Every practice finds out whether it has a contingency plan. The only question is whether the discovery happens during a calm Tuesday policy review or at 7:40 on a Monday morning when the EHR will not load and the practice manager is staring at a ransom note.
The Security Rule assumed this day would come. 45 CFR 164.308(a)(7) requires every covered entity and business associate to "establish (and implement as needed) policies and procedures for responding to an emergency or other occurrence (for example, fire, vandalism, system failure, and natural disaster) that damages systems that contain electronic protected health information."
That standard comes with five implementation specifications. Three are Required. Two are labeled Addressable, and if you have read why addressable does not mean optional, you already know that label is not a permission slip.
What a HIPAA Contingency Plan Must Contain
1. Data Backup Plan (Required)
The rule asks for procedures to "create and maintain retrievable exact copies" of ePHI. Two words carry the weight: retrievable and exact. A backup you have never restored is a hope, not a plan. The test is simple: pick a file, restore it, time it, write down the result. If your EHR is cloud-hosted, your piece of this is knowing what the vendor backs up, how often, and how you would get your data out. "The vendor handles it" is an answer only if you can say what the vendor actually does.
2. Disaster Recovery Plan (Required)
Procedures to "restore any loss of data." This is the sequence document: who calls whom, in what order systems come back, where the backups live, and what the passwords situation is when the password manager is on the dead server. For a five-person office it fits on two pages. The two pages need to exist on paper, because the plan stored only on the system that just died is a joke that writes itself.
3. Emergency Mode Operation Plan (Required)
The least understood piece. It covers the gap between the outage starting and systems coming back: how do you keep treating patients, and how do you keep ePHI secure, while running on paper and phones? Downtime forms, a paper schedule pulled each morning, and a rule for where downtime notes go when the EHR returns. Security does not pause during the outage; that is the entire point of the specification.
4. Testing and Revision (Addressable)
A tabletop test once a year is the reasonable-and-appropriate baseline for a small practice: sit down for one hour, walk through "the server is dead," find the three things that do not work, fix them, and document that you did. If you choose not to test, the Security Rule requires you to document why testing was not reasonable and what you did instead. Writing that memo honestly is usually harder than running the test.
5. Applications and Data Criticality Analysis (Addressable)
Rank what comes back first. EHR, then scheduling, then billing, then email is a common small-practice order, but yours depends on how you actually run. This is a one-hour worksheet, and it makes the disaster recovery plan honest: restoration order is a decision you make now, not an argument you have during the outage.
The Cloud Did Not Repeal This Rule
Moving to cloud systems changes the failure modes. It does not remove them, and it does not transfer your obligation. A cloud outage takes your practice offline just as thoroughly as a dead server, as the February 2026 Cloudflare outage demonstrated for thousands of businesses at once. Your vendor's uptime promise lives in their B.A.A. (Business Associate Agreement) and SLA. Your contingency plan is what your office does during the hours those promises are being broken.
What OCR Asks For
After a ransomware incident or a breach report, OCR investigates Security Rule compliance, and 164.308(a)(7) is part of that rule. Expect to produce the contingency plan and the written documentation behind it, which 164.316(b) requires you to keep for six years. Practices produce risk assessments and training logs and then hit a wall on this one, because it was never written. It is a required standard, and its absence is a finding all by itself, separate from whatever caused the breach. The rest of the Security Rule picture is in the Security Rule implementation guide.
Build It in an Afternoon
One page per component, five pages total, most of it bullet points. The policy template library includes a contingency plan template with the disaster recovery, emergency mode, and criticality pieces pre-structured. Fill it in, print two copies, put one somewhere that is not the server room, and calendar the annual test. That is the whole assignment.
---
FAQ
Is a contingency plan required for small practices?
Yes. 45 CFR 164.308(a)(7) applies to every covered entity and business associate regardless of size. Data backup, disaster recovery, and emergency mode operation plans are all designated Required.
Is cloud backup enough to satisfy HIPAA?
Cloud backup can satisfy the data backup specification if the copies are exact, retrievable, and you have verified restoration. You still need the disaster recovery and emergency mode pieces, which cover your office's response, not the vendor's.
How often should we test the contingency plan?
Testing is an addressable specification. For a small practice, an annual tabletop walkthrough, documented, is the widely accepted baseline. If you decide not to test, document the reasoning and the alternative.
What is an emergency mode operation plan?
The procedures for continuing critical business processes, and keeping ePHI secure, while systems are down: downtime forms, paper schedules, and how downtime documentation gets entered once systems return.
Do business associates need contingency plans too?
Yes. The Security Rule applies to business associates directly, and 164.308(a)(7) names them explicitly. If you are a vendor holding ePHI, this is your obligation, not just your client's.
Conclusion
A contingency plan for a small practice is a short document, not a binder. One Guy Consulting's Full-Scope plan includes the contingency policy template, the criticality worksheet, and consulting time to run your first tabletop test. Start with a free 30-minute compliance review. No obligation, no pressure.
Sources
- 45 CFR 164.308 (administrative safeguards)
- HHS Security Rule guidance material
- NIST SP 800-34: Contingency Planning Guide
Related Reading