Contingency Emergency Mode Operation Plan Policies, v1.0

Specifies that a health care related organization must have policies to enable continuation of critical business processes for protection of the security of electronic protected health information while operating in emergency mode.

Assessment Step

1
Policies for Continuation (PoliciesforContinuation)
Does the covered entity or business associate have policies to enable continuation of critical business processes for protection of the security of electronic protected health information while operating in emergency mode?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
A covered entity or business associate must perform these requirements in accordance with Section 164.306 (Security standards: General rules).

Conformance Criteria (1)

Policies for Continuation
The covered entity or business associate must have policies to enable continuation of critical business processes for protection of the security of electronic protected health information while operating in emergency mode.
Citations
HIPAA-Security-Rule
45 CFR Section 164.308(a)(7)(ii)
HIPAA-Security-Rule
45 CFR Section 164.306