Skip to content
compliancebase
HIPAA164.308 — Contingency Plan

§164.308(a)(7)

Contingency Plan

HIPAA · 45 CFR Part 164 · Last verified August 2026

Objective

Establish and test plans for responding to emergencies that damage systems containing ePHI, including backup, disaster recovery, emergency operations, and criticality analysis.

Points of focus

  • Maintain retrievable copies of ePHI
  • Restore critical systems and continue essential operations
  • Test plans and prioritize applications by criticality

Implementation notes

Define ePHI recovery objectives per service, isolate backup credentials, restore representative tenants into a clean environment, and exercise dependencies such as identity, keys, queues, and partner connectivity. Operationalize maintain retrievable copies of ephi in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain backup configuration and successful job reports with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that backups are provider-reported as successful but no complete ephi restore is attempted Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.

Audit tip: Sample backup configuration and successful job reports with dates and named reviewers. Be ready to walk through how you detect and correct: backups are provider-reported as successful but no complete ephi restore is attempted

Evidence auditors typically request:

  • Backup configuration and successful job reports
  • Dated restore test with measured recovery results
  • Application criticality analysis and disaster-recovery exercise

Common gaps

  • Backups are provider-reported as successful but no complete ePHI restore is attempted
  • Recovery priorities conflict with customer care dependencies and identity services

Cross-Framework Mapping

FrameworkRequirementImplementation note
HIPAA§164.308(a)(7)This control
SOC 2CC6.1, CC7.2SOC 2 evidence can support the safeguard, but HIPAA scope and Required/Addressable analysis remain distinct.
ISO 27001A.5.15, A.8.15ISO controls offer reusable operational evidence without replacing the Security Rule analysis.
GDPRArticle 32Article 32 overlaps for ePHI that is also EU personal data, subject to each law's scope.

Primary sources

Frequently Asked Questions

Contingency Plan applies to the systems and commitments in your Security Rule scope. Translate the requirement into concrete operating workflows — maintain retrievable copies of ephi — with evidence stored where auditors and customers can sample it.

Lead with backup configuration and successful job reports and pair it with dated restore test with measured recovery results. Samples should show who performed the control, when, against which population, and what changed as a result.

Teams often fail because backups are provider-reported as successful but no complete ephi restore is attempted Close the loop with dated operating records and test the control on a realistic production path.

Control operation can often be shared across SOC 2, ISO 27001, GDPR, and HIPAA — but each framework uses different vocabulary and accountability. Maintain an explicit crosswalk rather than assuming equivalence.

Review at least annually and after material product, vendor, or data-flow changes. High-risk or privileged paths may need quarterly sampling even when the criterion does not prescribe a cadence.

Framework versions referenced in this page:

  • HIPAA45 CFR Part 164

Last verified: August 2026 · Primary sources linked above