Skip to main content
Category: Administrative Safeguards

Emergency Mode Operation Plan

Also known as: EMOP, Emergency Mode Operations Plan
Simply put

An Emergency Mode Operation Plan is a documented set of procedures that a healthcare organization follows to keep its critical operations running during an emergency, such as a natural disaster, power failure, or other disruptive event. Its purpose is to ensure that essential business processes involving electronic protected health information (ePHI) can continue while the organization is operating under emergency conditions. It is one component of the broader contingency planning required under the HIPAA Security Rule.

Formal definition

The Emergency Mode Operation Plan is an implementation specification within the Contingency Plan standard under the Administrative Safeguards of the HIPAA Security Rule, generally cited at 45 CFR §164.308(a)(7)(ii)(C). It is designated as a Required implementation specification (not addressable), meaning covered entities and business associates must implement it rather than assess it for reasonableness and appropriateness. The plan specifies the procedures that enable the continuation of critical business processes so as to protect the security of ePHI while the organization operates in emergency mode. As a Security Rule provision, its scope is limited to ePHI and does not extend to PHI in oral or paper form, which falls under the Privacy Rule. It is distinct from, though related to, other Contingency Plan implementation specifications such as the Data Backup Plan and Disaster Recovery Plan. Readers should confirm the current regulatory text, as the specific CFR citation and requirements should be verified against the applicable regulation, and note that state law or the HITECH Act may impose additional obligations.

Why it matters

The Emergency Mode Operation Plan addresses one of the most vulnerable moments in a healthcare organization's operations: the period during a disaster, power failure, system outage, or other disruptive event when normal safeguards may be degraded or unavailable. During these conditions, the risk to electronic protected health information (ePHI) does not disappear, if anything, the pressure to continue delivering care can tempt staff to bypass security controls entirely. The EMOP exists to ensure that critical business processes involving ePHI can continue while the organization maintains the security of that information under emergency conditions.

Because the EMOP is a Required implementation specification under the HIPAA Security Rule, not an addressable one, covered entities and business associates must implement it rather than assess whether it is reasonable and appropriate for their environment. This distinction matters in practice: an organization cannot simply document why it chose not to have an emergency mode plan. It must actually establish the procedures. The plan is one component of the broader Contingency Plan standard, and it works alongside related specifications such as the Data Backup Plan and Disaster Recovery Plan.

It is important to keep the EMOP's scope in perspective. As a Security Rule provision, it applies only to ePHI and does not govern PHI in oral or paper form, which falls under the Privacy Rule. Organizations should also recognize that state law or the HITECH Act may impose additional obligations beyond what the Security Rule requires, and that having an EMOP in place does not by itself guarantee overall HIPAA compliance or prevent all incidents. It is one required piece of a larger contingency planning obligation.

Who it's relevant to

Security Officers
HIPAA Security Officers are generally responsible for developing, documenting, and maintaining the Emergency Mode Operation Plan as part of the organization's Contingency Plan. Because the EMOP is a Required implementation specification, security officers should ensure it is actually in place, not merely assessed, and that it integrates with the Data Backup Plan and Disaster Recovery Plan.
Covered Entities and Business Associates
Both covered entities and business associates are subject to the Security Rule's Contingency Plan standard and must implement an Emergency Mode Operation Plan. Business associates should confirm that their obligations, including emergency mode procedures, align with the terms of their business associate agreements and applicable regulatory requirements.
IT and Operations Teams
IT and operations personnel typically translate the EMOP into practical procedures, maintaining access to critical systems and ePHI during outages while preserving security controls. They are often the staff who execute the plan during an actual emergency, so familiarity with its procedures is essential.
Compliance Officers and Auditors
Compliance officers and auditors evaluate whether the organization has satisfied the Required EMOP specification. They should verify that documented procedures exist and are current, and remain aware that an EMOP addresses only ePHI under the Security Rule and does not by itself establish full HIPAA compliance. State law or the HITECH Act may add further obligations to confirm against current guidance.

Inside EMOP

Regulatory Basis and Required Status
The Emergency Mode Operation Plan is an implementation specification under the HIPAA Security Rule's Contingency Plan standard, located at 45 CFR §164.308(a)(7)(ii)(C). It is designated as a 'Required' implementation specification, not 'addressable,' meaning covered entities and business associates must implement it rather than assess whether it is reasonable and appropriate. Readers should confirm the specific regulatory text against the current version of the Security Rule.
Scope Limited to ePHI
As a Security Rule administrative safeguard, this plan applies only to electronic protected health information (ePHI). It does not govern paper or oral PHI, which fall under the Privacy Rule. Its purpose is to enable continuation of critical business processes to protect the security of ePHI during and immediately after an emergency.
Critical Business Process Continuity
The plan generally identifies the critical processes that must continue to operate to maintain the confidentiality, integrity, and availability of ePHI when normal operations are disrupted by events such as system failures, natural disasters, or other emergencies.
Relationship to the Broader Contingency Plan
It is one of several components of the Contingency Plan standard, alongside the Data Backup Plan and Disaster Recovery Plan (both Required), and the Testing and Revision Procedures and Applications and Data Criticality Analysis (both addressable). It functions as part of a coordinated contingency framework rather than in isolation.
Protection of ePHI During Emergency Operations
Because operating in emergency mode may involve alternate systems, manual processes, or reduced controls, the plan typically addresses how security protections for ePHI are maintained even when standard safeguards are unavailable.

