The HIPAA contingency plan your solo practice already must have
Summary
HIPAA's Security Rule already requires you to have a contingency plan for ePHI — it is a named administrative safeguard, not an optional extra. Scaled to a solo practice, it means a documented data-backup plan, a disaster-recovery plan to restore systems, an emergency-mode plan to keep treating during downtime, and procedures to test and revise all three. It starts from a risk analysis and lives as dated, retrievable paperwork.
By Gale Editorial · Updated 2026-07-27. Every figure cited to a dated source. How we write.
The answer: it is the Security Rule's contingency plan standard
If you are searching for a continuity plan HIPAA requires, you already have the obligation — the Security Rule names a contingency plan as a required administrative safeguard for electronic protected health information, scaled to the size of your practice and driven by a risk analysis 1Ref 1HHS Office for Civil Rights (2026).Summary of the HIPAA Security Rule.That the Security Rule requires a contingency plan as an administrative safeguard for ePHI, scaled to the practice and anchored in a risk analysis, with some implementation specifications required and others addressable, and that safeguards are judged in part on documentation.. A solo practice is not exempt; the rule scales down, it does not switch off. What changes for a practice of one is the size of the document, not the existence of the duty.
Do not confuse this with continuity-of-care protections that apply when a patient's insurance plan changes mid-treatment — that is a payer and state-insurance-law question about who keeps paying for care in progress. The HIPAA contingency plan is about your practice staying able to protect and reach ePHI, and keep treating, when something breaks: a dead laptop, a flooded office, a ransomware lock, or your own sudden absence.
The practical value of knowing it is already required is that you stop treating this as optional hardening you will get to someday. It is a standard an auditor can ask you to produce, and it is the difference between a bad week and a reportable breach when the systems go down.
Start where the rule does: the risk analysis
The contingency plan does not start with buying a backup drive; it starts with a risk analysis, because the Security Rule builds every safeguard on top of one. A solo practice can run its own using the free Security Risk Assessment tool that ONC and OCR publish for small practices — it walks you through where your ePHI lives, what could take it down, and which gaps to close first 2Ref 2Office of the National Coordinator / ASTP (2026).Security Risk Assessment Tool.That ONC/OCR publish a free Security Risk Assessment tool sized for small practices to perform the risk analysis on which the contingency plan is built.. The output of that analysis is the input to everything below.
The analysis forces you to inventory where ePHI actually sits: the EHR, a laptop, the cloud, paper, and — if it touches patient data — your phone. Your phone is a HIPAA device the moment it holds an app or an email with ePHI, so it belongs in scope. Some of that data carries a second lock, too: psychotherapy notes get extra protection, so your backups and access controls have to keep them separately guarded.
Most of what the analysis surfaces has a cheap fix. The 30-minute hardening of a password manager and multi-factor authentication closes the most common single point of failure, and securing office networks keeps the practice's own wifi from being the open door. Date the assessment when you finish it, and redo it whenever you change EHRs, add a device, or move offices — a stale risk analysis is the finding auditors write up first.
The five pieces of the plan
A contingency plan is not one document but a small set of linked procedures. The Security Rule frames them as backup, recovery, and keeping care going, plus the discipline to test and to prioritize — and it marks some as strictly required and others as addressable, meaning you either implement them or document why an equivalent measure is reasonable for a practice your size 1Ref 1HHS Office for Civil Rights (2026).Summary of the HIPAA Security Rule.That the Security Rule requires a contingency plan as an administrative safeguard for ePHI, scaled to the practice and anchored in a risk analysis, with some implementation specifications required and others addressable, and that safeguards are judged in part on documentation.. For a solo practice, all five are worth writing down rather than reasoning away.
| Piece | What it is | For a solo practice |
|---|---|---|
| Data backup plan | Retrievable exact copies of ePHI | Automatic, encrypted, offsite or cloud, and verified |
| Disaster recovery plan | Restore data and systems after a loss | Written restore steps and who you call |
| Emergency-mode operation plan | Keep protecting ePHI while you run in crisis | How you treat and chart during downtime |
| Testing and revision | Prove the plan works and update it | A dated restore test on the calendar |
| Applications and data criticality analysis | Rank what to restore first | The EHR and schedule before anything cosmetic |
The table's real lesson is that "we have backups" is not a plan. A backup you have never restored is a hope, a recovery plan nobody wrote is improvisation on your worst day, and an emergency-mode plan you skipped is why a patient in crisis cannot reach you when the EHR is down.
