11.1 Contingency Planning Frameworks: Business Impact Analysis (BIA) and Emergency Mode Operations

Key Takeaways

  • Under 45 CFR § 164.308(a)(7)(i), covered entities and business associates must establish and implement policies and procedures for responding to an emergency or other occurrence (including fire, vandalism, system failure, or natural disaster) that damages systems containing electronic protected health information (ePHI).
  • The HIPAA Contingency Plan standard comprises three statutory Required implementation specifications—Data Backup Plan (§ 164.308(a)(7)(ii)(A)), Disaster Recovery Plan (§ 164.308(a)(7)(ii)(B)), and Emergency Mode Operation Plan (§ 164.308(a)(7)(ii)(C))—and two statutory Addressable specifications—Testing and Revision Procedures (§ 164.308(a)(7)(ii)(D)) and Applications and Data Criticality Analysis (§ 164.308(a)(7)(ii)(E)).
  • A healthcare Business Impact Analysis (BIA), aligned with NIST SP 800-34 Rev. 1, identifies critical clinical, financial, legal, and operational workflows to determine Maximum Tolerable Downtime (MTD) and map system dependencies before catastrophic disruption occurs.
  • An Emergency Mode Operations Plan (EMOP) under 45 CFR § 164.308(a)(7)(ii)(C) must enable the continuation of critical patient care processes while maintaining the confidentiality, integrity, and availability of ePHI during utility failures, natural disasters, or cyberattacks.
  • The HIPAA Privacy and Security Rules remain legally binding during emergencies; Section 1135 waivers issued under the Social Security Act provide only narrow, time-limited relief (up to 72 hours) from specific administrative sanctions during presidential declarations and do not suspend general privacy or security protections.
Last updated: September 2026

Contingency Planning Frameworks: Business Impact Analysis (BIA) and Emergency Mode Operations

In modern healthcare delivery, an unexpected operational disruption—whether caused by a sophisticated ransomware outbreak, prolonged electrical grid collapse, catastrophic hurricane, or internal hardware failure—poses an immediate and existential threat to patient safety, clinical integrity, and regulatory compliance. Unlike traditional commercial enterprises where downtime primarily results in delayed revenue, downtime in a hospital or health system directly impacts patient morbidity and mortality. Clinical teams cut off from electronic health records (EHR), picture archiving and communication systems (PACS), laboratory information systems (LIS), and computer provider order entry (CPOE) cannot review critical drug allergies, retrieve active medication administration records, or evaluate urgent diagnostic imaging.

To ensure that healthcare organizations can withstand catastrophic events while rigorously safeguarding patient privacy and data integrity, the HIPAA Security Rule (45 CFR Part 164, Subpart C) establishes the Contingency Plan standard at 45 CFR § 164.308(a)(7)(i). For the AHIMA CHPS candidate, contingency planning requires deep mastery of the legal specifications, the methodology of the Business Impact Analysis (BIA), the calculation of operational metrics, and the practical execution of emergency mode operations.


Statutory Framework: 45 CFR § 164.308(a)(7)

The Contingency Plan standard is codified as an administrative safeguard under 45 CFR § 164.308(a)(7)(i):

"Standard: Contingency plan. Establish (and implement as needed) policies and procedures for responding to an emergency or other occurrence (for example, fire, vandalism, system failure, and natural disaster) that damages systems that contain electronic protected health information."

The standard is broken down into five distinct implementation specifications under 45 CFR § 164.308(a)(7)(ii). A frequent area of testing on the CHPS exam is the precise statutory classification of each specification as either Required or Addressable.

Implementation SpecificationStatutory CitationClassificationCore Regulatory Requirement
Data Backup Plan45 CFR § 164.308(a)(7)(ii)(A)RequiredEstablish and implement procedures to create and maintain retrievable exact copies of electronic protected health information (ePHI).
Disaster Recovery Plan45 CFR § 164.308(a)(7)(ii)(B)RequiredEstablish (and implement as needed) procedures to restore any loss of data resulting from an emergency or disaster.
Emergency Mode Operation Plan45 CFR § 164.308(a)(7)(ii)(C)RequiredEstablish (and implement as needed) procedures to enable continuation of critical business processes for protection of the security of ePHI while operating in emergency mode.
Testing and Revision Procedures45 CFR § 164.308(a)(7)(ii)(D)AddressableImplement procedures for periodic testing and revision of contingency plans to ensure their operational effectiveness.
Applications and Data Criticality Analysis45 CFR § 164.308(a)(7)(ii)(E)AddressableAssess the relative criticality of specific applications and data in support of other contingency plan components.

