HIPAA does not treat this as optional. The Security Rule contains a specific contingency plan standard with five implementation specifications, three of which are flatly required. This guide walks each one in the order you should tackle it, so the disaster recovery checklist medical clinic leaders end up with is sequenced rather than scattered.
HIPAA’s contingency plan standard at 45 CFR 164.308(a)(7) requires three things: a data backup plan, a disaster recovery plan, and an emergency mode operation plan. Testing and revision procedures plus an applications and data criticality analysis are addressable, which means flexible in how you implement them, not optional. Work in this order: rank your systems by criticality, set recovery objectives per system, make backups immutable, test restores rather than backups, write downtime procedures, map vendor dependencies, then exercise the plan annually and document every test.
Table of Contents
ToggleWhat HIPAA Actually Requires
The contingency plan standard directs covered entities to establish policies and procedures for responding to an emergency or other occurrence, giving fire, vandalism, system failure, and natural disaster as examples, that damages systems containing electronic protected health information.
Beneath that standard sit five implementation specifications. When HHS finalized the rule, it made testing and revision procedures and the applications and data criticality analysis addressable while requiring the rest.
| Provision | What it requires | Status |
| Data backup plan | Create and maintain retrievable exact copies of ePHI | Required |
| Disaster recovery plan | Restore any loss of data | Required |
| Emergency mode operation plan | Continue critical business processes while protecting ePHI security in emergency mode | Required |
| Testing and revision procedures | Periodically test and revise the contingency plan | Addressable |
| Applications and data criticality analysis | Assess relative criticality of applications and data | Addressable |
One clarification matters here. Addressable does not mean optional. It gives your practice flexibility in how you satisfy the specification based on your size and risk, provided you document the reasoning. Skipping it entirely and writing nothing down is not a compliant choice.
OCR treats missing backups as a substantive failure rather than a technicality. In January 2025, OCR settled with USR Holdings for $337,750 after unauthorized third parties deleted records belonging to 2,903 individuals. Because the entity lacked backup procedures, the data was permanently lost, and OCR cited missing risk analysis, no audit log review, and no retrievable backups.
Step 1: Rank Your Systems by Criticality
Start here, because every later item on your disaster recovery checklist medical clinic planning depends on it. List every system the practice depends on, then rank each by how quickly its absence stops patient care.
For most clinics the top tier is short: the EHR, the practice management and scheduling system, e-prescribing, lab and imaging interfaces, and the phone system. Second tier usually includes billing, payroll, and reporting. Third tier covers marketing and internal file shares.
Do not limit this to systems that touch protected health information. A phone system holds no records but stops a clinic cold, and a door access controller can prevent staff from reaching the building.
Write the ranking down with a named owner per system, the vendor, the support contact, and the license or account details you would need during a rebuild. That single document saves hours during a real event.
Step 2: Set Recovery Objectives Per System
Two numbers matter per system. Recovery time objective is how long you can function without it. Recovery point objective is how much data you can afford to lose, which in practice means how far back your last usable backup sits.
Any useful disaster recovery checklist medical clinic managers maintain sets these per system rather than for the practice as a whole. A four hour objective for the EHR and a one week objective for marketing files are both reasonable, and pretending they are the same wastes money on one and leaves you exposed on the other.
Be realistic about the consequences of getting this wrong. Healthcare ransomware attacks produce an average of more than 17 days of downtime (Comparitech, 2024). If your plan assumes two days, it is not a plan.
Our post on EHR downtime cost for clinics walks through translating those objectives into dollars, which is usually what unlocks the budget conversation.
Step 3: Build a Clinic Backup Plan Attackers Cannot Reach
A clinic backup plan that a ransomware operator can encrypt is not a backup plan. It is the single most common technical failure we find, and it undoes every other item on the list.
The threat is well documented. Backup repositories were targeted in 96% of attacks and successfully compromised in 76% of those cases (Veeam, 2024 Ransomware Trends Report). Attackers go after backups first precisely because doing so removes your leverage.
The answer is immutability and separation. Keep at least three copies of data on two different media with one copy off site and one offline or immutable, encrypt backups at rest and in transit, and use credentials for the backup system that are separate from your domain administrator accounts.
Worryingly, the trend is moving the wrong direction. Backup use among healthcare providers fell to 51% from 72% year over year (Sophos, State of Ransomware in Healthcare 2025). Practices that can restore hold a decisive advantage, since 58% of healthcare providers recovered within a week in 2025 while mean recovery costs excluding any ransom still reached roughly $1.02 million (Sophos, 2025). Our disaster recovery service exists to make that restoration path real rather than theoretical.
Step 4: Test Restores, Not Backups
A green dashboard tells you a job completed. It does not tell you the data is usable, complete, or restorable inside your recovery objective.
Test the restore instead, because this is the step that separates a real disaster recovery checklist medical clinic teams can rely on from a paper exercise. Pick a sample each quarter that includes patient charts, imaging studies, and billing records, restore them to an isolated environment, and have a clinical or billing staff member confirm the records are readable and correct. Time the restore and compare it against the objective you set in Step 2.