The criticality analysis is the piece that makes the rest usable. It forces you to rank your applications and data so that, on the worst morning, you restore the schedule and the active charts before the billing history or anything cosmetic. For a solo practice that ranking is short, but writing it down turns a chaotic recovery into an ordered one — you already know what comes back first and what can wait a day. And where a specification is addressable rather than strictly required, the honest move is not to skip it but to document the equivalent safeguard you use and why it is reasonable for a practice your size.
Backups and the vendor: the BAA you already need
The moment your backups live with a vendor — a cloud backup service, your EHR's hosting, an offsite data company — that vendor is a business associate, because it maintains ePHI on your behalf, and HIPAA requires a signed business associate agreement before the data goes there 3Ref 3HHS Office for Civil Rights (2026).Business Associates.That a backup, hosting, email, or answering-service vendor that maintains ePHI on the practice's behalf is a business associate requiring a signed business associate agreement.. A backup sitting in a consumer file-sync account with no BAA is itself a compliance gap, not the fix for one.
What to require of the backup, in the plan and in the contract:
- Encryption at rest and in transit, so a stolen drive or intercepted transfer is not itself a breach.
- Verified restores — the vendor (or you) can actually pull the data back, tested, not just accept it.
- Geographic separation from the office, so the flood that takes the building does not take the backup.
- Retention long enough to survive a slow-burning ransomware infection that corrupts data before you notice.
The same business-associate logic reaches beyond backups: your email host, answering service, and EHR all create, receive, or maintain ePHI, so each needs its own BAA. Keep signed copies where the contingency plan points to them, because "we had an agreement" is worth what you can produce.
When downtime is a breach: ransomware and the clock
A contingency plan is also your ransomware plan, and ransomware is where continuity and breach law meet. OCR's guidance treats a ransomware encryption of ePHI as a presumed reportable breach unless a documented risk assessment shows a low probability that the data was actually compromised 4Ref 4HHS Office for Civil Rights (2016).FACT SHEET: Ransomware and HIPAA.That a ransomware encryption of ePHI is presumed a reportable breach unless a documented risk assessment shows a low probability of compromise, tying the contingency plan's backups and logs to breach determination.. If it is a breach, the Breach Notification Rule starts a clock: notify affected individuals without unreasonable delay and no later than 60 days, and notify HHS on the rule's schedule 5Ref 5HHS Office for Civil Rights (2026).Breach Notification Rule.That a reportable breach requires notice to individuals no later than 60 days and notice to HHS on the rule's schedule, setting the timeline a ransomware or disaster incident triggers..
The first hour of a suspected ransomware incident has a short, concrete checklist worth keeping in the plan:
- Disconnect the affected device from the network to stop the spread, without powering it down if forensics may be needed.
- Preserve first — do not pay, wipe, or delete anything before you have captured what happened.
- Start the incident log from the first observation onward.
- Reach your backups and confirm they are intact and were isolated enough to survive.
- Call whoever the plan names — an IT professional, your cyber-insurance carrier, and counsel if a reportable breach looks likely.
This is why backups are a compliance control, not just an uptime convenience. Clean, tested, offline backups let you restore without negotiating with an attacker, and they feed the risk assessment that decides whether the incident is even reportable — if you can show the encrypted data was already secured and no exfiltration occurred, the analysis may land at low probability. Without backups and logs, you are guessing, and a guess resolves against you.
Keep an incident log from the first hour: what you saw, when, what was affected, what you did. State breach-notification laws can add their own requirements on top of the federal clock, so confirm your state's. And remember that restoring the systems is only half the job — after the disaster, reopening and rebuilding trust with patients is its own sequence.