Common questions

Answers to the questions practitioners most commonly ask about EMOP.

Is the Emergency Mode Operation Plan an addressable implementation specification that we can opt out of if it's not reasonable for our organization?
No. The Emergency Mode Operation Plan is a Required implementation specification under the Security Rule's contingency planning standard at 45 CFR §164.308(a)(7)(ii)(C), not an addressable one. This means a covered entity or business associate must implement it; there is no option to document a rationale for not implementing it as there would be with an addressable specification. Even where implementation specifications are addressable, addressable does not mean optional, but here the point is moot because this specification is designated Required.
Does having an Emergency Mode Operation Plan mean our overall contingency plan and HIPAA compliance are complete?
No. The Emergency Mode Operation Plan is one of several implementation specifications under the contingency plan standard, which also generally includes a data backup plan and a disaster recovery plan (both Required), along with testing/revision procedures and applications/data criticality analysis. Satisfying one specification does not establish compliance with the contingency plan standard as a whole, and the Security Rule addresses only ePHI. Broader HIPAA compliance also involves the Privacy Rule, Breach Notification Rule, and other Security Rule standards. Readers should verify current requirements against the applicable regulatory text.
What is the Emergency Mode Operation Plan intended to accomplish?
It is generally intended to establish and, when needed, activate procedures that enable continuation of critical business processes to protect the security of ePHI while operating in emergency mode, for example, during a system outage, natural disaster, or other event that disrupts normal operations. The focus is on maintaining protection of ePHI during the emergency, not solely on restoring systems afterward.
How does the Emergency Mode Operation Plan differ from the disaster recovery plan and data backup plan?
These are distinct Required specifications within the same contingency plan standard. In general terms, the data backup plan addresses creating and maintaining retrievable exact copies of ePHI, the disaster recovery plan addresses restoring lost data and systems, and the Emergency Mode Operation Plan addresses continuing critical processes that protect ePHI security while the organization is actually operating in emergency mode. They are complementary rather than interchangeable.
Should the Emergency Mode Operation Plan be tested?
The contingency plan standard includes a separate testing and revision procedures specification, which is generally addressable rather than Required. Even so, addressable does not mean optional; an organization typically evaluates whether periodic testing and revision is a reasonable and appropriate safeguard given its risk analysis and, if not, documents its rationale and any equivalent measures. Many organizations find that testing helps confirm the Emergency Mode Operation Plan works as intended.
Do business associates need an Emergency Mode Operation Plan, or only covered entities?
The Security Rule generally applies to both covered entities and business associates that create, receive, maintain, or transmit ePHI, so business associates are typically subject to the contingency plan standard, including this Required specification. Specific obligations may also be reinforced through business associate agreements. Organizations should confirm scope against the current regulatory text and any contractual terms.

Common misconceptions

The Emergency Mode Operation Plan is an addressable specification, so an organization can skip it if it decides the plan is not reasonable and appropriate.
It is a 'Required' implementation specification at 45 CFR §164.308(a)(7)(ii)(C). Covered entities and business associates must implement it. Even for addressable specifications, addressable does not mean optional; but this specification is not addressable at all.
The Emergency Mode Operation Plan and the Disaster Recovery Plan are the same thing.
They are distinct implementation specifications under the same Contingency Plan standard. The Emergency Mode Operation Plan generally focuses on continuing critical processes and protecting ePHI security while operating in emergency mode, whereas the Disaster Recovery Plan addresses restoring lost data and systems. Both are Required, but they serve different functions.
This plan covers all forms of protected health information during an emergency.
As a Security Rule safeguard, it applies only to ePHI. Protections for paper and oral PHI derive from the Privacy Rule. Additionally, state law or other frameworks may impose further continuity or emergency obligations beyond HIPAA.

Best practices

Treat the Emergency Mode Operation Plan as mandatory, documenting it as a 'Required' implementation specification under 45 CFR §164.308(a)(7)(ii)(C) rather than assessing it as optional or addressable.
Identify and prioritize the critical business processes needed to protect the security of ePHI, and specify how those processes continue when normal systems are unavailable.
Coordinate the plan with the other Contingency Plan components, Data Backup Plan, Disaster Recovery Plan, Testing and Revision Procedures, and Applications and Data Criticality Analysis, so they operate as a coherent whole.
Describe how ePHI security protections are maintained during emergency operations, including any alternate systems or manual procedures used.
Review and update the plan periodically and after significant changes to systems or operations, and verify obligations against the current version of the Security Rule.
Confirm whether state law, the HITECH Act, or frameworks such as the HITRUST CSF impose additional emergency or continuity requirements, keeping in mind that HITRUST certification is not itself a legal HIPAA requirement.