Data Backup and Storage
Data Backup and Storage refers to keeping a retrievable, exact copy of information (in the HIPAA context, electronic protected health information) in a separate location from the original so it can be recovered if data is lost, damaged, or destroyed. Under the HIPAA Security Rule, this is a specific safeguard that a covered entity or business associate should consider before moving or disposing of equipment that stores such data. It is one part of a broader set of controls for protecting hardware and electronic media.
In general data management usage, a data backup is a copy of system, configuration, or application data stored separately from the original so it can be used in the event of data loss, with backup storage being the physical location or device holding those copies. Within the HIPAA Security Rule, 'Data Backup and Storage' is an addressable implementation specification under the Device and Media Controls standard within the Physical Safeguards category (generally cited at 45 CFR 164.310(d)(2)(iv)); it calls for creating a retrievable, exact copy of electronic protected health information (ePHI), when needed, before movement of equipment. This specification is distinct from the required administrative 'Data Backup Plan' implementation specification under the Contingency Plan standard (generally cited at 45 CFR 164.308(a)(7)(ii)(A)); the two should not be conflated. As an addressable specification, 'Data Backup and Storage' is not optional: a regulated entity must assess whether the safeguard is reasonable and appropriate in its environment and, if not, document its rationale and implement an equivalent alternative where reasonable. This entry addresses only the Security Rule specification governing ePHI and does not cover Privacy Rule obligations for PHI in other forms; readers should verify current CFR citations, and note that the HITECH Act and applicable state law may impose additional requirements.
Why it matters
Data Backup and Storage matters because ePHI stored on hardware and electronic media is vulnerable to loss whenever equipment is moved, reassigned, retired, or disposed of. If an exact, retrievable copy of that data does not exist in a separate location before such movement occurs, an organization risks permanently losing patient information that may be needed for care, operations, or legal and regulatory purposes. This addressable specification sits under the Device and Media Controls standard within the Security Rule's Physical Safeguards, and it focuses specifically on that moment of transition when equipment holding ePHI is relocated or decommissioned.
It is important to distinguish this Physical Safeguard from the separate, required administrative 'Data Backup Plan' implementation specification found under the Contingency Plan standard. The two are frequently confused, but they are not the same: the Contingency Plan's Data Backup Plan is a required administrative control governing ongoing, routine backups for disaster recovery, while 'Data Backup and Storage' is an addressable physical control tied to the handling and movement of equipment and media. Conflating them can lead organizations to misjudge their obligations and misapply their documentation.
Because this is an addressable specification, it is not optional. A regulated entity must assess whether the safeguard is reasonable and appropriate for its environment and, where it is not, document the rationale and implement a reasonable equivalent alternative. Failing to make and document that assessment is itself a compliance gap. Note that penalty exposure, breach obligations, and additional requirements under the HITECH Act or applicable state law fall outside this specific specification, and readers should verify current CFR citations against the regulation.
Who it's relevant to
Inside Data Backup and Storage
Common questions
Answers to the questions practitioners most commonly ask about Data Backup and Storage.