The Interdependence of Required and Addressable Specifications

A critical legal insight for healthcare compliance leaders is that while Applications and Data Criticality Analysis (§ 164.308(a)(7)(ii)(E)) is statutorily classified as addressable, an organization cannot successfully design or execute the required specifications without it. Under 45 CFR § 164.306(d)(3), an addressable specification must be implemented unless the entity formally determines that it is not reasonable and appropriate and implements an equivalent alternative measure.

In practice, HHS Office for Civil Rights (OCR) enforcement actions make clear that an organization cannot create an effective Data Backup Plan, Disaster Recovery Plan, or Emergency Mode Operation Plan without first identifying which applications and data sets are mission-critical. Discarding the criticality analysis because it is labeled addressable is viewed by regulators as a failure of basic risk analysis under 45 CFR § 164.308(a)(1)(ii)(A).


Business Impact Analysis (BIA) Methodology in Healthcare

While HIPAA mandates an applications and data criticality analysis, the operational methodology used across the healthcare sector is the Business Impact Analysis (BIA), standardized by the National Institute of Standards and Technology (NIST) Special Publication 800-34 Revision 1 (Contingency Planning Guide for Federal Information Systems).

The BIA is an objective, systematic evaluation designed to correlate specific system components with the critical clinical and business services they support, quantifying the consequences of a disruption across four primary impact categories:

  1. Clinical & Life-Safety Impact: Direct risk of patient harm, morbidity, mortality, delayed emergency interventions, medication errors, and compromised surgical workflows.
  2. Regulatory & Legal Impact: Non-compliance with HIPAA Security/Privacy Rules, EMTALA (Emergency Medical Treatment and Labor Act), Medicare Conditions of Participation, state medical record retention laws, and accreditation mandates (e.g., The Joint Commission).
  3. Financial Impact: Lost billing revenue, cash flow interruption, cancelled elective procedures, diverted ambulances, forensic remediation expenses, extortion demands, and regulatory fines.
  4. Operational & Reputational Impact: Disruption to admissions, patient transfers, pharmacy dispensing, supply chain logistics, staff burnout, and loss of community trust.
NIST SP 800-34 Rev. 1 Business Impact Analysis (BIA) Process Flow:

   ┌─────────────────────────────────────────────────────────────┐
   │ STEP 1: Identify Clinical & Business Processes              │
   │ (ICU, Pharmacy, ED Triage, Inpatient Charting, PACS Imaging)│
   └──────────────────────────────┬──────────────────────────────┘
                                  │
                                  ▼
   ┌─────────────────────────────────────────────────────────────┐
   │ STEP 2: Map Infrastructure & System Dependencies            │
   │ (EHR Database, Active Directory/DNS, SAN Storage, WAN Links)│
   └──────────────────────────────┬──────────────────────────────┘
                                  │
                                  ▼
   ┌─────────────────────────────────────────────────────────────┐
   │ STEP 3: Quantify Disruption Impacts Over Time               │
   │ (Assess harm at 1 hr, 4 hrs, 24 hrs, 72 hrs, 7+ days)      │
   └──────────────────────────────┬──────────────────────────────┘
                                  │
                                  ▼
   ┌─────────────────────────────────────────────────────────────┐
   │ STEP 4: Establish Recovery Metrics & Tiers                  │
   │ (Calculate MTD, Define RTO / RPO, Prioritize Restoration)   │
   └─────────────────────────────────────────────────────────────┘

The Concept of Maximum Tolerable Downtime (MTD)

A foundational metric derived during the BIA is the Maximum Tolerable Downtime (MTD), also referred to as the Maximum Allowable Outage (MAO).

Maximum Tolerable Downtime (MTD): The absolute maximum threshold of time that a critical business or clinical process can remain non-functional before irreversible degradation, catastrophic financial collapse, widespread regulatory sanction, or unacceptable patient injury/loss of life occurs.

MTD establishes the outer boundary within which all recovery strategies must operate. If an acute care trauma hospital determines that its inpatient CPOE and pharmacy dispensing system has an MTD of 4 hours, any recovery strategy that requires 8 hours to restore the database is legally and clinically deficient.

System Tiering Based on Criticality

Following the BIA, healthcare systems classify applications into structured recovery tiers:

  • Tier 0 (Mission-Critical / Life-Safety): MTD < 2 hours. Telemetry monitoring, emergency department triage, PACS imaging for acute stroke, CPOE, pharmacy dispensing, identity and access management (Active Directory).
  • Tier 1 (Core Clinical & Business): MTD 2–12 hours. General inpatient documentation, outpatient scheduling, lab result interfaces, blood bank verification.
  • Tier 2 (Operational Support): MTD 12–48 hours. Revenue cycle management, billing and claims processing, release of information (ROI) workflows, electronic supply chain ordering.
  • Tier 3 (Administrative / Non-Urgent): MTD > 48 hours. Historical research archives, staff education portals, internal intranet, general accounting.