Document each test with the date, what you restored, how long it took, who verified it, and what failed. Those records are the evidence OCR asks for, and they are what turn an addressable specification into a defensible one.
Include at least one full system rebuild in your annual cycle rather than only file-level restores. Recovering a single chart proves very little about recovering an EHR server.
Step 5: Write the Emergency Mode Operation Plan
This is the specification practices skip most often, and it is required. Emergency mode operation covers how you keep delivering care and protecting ePHI while systems are down.
Medical Practice Business Continuity Starts With Paper
Build the packet before you need it. That means printed downtime forms for intake, vitals, orders, and prescriptions, a paper schedule for the next 48 hours generated on a rolling basis, printed contact lists for referring providers and labs, a documented process for verifying patient identity without the EHR, and clear instructions for reconciling paper records back into the system afterward.
Medical practice business continuity planning has to address security explicitly here, because the requirement covers protecting ePHI in emergency mode, not just continuing operations. Define where paper records are stored during the outage, who has access, and how they are tracked and destroyed after reconciliation.
Store the packet in more than one location, including one that does not depend on your network. A plan that lives only on the file server you just lost is not available when it matters.
Step 6: Map Vendor Dependencies and Notification Duties
Most clinics now depend on outside platforms for the systems they cannot lose. That makes vendor mapping part of medical practice business continuity rather than a procurement detail.
The exposure is measurable. Third-party involvement in breaches doubled year over year and now accounts for 30% of all breaches (Verizon, 2025 Data Breach Investigations Report). Your EHR host, backup provider, clearinghouse, and imaging vendor each represent a path to downtime you do not control.
For each vendor, record the support number and escalation path, their committed recovery objectives, whether a business associate agreement is in place, and what they are contractually obliged to tell you and how fast. Then confirm you know which party restores what, because assuming your cloud EHR vendor keeps recoverable backups on your behalf is a common and expensive mistake.
Ask each vendor directly whether they have tested their own recovery in the last twelve months, and keep the answer. Our cloud services team reviews these dependencies as part of onboarding.
Step 7: Exercise the Plan and Revise It
Building a Disaster Recovery Checklist Medical Clinic Staff Will Use
An untested plan is a document, not a capability, and a disaster recovery checklist medical clinic staff have never rehearsed will not survive contact with a real outage. Run a tabletop exercise at least annually with the people who would actually execute it, including front desk staff, a clinician, billing, and whoever holds the vendor relationships.
Use realistic scenarios: ransomware encrypting the EHR and the backup server, a multi-day power or internet outage, a cloud vendor outage lasting 24 hours, and a departing employee who held the only credentials to a critical system. Walk each one to the point where somebody has to make a decision.
Capture what broke in the exercise and assign owners with dates, then fold the findings back into your clinic backup plan and downtime packet. The revision half of the specification is what most practices miss, and unclosed findings are worse than no exercise at all because they document a known gap.
Pair the exercise with your incident response plan so the two documents reference each other. Recovery and response are the same event from different angles, and medical practice business continuity depends on both.
The Disaster Recovery Checklist Medical Clinic Teams Can Start Today
The Healthcare DR Checklist
Use this version to assign owners and track completion.
| Step | Action | Evidence to keep |
| 1 | Rank every system by criticality with a named owner | Signed criticality list with vendors and contacts |
| 2 | Set RTO and RPO per system | Objectives table approved by leadership |
| 3 | Make backups immutable and separated, three copies across two media | Backup configuration export and encryption confirmation |
| 4 | Restore a sample quarterly and verify readability | Dated restore logs with verifier name and duration |
| 5 | Assemble printed downtime packet in two locations | Packet inventory and reconciliation procedure |
| 6 | Map vendors, objectives, BAAs, and notification duties | Vendor register with escalation paths |
| 7 | Run an annual tabletop and close findings | Exercise notes and remediation tracker |
| Ongoing | Review after any staffing, vendor, or system change | Change log with review dates |
Two items on this list cost nothing and surface problems immediately: attempt one restore this week, and check whether your backup system uses credentials separate from your domain administrator account. Start there.
Practices without internal IT capacity usually need help sustaining steps three, four, and seven, which is what ongoing managed IT support covers for our small practices and medical clinics.
What the Proposed Security Rule Would Change
HHS published a notice of proposed rulemaking in January 2025 that would tighten contingency planning considerably. Under the proposal, regulated entities would establish written procedures to restore the loss of certain relevant electronic information systems and data within 72 hours, perform a criticality analysis to determine restoration priority, and review and test contingency plans at least every twelve months (HHS OCR, NPRM fact sheet).
The proposal also extends criticality analysis beyond systems that handle ePHI, adds a 24 hour requirement for business associates to notify covered entities upon activating their contingency plans, and would remove the required versus addressable distinction so that specifications become mandatory with limited exceptions.
Correct a common misreading while you are at it. The proposed 72 hour figure is a restoration target, not a breach notification deadline. The existing 60 day notification requirement is unchanged.
