At 4:40 p.m. on a Friday, your practice management system stops responding. The vendor's status page says "investigating." You have nineteen patients on tomorrow's schedule, a Saturday urgent-care block, and no idea when the system comes back. What your staff does in the next ninety minutes is either written down in a HIPAA contingency plan you tested in the last twelve months, or it is improvised — and improvised downtime is where PHI ends up on personal phones, in unencrypted spreadsheets, and on paper that never gets reconciled back into the chart.

This article is for the person who has to write that plan and prove it exists. It covers the five components the Security Rule actually names, who in your practice owns each one, how often you test, and what documented evidence looks like when a regulator or a cyber insurer asks.

What a HIPAA Contingency Plan Is, in One Paragraph

A HIPAA contingency plan is the set of written policies and procedures a covered entity or business associate maintains under 45 CFR 164.308(a)(7) to respond to an emergency or other occurrence — fire, vandalism, system failure, natural disaster, ransomware — that damages systems containing electronic protected health information. It has five named components: a data backup plan, a disaster recovery plan, an emergency mode operation plan, testing and revision procedures, and an applications and data criticality analysis. The first three are required implementation specifications. The last two are addressable, meaning you either implement them or document a reasonable, written justification for why you did not and what you did instead. You retain the plan and its supporting records for six years under 164.316(b)(2).

The Five Components, Translated Into Practice Work

1. Data Backup Plan — Required

"We use a cloud EHR" is not a data backup plan. Your plan names every system holding ePHI, states where its data is backed up, how often, how long copies are retained, whether copies are encrypted at rest, and who verifies the backup ran.

The systems practices forget: the imaging modality with a local hard drive, the fax server, the transcription folder on the front-desk workstation, the standalone spirometry laptop, the billing spreadsheet someone keeps "just for reconciliation," and the phone system that stores voicemail with clinical content. Walk the building. Open the closets.

2. Disaster Recovery Plan — Required

This is the procedure to restore lost data. It answers: who initiates a restore, what the sequence is, how long each system takes, and how you verify the restored data is complete and accurate. A restore procedure that has never been executed is a hypothesis, not a plan.

Write the sequence in dependency order. If your e-prescribing module depends on the patient index, the index restores first. Assign a named backup person for every named primary — the practice administrator being on a cruise is not an emergency exception.

3. Emergency Mode Operation Plan — Required

This is the one most practices skip, and it is the one your front desk actually uses. It covers how you keep operating — and keep protecting ePHI — while systems are down.

Concretely: paper encounter forms stored where staff can find them, a printed next-day schedule generated automatically each evening, a downtime log for every patient seen, a rule for where paper lives during the outage (locked drawer, not the counter), and a reconciliation procedure for entering downtime documentation once systems return. Set a deadline for reconciliation — 48 hours after restoration is a defensible standard — and assign it to a named role.

Pair this with the emergency access procedure required separately at 164.312(a)(2)(ii): a documented way for authorized clinicians to reach ePHI during an emergency, including break-glass credentials, where they are stored, who can authorize their use, and how that use is logged and reviewed afterward.

4. Testing and Revision Procedures — Addressable

Addressable is not optional. If you skip it, you write down why, and "it was inconvenient" will not hold. For a practice of any size, annual testing is the realistic floor.

5. Applications and Data Criticality Analysis — Addressable

Rank your systems by how long you can function without them. A three-tier model works: Tier 1 systems you cannot see patients without (EHR, e-prescribing), Tier 2 you can defer for a day (claims submission, patient portal messaging), Tier 3 you can defer for a week (reporting, analytics). That ranking drives where you spend money on redundancy and which system you restore first.

Your Recovery Time Objective Is a Business Decision, Not an IT Setting

Two numbers control everything else in your HIPAA contingency plan. Recovery Time Objective (RTO) is how long a system can be down before the harm becomes unacceptable. Recovery Point Objective (RPO) is how much data you can afford to lose — the gap between the last good backup and the moment of failure.

If your EHR RPO is 24 hours because backups run nightly, then a Tuesday afternoon failure loses a full day of documentation. Decide whether that is acceptable, in writing, with the physician owners in the room. If it is not, you buy more frequent backups. That decision, documented and dated, is what turns a template into a plan.

HHS proposed significant Security Rule updates in a notice of proposed rulemaking published in January 2025, including more prescriptive contingency and restoration expectations. As of December 2025 that rulemaking is not final, so your obligation remains the current rule text — but practices setting RTOs this year should assume the direction of travel is toward tighter, documented restoration timelines rather than looser ones. You can track the rule text and OCR guidance on the HHS Security Rule page.

Ransomware Turns a Contingency Event Into a Breach Analysis

OCR guidance is clear that a ransomware infection affecting ePHI is presumed to be a reportable breach unless you can demonstrate, through the four-factor risk assessment at 164.402, a low probability that PHI was compromised. Encryption of your data by an attacker counts as an unauthorized acquisition even if nothing left the building.