Emergency Mode Operations Plan (EMOP)

Codified at 45 CFR § 164.308(a)(7)(ii)(C), the Emergency Mode Operation Plan (EMOP) is a mandatory implementation specification requiring organizations to establish procedures that enable the continuation of critical business processes for the protection of the security of ePHI while operating in emergency mode.

While a Disaster Recovery Plan focuses on technical restoration of IT systems and data, the EMOP governs how the enterprise actually delivers healthcare and protects data while the primary IT environment is dead or compromised.

Threat Vectors Triggering EMOP

An EMOP must address varied disruption scenarios:

  1. Advanced Cyberattacks (Ransomware Outbreaks): Hostile encryption of network storage, Active Directory compromise, or deliberate containment isolation where IT disconnects the hospital from the Internet and isolates internal network segments.
  2. Physical and Environmental Disasters: Hurricanes, catastrophic flooding, earthquakes, structural fires, or tornadoes damaging on-premise data centers.
  3. Utility and Critical Infrastructure Failures: Long-duration commercial power grid loss, emergency generator mechanical failure, municipal water outages (affecting HVAC chiller cooling in server rooms), or metropolitan fiber optic severance.

Maintaining the Security Rule Safeguards During Emergency Mode

A critical misconception among healthcare staff is that when an emergency is declared, information security and privacy rules are suspended. Under the HIPAA Security Rule, safeguards must be maintained during emergency mode operations:

Safeguard Maintenance Framework During Emergency Operations:

                           EMERGENCY MODE DECLARED
                         (Primary EHR / Network Down)
                                      │
      ┌───────────────────────────────┼───────────────────────────────┐
      ▼                               ▼                               ▼
ADMINISTRATIVE SAFEGUARDS       PHYSICAL SAFEGUARDS             TECHNICAL SAFEGUARDS
- Incident Command Activation   - Secured Paper Chart Storage   - Hardened Offline Laptops
- Reassigned Staff Roles        - Clean Desk / Private Areas    - Break-Glass Accounts
- Minimum Necessary Protocols   - Perimeter Access Control      - Mandatory Audit Logging
- Daily Executive Briefings     - Escorted Visitor Policies     - Network Egress Severed

1. Administrative Safeguards in Emergency Mode

  • Incident Command System (ICS): Activation of the Hospital Incident Command System (HICS). The Privacy Officer and Information Security Officer must sit within the Command Staff to provide real-time guidance on data flows, disclosures, and technical risks.
  • Workforce Reassignment & Verification: Administrative procedures to reassign clinical staff to manual data entry, paper charting runners, or physical couriers while maintaining role-based verification.
  • Emergency Disclosures: Policies governing how clinical staff disclose patient status during a mass casualty or disaster scenario under 45 CFR § 164.510(b)(3) (disclosures for disaster relief purposes) and 45 CFR § 164.512(j) (averting a serious and imminent threat to health or safety).

2. Physical Safeguards in Emergency Mode

  • Paper and Shadow Chart Protection: When clinical systems fail, staff revert to manual paper downtime packets, printed medication sheets, and paper diagnostic requisitions. Under 45 CFR § 164.310, these physical documents represent PHI and must be protected against unauthorized snooping, theft, or exposure. They must be stored in staffed nursing stations, placed in closed chart holders, and transferred between departments in sealed, opaque envelopes.
  • Facility Perimeter Security: During physical disasters (e.g., storms or facility evacuation), physical access controls must prevent unauthorized third parties (media, curious public, unauthorized family) from entering triage zones where paper medical charts are displayed.

3. Technical Safeguards in Emergency Mode

  • Hardened Standalone Workstations: Deployment of pre-configured, encrypted downtime PCs that contain localized, read-only copies of active inpatient summaries. These workstations must utilize local full-disk encryption (BitLocker/FileVault) and restrict unauthorized USB data export.
  • Break-Glass Emergency Accounts: If auxiliary systems remain operational but standard single sign-on (SSO) or multi-factor authentication (MFA) gateways are disabled due to network severance, staff utilize pre-staged "break-glass" emergency accounts. These credentials must generate auditable system logs that are systematically reviewed post-incident under 45 CFR § 164.312(b).

Disaster Declarations and Section 1135 Waivers

A perennial high-difficulty topic on the CHPS examination involves the legal boundaries of Section 1135 Waivers under the Social Security Act.

When the President declares a national emergency or major disaster under the Stafford Act or the National Emergencies Act, and the Secretary of Health and Human Services (HHS) declares a Public Health Emergency (PHE) under Section 319 of the Public Health Service Act, the Secretary is authorized under Section 1135 of the Social Security Act to temporarily waive or modify certain healthcare legal mandates.

