Skip to content

The HIPAA contingency plan

By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · HIPAA

HIPAA's contingency plan is BC/DR for health data, with one part the law makes non-negotiable: you must back up ePHI and be able to restore it.

What it requires

The contingency plan standard (an administrative safeguard) requires you to prepare for events that damage systems holding ePHI. It has several parts: a data backup plan and a disaster recovery plan (both required), emergency-mode operation, and — addressable — testing/revision and an applications-and-data criticality analysis.

Backups you can restore

The required core is straightforward but load-bearing: you must back up ePHI and be able to recover it. As with any BC/DR, an untested backup is a hope — restore-testing is what proves the plan works, and while testing is "addressable," it is hard to argue a disaster recovery plan you have never exercised is reasonable.

Emergency-mode operation

Emergency-mode operation asks how you continue critical processes that protect ePHI during an emergency — degraded but functioning. For most SaaS this folds into the same incident and continuity planning you already have, scoped to the ePHI systems.

Reuse your BC/DR

The HIPAA contingency plan maps almost one-to-one onto SOC 2 / ISO 27001 business continuity and backup controls — build it once and credit it across frameworks, scoped to ePHI. SentinelPanda tracks the contingency/BC-DR controls and the restore-test evidence.

Business continuity and disaster recovery for SOC 2 HIPAA administrative safeguards

Run your compliance program in one workspace.