Skip to main content
Category: Physical and Technical Safeguards

Data Backup and Storage

Also known as: Data Backup and Storage Specification
Simply put

Data Backup and Storage refers to keeping a retrievable, exact copy of information (in the HIPAA context, electronic protected health information) in a separate location from the original so it can be recovered if data is lost, damaged, or destroyed. Under the HIPAA Security Rule, this is a specific safeguard that a covered entity or business associate should consider before moving or disposing of equipment that stores such data. It is one part of a broader set of controls for protecting hardware and electronic media.

Formal definition

In general data management usage, a data backup is a copy of system, configuration, or application data stored separately from the original so it can be used in the event of data loss, with backup storage being the physical location or device holding those copies. Within the HIPAA Security Rule, 'Data Backup and Storage' is an addressable implementation specification under the Device and Media Controls standard within the Physical Safeguards category (generally cited at 45 CFR 164.310(d)(2)(iv)); it calls for creating a retrievable, exact copy of electronic protected health information (ePHI), when needed, before movement of equipment. This specification is distinct from the required administrative 'Data Backup Plan' implementation specification under the Contingency Plan standard (generally cited at 45 CFR 164.308(a)(7)(ii)(A)); the two should not be conflated. As an addressable specification, 'Data Backup and Storage' is not optional: a regulated entity must assess whether the safeguard is reasonable and appropriate in its environment and, if not, document its rationale and implement an equivalent alternative where reasonable. This entry addresses only the Security Rule specification governing ePHI and does not cover Privacy Rule obligations for PHI in other forms; readers should verify current CFR citations, and note that the HITECH Act and applicable state law may impose additional requirements.

Why it matters

Data Backup and Storage matters because ePHI stored on hardware and electronic media is vulnerable to loss whenever equipment is moved, reassigned, retired, or disposed of. If an exact, retrievable copy of that data does not exist in a separate location before such movement occurs, an organization risks permanently losing patient information that may be needed for care, operations, or legal and regulatory purposes. This addressable specification sits under the Device and Media Controls standard within the Security Rule's Physical Safeguards, and it focuses specifically on that moment of transition when equipment holding ePHI is relocated or decommissioned.

It is important to distinguish this Physical Safeguard from the separate, required administrative 'Data Backup Plan' implementation specification found under the Contingency Plan standard. The two are frequently confused, but they are not the same: the Contingency Plan's Data Backup Plan is a required administrative control governing ongoing, routine backups for disaster recovery, while 'Data Backup and Storage' is an addressable physical control tied to the handling and movement of equipment and media. Conflating them can lead organizations to misjudge their obligations and misapply their documentation.

Because this is an addressable specification, it is not optional. A regulated entity must assess whether the safeguard is reasonable and appropriate for its environment and, where it is not, document the rationale and implement a reasonable equivalent alternative. Failing to make and document that assessment is itself a compliance gap. Note that penalty exposure, breach obligations, and additional requirements under the HITECH Act or applicable state law fall outside this specific specification, and readers should verify current CFR citations against the regulation.

Who it's relevant to

Security Officers and Compliance Teams
Those responsible for a regulated entity's Security Rule compliance need to correctly place this specification within the Physical Safeguards, under Device and Media Controls, and keep it distinct from the required administrative Data Backup Plan under the Contingency Plan standard. They should document the assessment of whether this addressable measure is reasonable and appropriate and, if not, record the rationale and any equivalent alternative implemented.
IT and Infrastructure Staff
Personnel who move, reassign, retire, or dispose of hardware and electronic media are the ones who put this specification into practice. When such equipment stores ePHI, they should ensure a retrievable, exact copy is created before movement where needed, and store that copy in a separate location so data is not lost during the transition.
Business Associates and Subcontractors
Business associates and their subcontractors that create, receive, maintain, or transmit ePHI on behalf of a covered entity are also subject to the Security Rule's Physical Safeguards. They should assess and, where reasonable and appropriate, apply this addressable specification when handling equipment that stores ePHI, consistent with their obligations flowing through business associate agreements.
Auditors and Assessors
Those evaluating Security Rule conformance should confirm that an organization has correctly treated 'Data Backup and Storage' as an addressable Physical Safeguard rather than conflating it with the required Data Backup Plan, and should verify that any decision not to implement the specification as written is properly documented with a reasonable alternative. Note that HITRUST CSF assessment or certification is a separate private framework and does not by itself establish HIPAA compliance.