The Strict Scope of Section 1135 HIPAA Waivers

Candidates must understand that a Section 1135 waiver does NOT waive HIPAA in its entirety. The Secretary's waiver authority applies strictly to specific administrative sanctions under the HIPAA Privacy Rule, and ONLY if the following strict legal conditions are met:

  1. The hospital must be located in the designated emergency area.
  2. The hospital must have implemented its formal Emergency Mode Operations Plan.
  3. The waiver is effective for a maximum duration of 72 hours from the time the hospital implements its EMOP.

Furthermore, the waiver applies strictly to five specific Privacy Rule provisions:

  • The requirement to obtain a patient's consent to speak with family members or friends involved in the patient's care (45 CFR § 164.510(b)).
  • The requirement to honor a patient's request to opt out of the facility directory (45 CFR § 164.510(a)).
  • The requirement to distribute a Notice of Privacy Practices (NPP) (45 CFR § 164.520).
  • The patient's right to request privacy restrictions on uses and disclosures (45 CFR § 164.522(a)).
  • The patient's right to request confidential communications (45 CFR § 164.522(b)).

[!CRITICAL] The Security Rule is NEVER Waived: Neither the President, the HHS Secretary, nor OCR possesses statutory authority under Section 1135 to waive the HIPAA Security Rule (45 CFR Part 164, Subpart C). Covered entities must maintain the administrative, physical, and technical safeguards of ePHI throughout any emergency or disaster. Claims that "HIPAA was suspended during the hurricane" are legally false and constitute an immediate failure on the CHPS exam.


CHPS Exam Tips and Common Traps

[!TIP] Exam Tip: Required vs. Addressable Classifications Commit the classifications in 45 CFR § 164.308(a)(7)(ii) to memory: Data Backup (Required), Disaster Recovery (Required), Emergency Mode Operations (Required). Testing and Revision (Addressable) and Applications/Data Criticality Analysis (Addressable). If a question asks which contingency plan component is statutorily addressable, look for Testing/Revision or Criticality Analysis.

[!WARNING] Candidate Trap: Addressable Does Not Permit Inaction When an exam scenario presents an organization that abandoned its Applications and Data Criticality Analysis because it is "only addressable," recognize this as non-compliance. An addressable specification requires formal risk assessment and documentation. Without criticality analysis, an organization cannot substantiate that its backup and recovery plans are reasonable and appropriate.

[!CAUTION] Candidate Trap: Paper Chart Privacy in Disasters When an EHR goes dark and hospital units transition to paper charts, the HIPAA Privacy Rule still governs every paper record. Leaving paper charts unattended at nursing station counters, in hallways, or within sight of visitors violates 45 CFR § 164.530(c) (Physical Safeguards for Privacy). Emergency operations demand intensified physical privacy vigilance.

Loading diagram...
HIPAA Contingency Planning Architecture, BIA Workflow, and Statutory Specifications
Test Your Knowledge

A regional hospital compliance team is reviewing its HIPAA Security Rule policies following an internal audit. The audit highlights that the hospital maintains formal policies for its Data Backup Plan, Disaster Recovery Plan, and Emergency Mode Operation Plan, but lacks formal documentation for its Applications and Data Criticality Analysis. The Chief Information Officer (CIO) argues that because criticality analysis is classified as an 'addressable' implementation specification under 45 CFR § 164.308(a)(7)(ii)(E), the hospital is legally permitted to omit it without consequence. How should the Chief Privacy and Security Officer evaluate this position?

A
B
C
D
Test Your Knowledge

During a comprehensive Business Impact Analysis (BIA) aligned with NIST SP 800-34 Rev. 1, an acute care hospital's clinical and IT disaster planning committee analyzes the computerized provider order entry (CPOE) and inpatient pharmacy dispensing systems. The committee determines that manual paper workarounds can sustain patient safety for a maximum of 3 hours, beyond which medication verification delays create severe risks of clinical error, patient toxicity, and mortality. In contingency planning terminology, what metric has the committee established?

A
B
C
D
Test Your Knowledge

A major category 4 hurricane strikes a coastal county, causing catastrophic flooding and long-term utility grid collapse. The President declares a federal disaster under the Stafford Act, and the HHS Secretary declares a Public Health Emergency and issues a Section 1135 waiver. A local community hospital activates its Emergency Mode Operations Plan (EMOP), evacuates 40 patients to a temporary field clinic, and reverts entirely to paper charting. The facility privacy officer is asked by clinical staff whether HIPAA compliance is suspended during the disaster. What is the accurate legal determination?

A
B
C
D