This rule is not final. The timeline has slipped more than once, so treat it as a direction of travel rather than a current obligation, and note that a practice already doing Steps 1 through 7 is largely aligned with it. We track the status in our HIPAA Security Rule update analysis, and our HIPAA compliance work maps each specification to documented evidence.
Note Worthy Info
- Three specifications are required, not addressable. Data backup plan, disaster recovery plan, and emergency mode operation plan under 164.308(a)(7)(ii)(A) through (C).
- Addressable does not mean optional. It permits flexibility in how you implement, with documented reasoning.
- Missing backups draw penalties. OCR settled with USR Holdings for $337,750 where deleted records were permanently lost for lack of backup procedures (HHS OCR, January 2025).
- Attackers target backups first. Backup repositories were hit in 96% of attacks and compromised in 76% of those (Veeam, 2024).
- Backup adoption is falling. Healthcare backup use dropped to 51% from 72% year over year (Sophos, 2025).
- Plan for weeks, not days. Healthcare ransomware downtime averages more than 17 days (Comparitech, 2024).
- Vendors are a third of the risk. Third-party involvement now accounts for 30% of breaches (Verizon, 2025 DBIR).
- A healthcare DR checklist is only as good as its last test. Unclosed findings document a known gap.
- A green backup dashboard proves nothing. Only a timed, verified restore does.
Frequently Asked Questions
- What has to be in a disaster recovery checklist medical clinic teams can defend to an auditor?
At minimum, evidence for each of the five contingency plan specifications: a documented data backup plan, a written disaster recovery plan with restoration procedures, an emergency mode operation plan covering downtime workflows, dated records of testing and revision, and a criticality analysis ranking your applications and data. Documentation matters as much as capability, because OCR reviews what you can produce.
- How often should a clinic test its backups?
Restore a sample at least quarterly and include a full system rebuild annually. File-level restores prove very little about recovering a server, and the proposed Security Rule updates point toward monthly backup and restoration testing, so quarterly is a defensible current floor rather than a ceiling.
- Does our cloud EHR vendor handle disaster recovery for us?
Partly, and never entirely. Vendors typically protect their own infrastructure while you remain responsible for configuration, user access, exported data, and everything outside their platform. Confirm in writing what they back up, their recovery objectives, and how quickly they must notify you, then plan for the gap.
- What is the difference between a disaster recovery plan and a business continuity plan?
Disaster recovery covers restoring technology and data. Medical practice business continuity is broader, covering how the clinic keeps seeing patients during the outage, including staffing, paper workflows, and communication. HIPAA’s emergency mode operation plan sits in that broader category and is required.
- What recovery time objective should a small clinic set for its EHR?
Most practices land between four and twenty four hours for the EHR based on patient volume and how much care depends on chart access. Set it from clinical consequence rather than from what your current tooling happens to deliver, then close the gap between the two deliberately.
- Does the proposed HIPAA rule require us to restore everything within 72 hours?
No. The proposal would require written procedures to restore critical relevant electronic information systems and data within 72 hours, with other systems restored according to your criticality analysis. It is also still a proposal rather than a final rule, and the 72 hour figure is not a breach notification deadline.
- We are a two provider practice with no IT staff. Where do we start?
Do three things this month. Write the criticality list, attempt one restore and time it, and print a downtime packet. Those steps require no purchase, satisfy the beginning of three specifications, and reveal whether your existing backups actually work.
The Bottom Line
A disaster recovery checklist medical clinic teams can sustain is not a product you buy once. It is a short set of habits: knowing which systems stop care, knowing how fast each must return, keeping backups attackers cannot touch, proving restores work, and having paper ready when screens go dark.
Practices that work through these seven steps end up with something better than compliance. They end up able to keep seeing patients on the worst day of the year, which is the only real test any of this has to pass.
Use the disaster recovery checklist medical clinic teams can act on above, start with the restore test, and close one gap at a time. If you would rather have someone verify your recovery path before you need it, request a free risk assessment and we will test it with you.
About SecTec
SecTec is a managed security services provider based in McLean, Virginia, serving medical clinics, community health organizations, nonprofits, and faith based organizations across Virginia, Maryland, and the Washington DC region. Our team builds and operates client security programs, conducts HIPAA risk analysis and contingency plan reviews, runs restore testing and tabletop exercises, and monitors endpoint and network defense across our client portfolio using NinjaOne and SentinelOne. Every article in our Medical Clinic IT series is written and reviewed by the practitioners who do this work daily.
Sources reviewed for this article: 45 CFR 164.308(a)(7) and the HIPAA Security Rule final rule preamble regarding required and addressable implementation specifications; HHS Office for Civil Rights, HIPAA Security Rule Notice of Proposed Rulemaking fact sheet, December 2024, published January 6, 2025; HHS OCR enforcement announcement, USR Holdings settlement, January 2025; Veeam, 2024 Ransomware Trends Report; Sophos, The State of Ransomware in Healthcare 2025; Verizon, 2025 Data Breach Investigations Report; Comparitech ransomware downtime research, December 2024.
SecTec helps practices turn a disaster recovery checklist medical clinic teams can follow into tested, documented capability.