Inside Data Backup and Storage

Data Backup and Storage (Addressable Specification)
An addressable implementation specification within the Physical Safeguards, falling under the Device and Media Controls standard (generally cited at 45 CFR §164.310(d)(2)(iv)). It calls for creating a retrievable, exact copy of electronic protected health information (ePHI), when needed, before moving equipment. Note that addressable does not mean optional; a covered entity or business associate must assess whether the specification is reasonable and appropriate, implement it if so, or document why not and adopt an equivalent alternative where reasonable.
Placement Within Physical Safeguards
This specification sits within the Physical Safeguards category of the Security Rule, specifically under Device and Media Controls. It should not be confused with the separately named 'Data Backup Plan,' which is a required administrative specification under the Contingency Plan standard (generally cited at 45 CFR §164.308(a)(7)(ii)(A)). The two address related but distinct concerns.
Retrievable Exact Copy
The core focus is the ability to create and retrieve an exact copy of ePHI before equipment or media containing that data is moved, so that information is not lost during hardware relocation, disposal, or reuse.
Scope Limitation to ePHI
Because this is a Security Rule specification, it applies only to protected health information in electronic form. PHI in oral or paper form is governed by the Privacy Rule and is outside the scope of this technical/physical safeguard context.
Applicability to Regulated Entities
The specification generally applies to covered entities and to business associates (and their subcontractors) through the flow-down of obligations established in business associate agreements. HIPAA does not attach obligations to every vendor that touches data absent such a defined relationship.

Common questions

Answers to the questions practitioners most commonly ask about Data Backup and Storage.

Is "Data Backup and Storage" a required HIPAA implementation specification?
No. "Data Backup and Storage" is an addressable implementation specification within the Device and Media Controls standard under the Physical Safeguards (generally cited at 45 CFR §164.310(d)(2)(iv)). It is important not to confuse it with the separate "Data Backup Plan," which is a required implementation specification under the administrative Contingency Plan standard (generally cited at 45 CFR §164.308(a)(7)(ii)(A)). Because "Data Backup and Storage" is addressable, a covered entity or business associate must assess whether the specification is reasonable and appropriate in its environment. Addressable, however, does not mean optional: if the entity determines the specification is not reasonable and appropriate, it must document that determination and implement an equivalent alternative where reasonable and appropriate. Readers should verify the current regulatory text for exact citations and wording.
Does this specification belong under both the Physical and Technical Safeguards?
The HIPAA specification named "Data Backup and Storage" sits within the Physical Safeguards only, as part of the Device and Media Controls standard. It addresses creating a retrievable, exact copy of electronic protected health information (ePHI) before equipment is moved. While backup activities can involve technical measures in practice, the specification itself is categorized as a physical safeguard under the Security Rule. Related but distinct backup obligations, such as the required Data Backup Plan, live under the administrative Contingency Plan standard. Keeping these placements separate matters because the applicable requirements and whether a specification is required or addressable differ between them.
When does the Data Backup and Storage specification typically come into play?
This addressable specification generally applies when hardware or electronic media containing ePHI is going to be moved. The idea is to create a retrievable, exact copy of the ePHI, when reasonable and appropriate, before the equipment is relocated, so that the information is not lost during the move. It is one of several implementation specifications under Device and Media Controls. Because it is addressable, an organization should evaluate its own circumstances and document how it meets the specification or why an equivalent alternative is reasonable and appropriate. This is distinct from routine operational backups performed under the administrative Data Backup Plan, and readers should confirm scope against the current Security Rule text.
How should an organization document a decision about an addressable specification like this?
For any addressable implementation specification, organizations generally document their risk-based analysis: whether the specification is reasonable and appropriate given the entity's size, complexity, technical infrastructure, and risk environment. If it is implemented, the documentation typically describes how. If it is not implemented as written, the documentation should explain the rationale and describe any equivalent alternative measure adopted where reasonable and appropriate, or why no alternative is warranted. Maintaining this documentation is important because addressable does not mean the specification can simply be ignored. Organizations should retain such records consistent with the Security Rule's documentation requirements and verify retention expectations against current guidance.
How does this specification relate to the required Data Backup Plan?
They are related in subject matter but are separate requirements with different mandatory status. The "Data Backup Plan" is a required administrative specification under the Contingency Plan standard, generally focused on establishing and implementing procedures to create and maintain retrievable exact copies of ePHI as part of contingency and continuity planning. "Data Backup and Storage" is an addressable physical specification under Device and Media Controls, focused on backing up ePHI before moving equipment. An organization typically addresses both, but should not treat the addressable physical specification as if it carried the required status of the administrative Data Backup Plan. Readers should confirm the precise scope of each against current regulatory text.
Do backup practices alone establish overall HIPAA compliance or prevent all data loss?
No. Meeting backup-related specifications is one part of a broader Security Rule program that also includes other administrative, physical, and technical safeguards. No single measure guarantees compliance or prevents all data loss or breaches. In addition, HITRUST CSF certification, which some organizations pursue, is offered by a private organization and is not a legal requirement; it does not by itself establish HIPAA compliance. Organizations should also be aware that the HITECH Act, state laws, and other frameworks may impose additional requirements beyond HIPAA. Backup practices should be evaluated as part of an ongoing, documented risk analysis rather than viewed as a standalone assurance of compliance.

