HIPAA Security Rule
Administrative

HIPAA Security Rule 164.308(a)(7)(i): Contingency Plan (Standard)

Establish policies for responding to emergencies that damage ePHI systems. NIST recommends contingency planning per SP 800-34 with business impact analysis driving recovery priorities.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 64 controls across 27 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 22301:2019 · 11 controls

  • 4.2.1 General
  • 4.3.1 General
  • 6.1.1 Determining risks and opportunities
  • 8.1 Operational planning and control
  • 8.2.1 General
  • 8.2.2 Business impact analysis
  • 8.4 Business continuity plans and procedures
  • 8.4.1 General
  • 8.4.4 Business continuity plans
  • 8.4.5 Recovery
  • 8.5 Exercise programme

ISO 27001:2022 · 5 controls

  • 5.23 Information security for use of cloud services
  • 5.24 Information security incident management planning and preparation
  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity
  • 8.13 Information backup

NIST SP 800-53 Rev 5 · 5 controls

  • NIST800-CP-1 Policy and procedures for contingency planning
  • NIST800-CP-2 Contingency plan
  • NIST800-PE-23 Facility Location. Plan the location or site of the facility where the system resides considering physical and environmental hazards; and For existing facilities, consider the physical and environmental hazards in the organizational risk management
  • NIST800-SA-17 Developer Security and Privacy Architecture and Design. Require the developer of the system, system component, or system service to produce a design specification and security and privacy architecture that: Is consistent with the organization's
  • NIST800-SA-8 Security and privacy engineering principles
  • NIST-CSF-GV.OC-04 Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
  • NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
  • NIST-CSF-PR.DS-11 Backups of data are created, protected, maintained, and tested
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process

SOC 2 · 4 controls

  • SOC2-A1.3 Recovery plan procedures support system recovery from failures
  • SOC2-CC3.4 COSO principle 9: Identifies and assesses changes that could impact internal controls
  • SOC2-CC5.2 COSO principle 11: Selects and develops general controls over technology
  • SOC2-CC9.1 Identifies, selects and develops risk mitigation activities
  • CFTC-SS-22 Business Continuity and Disaster Recovery Planning Category
  • CFTC-SS-37 Protection of Swap Data Repository Data
  • CFTC-SS-8 Business Continuity and Disaster Recovery Plan and Resources

ISO 27701:2019 · 3 controls

  • 6.11 Systems acquisition, development and maintenance
  • 6.14.1 Information security continuity
  • 6.9 Operations security
  • CPS230-26 Critical Operations Register, Continuity Plan and Activation
  • CPS230-P40 Required Content of the Business Continuity Plan
  • CCM-BCR-01 Business Continuity Management Policy and Procedures
  • CCM-BCR-04 Business Continuity Planning

FedRAMP High · 2 controls

  • CP-1 Policy and Procedures
  • CP-2 Contingency Plan

FedRAMP Moderate · 2 controls

  • CP-1 Policy and Procedures
  • CP-2 Contingency Plan

ISO 27002:2022 · 2 controls

  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity

NIST SP 800-161 Rev 1 · 2 controls

  • CP-1 Policy and Procedures
  • CP-2 Contingency Plan
  • CP-1 Policy and Procedures
  • CP-2 Contingency Plan
  • CP-1 Policy and Procedures
  • CP-2 Contingency Plan
  • ANSSI-HYG-37 Define and Apply a Backup Policy for Critical Components
  • CPS220-P35 Required Content of Risk Management Policies and Procedures

APRA CPS 234 · 1 control

  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • AEO-12 Crisis Management and Incident Recovery
  • ASBv3-GS-8 Define and implement backup and recovery strategy

C5 (Germany) · 1 control

CIS Controls v8 · 1 control

  • CIS-11.1 Establish and Maintain a Data Recovery Process

PCI DSS 4.0 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Administrative

You are reading one control. How much of HIPAA Security Rule have you already done?

HIPAA Security Rule 164.308(a)(7)(i) is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of HIPAA Security Rule your existing evidence covers. Hold ISO 27001:2022 and 53 of 67 HIPAA Security Rule controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 64 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 64 it maps to, and the evidence behind each claim, over MCP and REST.