Skip to main content
Category: Administrative Safeguards

Data Backup Plan

Also known as: Backup Plan, Data Backup and Recovery Plan
Simply put

A data backup plan is a documented approach for creating and maintaining copies of important data so it can be restored if the original is lost, corrupted, or destroyed. In a HIPAA context, it generally focuses on ensuring that retrievable copies of electronic protected health information (ePHI) exist and can be recovered after a failure or disaster. It typically defines what data is backed up, how often, where copies are stored, and how they are restored.

Formal definition

Under the HIPAA Security Rule, a Data Backup Plan is a required implementation specification within the Contingency Plan standard of the administrative safeguards. It generally requires covered entities and business associates to establish and implement procedures to create and maintain retrievable exact copies of ePHI. In practice, an effective plan typically addresses backup scope and data selection, backup schedule and frequency, storage location (often physically or logically separate from the original data), and restoration/recovery procedures. Because the Security Rule applies only to ePHI, a Data Backup Plan under HIPAA is limited to electronic data; protection of PHI in oral or paper form falls under the Privacy Rule and is out of scope for this specification. As a 'required' implementation specification, this measure is not optional. Note that the Security Rule sets the objective (retrievable exact copies) rather than prescribing specific technologies, retention periods, or backup frequencies; organizations should determine these based on their risk analysis, and readers should verify current requirements against the applicable regulatory text. State law, the HITECH Act, or frameworks such as the HITRUST CSF may impose additional or more detailed requirements; HITRUST certification is not itself a legal requirement and does not by itself establish HIPAA compliance.

Why it matters

A Data Backup Plan is one of the required implementation specifications within the Contingency Plan standard of the HIPAA Security Rule's administrative safeguards, meaning covered entities and business associates are generally expected to establish and implement procedures to create and maintain retrievable exact copies of ePHI. Its importance stems from the availability dimension of ePHI protection: if patient records, imaging data, or other electronic health information are lost, corrupted, or destroyed, whether through hardware failure, human error, a natural disaster, or a ransomware event, the ability to restore that data can be the difference between continuity of care and prolonged operational disruption.

Because the Security Rule treats the Data Backup Plan as a 'required' rather than 'addressable' specification, organizations generally cannot treat backups as optional or defer them based on convenience. The plan works alongside other contingency components, but its specific objective is ensuring that retrievable, exact copies of ePHI exist. Failing to maintain such copies can leave an organization unable to recover critical data after an incident, and may also draw regulatory scrutiny from HHS OCR if a lack of adequate backup procedures contributes to an availability failure involving ePHI.

It is worth emphasizing that no backup plan by itself guarantees HIPAA compliance or prevents all data loss; effectiveness depends on how well the plan is implemented, tested, and aligned with the organization's risk analysis. Readers should also note that state law, the HITECH Act, or frameworks such as the HITRUST CSF may impose additional or more detailed backup and recovery expectations beyond the baseline objective set by the Security Rule.

Who it's relevant to

Security Officers and IT Compliance Teams
Security officers are typically responsible for establishing and implementing backup procedures that meet the required Data Backup Plan specification. They generally define backup scope, schedules, storage locations, and restoration processes, and align these decisions with the organization's risk analysis rather than a fixed prescribed standard.
Covered Entities
Healthcare providers, health plans, and healthcare clearinghouses that create, receive, maintain, or transmit ePHI are generally expected to maintain a Data Backup Plan as part of their Security Rule contingency planning obligations.
Business Associates and Subcontractors
Business associates that handle ePHI on behalf of covered entities are also generally subject to the Security Rule and its administrative safeguards. Their obligations, including maintaining retrievable copies of ePHI, typically flow through business associate agreements, and similar obligations may extend to subcontractors.
Auditors and Assessors
Auditors reviewing HIPAA Security Rule compliance, or assessors evaluating against frameworks such as the HITRUST CSF, generally examine whether documented backup and recovery procedures exist and function as intended. Note that HITRUST certification is not itself a legal requirement and does not by itself establish HIPAA compliance.

Inside Data Backup Plan

Regulatory Basis
The Data Backup Plan is a required implementation specification under the HIPAA Security Rule's administrative safeguards, specifically within the Contingency Plan standard. As a required specification, it must be implemented by covered entities and business associates; it is not left to discretion in the way addressable specifications allow.
Scope of Protected Data
Because it derives from the Security Rule, the Data Backup Plan applies to electronic protected health information (ePHI). It does not, by itself, address PHI in oral or paper form, which falls under the broader Privacy Rule.
Retrievable Exact Copies
The core objective is to establish and implement procedures to create and maintain retrievable exact copies of ePHI, so that data can be recovered following loss, corruption, disaster, or system failure.
Relationship to Other Contingency Specifications
The Data Backup Plan works alongside the Disaster Recovery Plan and the Emergency Mode Operation Plan, which are also required specifications within the Contingency Plan standard. Testing and revision procedures and applications/data criticality analysis are addressable specifications supporting these efforts.
Coverage Across Systems
The plan generally should account for all systems and repositories where ePHI resides, since gaps in backup scope can leave portions of ePHI unrecoverable.

