Emergency Mode Operation Plan
An Emergency Mode Operation Plan is a documented set of procedures that a healthcare organization follows to keep its critical operations running during an emergency, such as a natural disaster, power failure, or other disruptive event. Its purpose is to ensure that essential business processes involving electronic protected health information (ePHI) can continue while the organization is operating under emergency conditions. It is one component of the broader contingency planning required under the HIPAA Security Rule.
The Emergency Mode Operation Plan is an implementation specification within the Contingency Plan standard under the Administrative Safeguards of the HIPAA Security Rule, generally cited at 45 CFR §164.308(a)(7)(ii)(C). It is designated as a Required implementation specification (not addressable), meaning covered entities and business associates must implement it rather than assess it for reasonableness and appropriateness. The plan specifies the procedures that enable the continuation of critical business processes so as to protect the security of ePHI while the organization operates in emergency mode. As a Security Rule provision, its scope is limited to ePHI and does not extend to PHI in oral or paper form, which falls under the Privacy Rule. It is distinct from, though related to, other Contingency Plan implementation specifications such as the Data Backup Plan and Disaster Recovery Plan. Readers should confirm the current regulatory text, as the specific CFR citation and requirements should be verified against the applicable regulation, and note that state law or the HITECH Act may impose additional obligations.
Why it matters
The Emergency Mode Operation Plan addresses one of the most vulnerable moments in a healthcare organization's operations: the period during a disaster, power failure, system outage, or other disruptive event when normal safeguards may be degraded or unavailable. During these conditions, the risk to electronic protected health information (ePHI) does not disappear, if anything, the pressure to continue delivering care can tempt staff to bypass security controls entirely. The EMOP exists to ensure that critical business processes involving ePHI can continue while the organization maintains the security of that information under emergency conditions.
Because the EMOP is a Required implementation specification under the HIPAA Security Rule, not an addressable one, covered entities and business associates must implement it rather than assess whether it is reasonable and appropriate for their environment. This distinction matters in practice: an organization cannot simply document why it chose not to have an emergency mode plan. It must actually establish the procedures. The plan is one component of the broader Contingency Plan standard, and it works alongside related specifications such as the Data Backup Plan and Disaster Recovery Plan.
It is important to keep the EMOP's scope in perspective. As a Security Rule provision, it applies only to ePHI and does not govern PHI in oral or paper form, which falls under the Privacy Rule. Organizations should also recognize that state law or the HITECH Act may impose additional obligations beyond what the Security Rule requires, and that having an EMOP in place does not by itself guarantee overall HIPAA compliance or prevent all incidents. It is one required piece of a larger contingency planning obligation.
Who it's relevant to
Inside EMOP
Common questions
Answers to the questions practitioners most commonly ask about EMOP.