HIPAA Security Rule
Administrative

HIPAA Security Rule 164.308(a)(7)(i): Contingency Plan (Standard)

Establish policies for responding to emergencies that damage ePHI systems. NIST recommends contingency planning per SP 800-34 with business impact analysis driving recovery priorities.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 58 controls across 24 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 22301:2019 · 11 controls

  • 4.2.1 General
  • 4.3.1 General
  • 6.1.1 Determining risks and opportunities
  • 8.1 Operational planning and control
  • 8.2.1 General
  • 8.2.2 Business impact analysis
  • 8.4 Business continuity plans and procedures
  • 8.4.1 General
  • 8.4.4 Business continuity plans
  • 8.4.5 Recovery
  • 8.5 Exercise programme

ISO 27001:2022 · 5 controls

  • 5.23 Information security for use of cloud services
  • 5.24 Information security incident management planning and preparation 
  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity
  • 8.13 Information backup

NIST SP 800-53 Rev 5 · 5 controls

  • NIST-CSF-GV.OC-04 Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
  • NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
  • NIST-CSF-PR.DS-11 Backups of data are created, protected, maintained, and tested
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process

SOC 2 · 4 controls

  • SOC2-A1.3 A1.3 Testing recovery plan procedures
  • SOC2-CC3.4 CC3.4 Identifying and assessing significant changes (COSO principle 9)
  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC9.1 CC9.1 Mitigating risks of business disruption
  • CFTC-SS-22 Business Continuity and Disaster Recovery Planning Category
  • CFTC-SS-37 Protection of Swap Data Repository Data
  • CFTC-SS-8 Business Continuity and Disaster Recovery Plan and Resources

ISO 27701:2019 · 3 controls

  • 6.11 Systems acquisition, development and maintenance
  • 6.14.1 Information security continuity
  • 6.9 Operations security
  • CPS230-26 Critical Operations Register, Continuity Plan and Activation
  • CPS230-P40 Required Content of the Business Continuity Plan
  • CCM-BCR-01 Business Continuity Management Policy and Procedures
  • CCM-BCR-04 Business Continuity Planning

FedRAMP High · 2 controls

  • CP-1 Policy and Procedures
  • CP-2 Contingency Plan

FedRAMP Moderate · 2 controls

  • CP-1 Policy and Procedures
  • CP-2 Contingency Plan

ISO 27002:2022 · 2 controls

  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity

NIST SP 800-161 Rev 1 · 2 controls

  • E8-BACKUP-ML1 Regular Backups (ML1)
  • ANSSI-HYG-37 Define and Apply a Backup Policy for Critical Components
  • CPS220-P35 Required Content of Risk Management Policies and Procedures

APRA CPS 234 · 1 control

  • CPS234-P24 Information Security Response Plans
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • AEO-12 Crisis Management and Incident Recovery
  • ASBv3-GS-8 Define and implement backup and recovery strategy

C5 (Germany) · 1 control

CIS Controls v8 · 1 control

  • CIS-11.1 Establish and Maintain a Data Recovery Process

PCI DSS 4.0 · 1 control

  • 12.10.1 12.10.1 Incident response plan ready for activation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Administrative

You are reading one control. How much of HIPAA Security Rule have you already done?

HIPAA Security Rule 164.308(a)(7)(i) is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of HIPAA Security Rule your existing evidence covers. Hold ISO 27001:2022 and 53 of 67 HIPAA Security Rule controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 64 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 58 it maps to, and the evidence behind each claim, over MCP and REST.