Emergency mode: keeping care running when the systems are down
Emergency-mode operation is the piece providers skip, because it is about clinical continuity rather than IT. It answers a plain question: if your EHR, your building, or you are unavailable tomorrow, how does a patient still reach help, and how do you still chart? The federal business-continuity framework — a risk assessment, a written plan, and an emergency communications step — sizes down cleanly to a practice of one 6Ref 6U.S. Department of Homeland Security (2026).Ready.gov Business.That the federal business-continuity framework — risk assessment, a written continuity plan, and emergency communications — sizes down to a practice of one and structures the emergency-mode operation piece..
A solo practice's emergency-mode plan is short and concrete:
- A downtime charting method — paper templates you can scan back into the record later — so care during the outage is still documented.
- A way for patients to reach you or your coverage — an answering service under a BAA, or a covering colleague — when the usual channel is dead.
- A prescription and refill path that does not depend on the system that failed.
- The standing crisis routing every behavioral-health practice already gives patients: 988 for suicide and crisis, 911 for immediate danger, and 741741 for text.
Keep the plan somewhere you can reach without the EHR — a printed copy in a known place — because a continuity plan trapped inside the system that just failed is not a plan. The test of emergency mode is whether a covering clinician, or you on a bad day, could run it from that one page.
Test it, date it, and keep the paper
The plan that fails an audit is the one nobody can produce, and the plan that fails a real disaster is the one nobody ever tested. Both problems have the same fix: put a dated restore test and a plan review on the calendar, run them, and keep the results. HIPAA's safeguards are judged in part on documentation, so a plan you cannot show is, for compliance purposes, close to a plan you do not have 1Ref 1HHS Office for Civil Rights (2026).Summary of the HIPAA Security Rule.That the Security Rule requires a contingency plan as an administrative safeguard for ePHI, scaled to the practice and anchored in a risk analysis, with some implementation specifications required and others addressable, and that safeguards are judged in part on documentation..
Build the maintenance into a rhythm you will actually keep. Review the plan and the underlying risk analysis on a set cadence and any time something material changes — a new EHR, a new device, a new office, a new business associate. Once a year at minimum, run a real restore: pull a file back from the backup and confirm it opens, rather than trusting the green checkmark in the dashboard.
Store the plan, the risk analysis, and the signed BAAs together, reachable offline. That single act is what turns reopening after a disaster from improvisation into execution — you are running a rehearsed plan instead of inventing one while the phone rings. The contingency plan HIPAA requires is not paperwork for its own sake; on the day you need it, it is the difference between a hard week and a lost practice.
Common questions
Run your practice on Gale
The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.
Start or manage a practice →References
- 1.HHS Office for Civil Rights (2026). Summary of the HIPAA Security Rule. U.S. Department of Health and Human Services. linkThat the Security Rule requires a contingency plan as an administrative safeguard for ePHI, scaled to the practice and anchored in a risk analysis, with some implementation specifications required and others addressable, and that safeguards are judged in part on documentation.
- 2.Office of the National Coordinator / ASTP (2026). Security Risk Assessment Tool. HealthIT.gov. link ✓That ONC/OCR publish a free Security Risk Assessment tool sized for small practices to perform the risk analysis on which the contingency plan is built.
- 3.HHS Office for Civil Rights (2026). Business Associates. U.S. Department of Health and Human Services. linkThat a backup, hosting, email, or answering-service vendor that maintains ePHI on the practice's behalf is a business associate requiring a signed business associate agreement.
- 4.HHS Office for Civil Rights (2016). FACT SHEET: Ransomware and HIPAA. U.S. Department of Health and Human Services. link ✓That a ransomware encryption of ePHI is presumed a reportable breach unless a documented risk assessment shows a low probability of compromise, tying the contingency plan's backups and logs to breach determination.
- 5.HHS Office for Civil Rights (2026). Breach Notification Rule. U.S. Department of Health and Human Services. linkThat a reportable breach requires notice to individuals no later than 60 days and notice to HHS on the rule's schedule, setting the timeline a ransomware or disaster incident triggers.
- 6.U.S. Department of Homeland Security (2026). Ready.gov Business. Ready.gov (DHS/FEMA). link ✓That the federal business-continuity framework — risk assessment, a written continuity plan, and emergency communications — sizes down to a practice of one and structures the emergency-mode operation piece.
https://www.gale.care/for-providers/ecc-continuity-plan-required · 6 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.