That means your contingency plan and your breach response procedure have to hand off to each other cleanly. The person restoring systems is not the person doing forensics, and neither of them should be the person deciding what gets reported. Name all three roles in advance. Preserve logs before you rebuild — a restore that overwrites the evidence makes the four-factor analysis unwinnable. HHS maintains practical guidance on this at its cybersecurity guidance hub, and the public record of reported incidents lives on the OCR breach portal.

Your Plan Is Only as Good as Your Vendors' Plans

If your EHR, backup provider, transcription service, or IT managed service provider goes dark, your emergency mode operation plan is the only thing standing. So your contingency planning has to reach into your business associate relationships.

For every vendor touching ePHI, you should be able to answer: What is their committed restoration time? Do they notify you of an incident, and within how many days? Do they hold backups of your data, and can you get an export if the relationship ends abruptly? Are those commitments in the signed agreement, or only on a marketing page?

Many practices discover during a vendor outage that the business associate agreement on file is unsigned, undated, or was never executed with a subcontractor at all. If your vendor list has gaps, closing them is the fastest compliance win available — you can generate a signature-ready business associate agreement through a six-step wizard with PDF and DOCX export, one-time purchase, and get the missing agreements executed this week rather than next quarter.

Testing: Three Formats, One Documentation Standard

Tabletop Exercise — Annual, 90 Minutes

Put the practice administrator, privacy officer, security officer, lead clinician, front-desk supervisor, and IT contact in a room. Read a scenario aloud: "It is 7:15 a.m. Monday. The EHR login page returns an error. The vendor's support line has a 40-minute hold." Work through the first four hours. Write down every gap someone names.

Restore Test — Annual, Per Critical System

Actually restore a backup to an isolated environment and verify the data. Record the date, who performed it, how long it took, what was restored, and whether it matched expectations. This is the single piece of evidence that most distinguishes a real program from a binder.

Downtime Drill — Twice Yearly, 60 Minutes

Run the front desk on paper for one hour during a live clinic session. You will find out immediately whether the forms exist, whether staff know where they are, and whether reconciliation works.

What the Documentation Looks Like

  • Date, duration, and format of the exercise
  • Participants by name and role
  • Scenario used
  • Gaps identified, each with an owner and a target date
  • Plan version number before and after revision
  • Signature or attestation from the security officer

Assigning Ownership So the Plan Survives Turnover

Contingency plans decay when the only person who understood them leaves. Assign by role, never by name alone.

  • Security Officer: owns the plan document, approves revisions, schedules testing, retains records for six years.
  • Practice Administrator: declares an emergency, authorizes emergency mode operation, notifies leadership and patients about schedule changes.
  • IT contact or MSP: executes restores, preserves logs, reports restoration status on a fixed cadence during an incident.
  • Front-Desk Supervisor: distributes downtime forms, maintains the downtime log, owns reconciliation within 48 hours.
  • Privacy Officer: runs the four-factor breach analysis, manages notification timelines if the event becomes reportable.

Print a one-page version of these assignments with phone numbers and store it somewhere that does not require a working network — a laminated card in the med room and a copy in the administrator's car both count.

A 90-Day Build for a Practice Starting From Nothing

Days 1–30: Inventory every system and device that creates, receives, maintains, or transmits ePHI. Rank them into three criticality tiers. Confirm which are actually backed up and pull the last 30 days of backup logs.

Days 31–60: Draft the three required components. Set RTO and RPO for each Tier 1 system with owner sign-off. Build the paper downtime packet and the emergency access procedure. Audit your business associate agreements against the vendor inventory.

Days 61–90: Run one tabletop and one restore test. Revise the plan against what you learned. Train all staff on emergency mode operation and log attendance. File everything with a version number and a review date twelve months out.

Your contingency planning should feed directly from your risk analysis under 164.308(a)(1)(ii)(A) — the criticality tiers and the threat scenarios come from the same source. NIST's SP 800-34 Rev. 1 contingency planning guide is the standard reference for structure, and if you need the risk analysis and supporting policy set generated alongside the plan, automated HIPAA risk analysis and document generation will get you a defensible baseline faster than starting in a blank word processor.

The Evidence Folder

When someone asks for your HIPAA contingency plan — an OCR data request, a cyber insurance underwriter, a health system credentialing your practice — this is what should be in one folder: the signed and dated plan with a version number, the criticality analysis, RTO/RPO decisions with owner approval, the last twelve months of backup verification logs, the most recent restore test record, the most recent tabletop report with its gap list and closure dates, staff training attendance, the emergency access procedure and break-glass usage log, and your current business associate agreements.

If you can produce that folder in an afternoon, you have a program. If you have to reconstruct it, you have a document.

Start with the vendor layer, because it is the fastest to fix and the most commonly deficient. Pull your list of every service that touches ePHI, check which agreements are signed and current, and generate the missing business associate agreements before your next testing cycle — then the contingency plan you write actually rests on commitments someone signed.