Health Information Management

Why is disaster recovery a proposed security requirement?

HIPAA Weekly Advisor, November 21, 2001

Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!

Q: The proposed HIPAA security requirements mention disaster recovery. I thought disaster recovery dealt with the aftermath of earthquakes or fires. Why is it a proposed requirement of HIPAA and what do we have to do to comply?

A: Disaster recovery is part of the business continuity process. Generally, businesses and health care organizations back up their data and computer systems and rarely lose sleep over it.

But every business should have a business continuity process in place for events more serious than a simple power outage. Not only are contingency plans and a process for disaster recovery part of the HIPAA security notice of proposed rules making (NPRM) under administrative procedures, but they simply make good business sense.

Disaster recovery includes a number of processes and components depending on the size and complexity of the information technology infrastructure.

Since the Administrative Simplification Act requires an increasing shift to the electronic processing of health records, health care organizations need to guarantee that the data and information systems are protected in the event of a disaster. Because of the potential destruction of vital patient and financial data, and the potential risk involved, organizations need to develop a disaster plan. It usually requires a data backup process and off-site data storage, mobile phone units, and remote workstations.

Some vendors even provide mirroring capability for your Web site or a hot site that operates when your central servers do not. Mirroring guarantees constant data access and integrity in the event of a disaster. For example, data storage company EMC2 (http://www.emc.com) replicates information as it is created and stores the data in multiple locations. Since it is protected off-site, it can be available in a system outage.

To read the rest of this answer, go to http://www.hipaapro.com/content.cfm?content_id=16093



Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!

  • Briefings on APCs

    Worried about the complexities of the new rules under OPPS and APCs? Briefings on APCs helps you understand the new rules...

  • Medical Records Briefing

    Guiding Health Information Management professionals through the continuously changing field of medical records and toward a...

  • Briefings on Coding Compliance Strategies

    Submitting improper Medicare documentaion can lead to denial of fees, payback, fines, and increased diligence from payers...

  • Briefings on HIPAA

    How can you minimize the impact of HIPAA? Subscribe to Briefings on HIPAA, your health information management resource for...

  • APCs Weekly Monitor

    This HTML-based e-mail newsletter provides weekly tips and advice on the new ambulatory payment classifications regulations...

Most Popular

Related Articles