Common misconceptions

Data Backup and Storage is a required implementation specification that must be implemented exactly as written.
The named 'Data Backup and Storage' specification is addressable, not required. It is distinct from the required administrative 'Data Backup Plan' under the Contingency Plan standard. Addressable means a regulated entity must evaluate whether the measure is reasonable and appropriate for its environment and either implement it, implement a reasonable alternative, or document why it is not applicable. Addressable does not mean the entity may simply ignore it.
Data Backup and Storage and the Data Backup Plan are the same control.
They are separate specifications with different placements and obligations. 'Data Backup and Storage' is an addressable Physical Safeguard under Device and Media Controls, focused on retrievable copies of ePHI before moving equipment. The 'Data Backup Plan' is a required Administrative Safeguard under the Contingency Plan standard. Practitioners should treat them distinctly and verify each against the current regulatory text.
Maintaining backups guarantees HIPAA compliance or prevents all data loss.
No single safeguard establishes overall compliance or eliminates all risk. Backup practices are one part of a broader set of safeguards, and compliance is generally assessed across the full Security Rule alongside applicable Privacy, Breach Notification, and Enforcement Rule obligations. State law and the HITECH Act may impose additional requirements, and HITRUST certification does not by itself establish HIPAA compliance.

Best practices

Treat the addressable nature of Data Backup and Storage seriously: document your risk-based assessment of whether the specification is reasonable and appropriate, and record either your implementation approach or the rationale and any equivalent alternative measure.
Distinguish this Physical Safeguard specification from the required administrative Data Backup Plan under the Contingency Plan standard, and ensure both are addressed separately in your policies rather than treated as one control.
Establish procedures to create a retrievable, exact copy of ePHI before moving, disposing of, or reusing equipment and media, and verify that copies can actually be restored.
Limit the scope of this control to ePHI, recognizing that oral and paper PHI are handled under the Privacy Rule and other safeguards.
Ensure backup and media-handling obligations flow through business associate agreements to business associates and subcontractors where those relationships exist, rather than assuming HIPAA reaches every vendor directly.
Periodically review your approach against the current regulatory text and applicable state law or HITECH requirements, and verify any specific CFR citations, deadlines, or figures before relying on them.