gaps
- Backups are provider-reported as successful but no complete ePHI restore is attempted
- Recovery priorities conflict with customer care dependencies and identity services
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| HIPAA | §164.308(a)(7) | This control |
| SOC 2 | CC6.1, CC7.2 | SOC 2 evidence can support the safeguard, but HIPAA scope and Required/Addressable analysis remain distinct. |
| ISO 27001 | A.5.15, A.8.15 | ISO controls offer reusable operational evidence without replacing the Security Rule analysis. |
| GDPR | Article 32 | Article 32 overlaps for ePHI that is also EU personal data, subject to each law's scope. |
Primary sources
- HHS HIPAA Security Rule: 45 CFR Part 164 — Security and Privacy Rules; topic: §164.308(a)(7)