Common questions

Answers to the questions practitioners most commonly ask about Data Backup Plan.

Is a Data Backup Plan an addressable specification that we can skip if it seems burdensome?
No. The Data Backup Plan is a required implementation specification within the Contingency Plan standard of the Security Rule's administrative safeguards, not an addressable one. Because it is required, covered entities and business associates must implement it; the addressable-versus-required distinction does not give the option to omit a required specification. Keep in mind that even for addressable specifications, addressable does not mean optional, it means an entity may implement an equivalent alternative or document why a specification is not reasonable and appropriate. That flexibility does not apply here, since a Data Backup Plan is required.
Does having a Data Backup Plan by itself mean we are compliant with the HIPAA Security Rule's contingency requirements?
No. The Data Backup Plan is only one required specification within the broader Contingency Plan standard, which also generally includes other specifications such as a disaster recovery plan and an emergency mode operation plan. Implementing backups alone does not satisfy the full contingency standard, and it does not establish overall Security Rule compliance. The Security Rule requires a coordinated set of administrative, physical, and technical safeguards, and readers should confirm the full set of contingency requirements against the current regulatory text.
What does a Data Backup Plan need to cover to meet the Security Rule requirement?
A Data Backup Plan generally must establish and implement procedures to create and maintain retrievable exact copies of electronic protected health information (ePHI). In practice this typically means identifying which ePHI systems and data are in scope, defining backup frequency, and ensuring copies can actually be restored. Because the Security Rule applies only to ePHI, the plan addresses electronic data; protection of paper or oral PHI falls under the Privacy Rule rather than this specification. Organizations should scale their approach to their size, complexity, and risk analysis results.
How often should backups be performed and tested?
The Security Rule does not prescribe a specific backup frequency or a fixed testing schedule; instead, these decisions are generally driven by an entity's risk analysis and the criticality of the ePHI involved. Many organizations align backup frequency with how much data loss they can tolerate and test restoration periodically to confirm copies are truly retrievable. Note that testing is often associated with the disaster recovery and testing/revision components of the Contingency Plan standard, so review the current regulatory text to confirm how these related specifications apply to your environment.
How does the Data Backup Plan relate to encryption and physical security of backup media?
The Data Backup Plan focuses on creating and maintaining retrievable exact copies of ePHI, but backup copies themselves are ePHI and therefore remain subject to other applicable safeguards. Technical safeguards such as encryption (an addressable specification, which does not mean optional) and physical safeguards governing media storage, access, and disposal may all apply to backup media. Entities should coordinate the Data Backup Plan with these other required and addressable specifications rather than treating backups in isolation.
Do business associates need their own Data Backup Plans, and can we rely on a vendor's backups?
Business associates that create, receive, maintain, or transmit ePHI are generally directly subject to the Security Rule and are expected to implement their own contingency measures, including a Data Backup Plan. A covered entity's obligations toward a vendor typically flow through a business associate agreement, and relying on a vendor's backups does not remove the covered entity's own responsibility for its ePHI. Responsibilities should be clearly allocated in the agreement, and each party should confirm its obligations against the current regulatory text.

Common misconceptions

A Data Backup Plan is optional or can be skipped if a covered entity judges it unnecessary.
Within the HIPAA Security Rule's Contingency Plan standard, the Data Backup Plan is a required implementation specification, not an addressable one. Required specifications must be implemented. Even addressable specifications are not simply optional; they require assessment and documented decision-making.
Having backups guarantees HIPAA compliance and prevents data loss incidents.
A Data Backup Plan is one required specification among many safeguards. No single measure guarantees compliance or prevents all breaches or data loss. Backups must be paired with other administrative, physical, and technical safeguards and should be tested to confirm data is actually retrievable.
Achieving a HITRUST CSF certification satisfies the Data Backup Plan requirement automatically.
HITRUST is a private organization and the HITRUST CSF is a certifiable control framework, not a legal mandate. Certification may help demonstrate a mature backup program, but it does not by itself establish HIPAA compliance, which is enforced by HHS OCR against the regulatory text.

Best practices

Inventory all systems, applications, and repositories where ePHI resides so the backup scope does not leave critical data uncovered.
Design procedures to produce retrievable exact copies of ePHI and periodically verify that restorations actually succeed, since untested backups may not be recoverable when needed.
Coordinate the Data Backup Plan with the Disaster Recovery Plan and Emergency Mode Operation Plan so recovery efforts function together during a disruption.
Document the plan and any decisions related to supporting addressable specifications such as testing/revision procedures and data criticality analysis.
Protect backup copies with appropriate technical and physical safeguards, since backup media containing ePHI remains subject to the Security Rule.
Review the current regulatory text and, where applicable, the current HITRUST CSF version, and account for any additional requirements under state law or the HITECH Act.