What would you do in
the event of a
disaster?
 A fire, tornado or other disaster
has hit your medical practice.
 You can’t get in to the building.
What do you do
about …
• Patients scheduled for that day?
• Notifying Staff?
• Accessing important patient
medical information?
A medical practice’s unencrypted
server was hacked and the data
was held hostage.
What would
you do?
Under HIPAA law, it’s critical
that medical practices have a well
thought-out and documented
contingency plan.
Contingency Planning
“Establish (and implement
as needed) policies and
procedures for responding
to an emergency or other
occurrence (for example,
fire, vandalism, system
failure,
and natural disaster) that
damages systems that
contain electronic protected
health information.”
 Medical practices must “ensure the
confidentiality, integrity, and
availability of all electronic protected
health information the covered entity
creates, receives, maintains or
transmits” and to “protect against any
reasonably anticipated threats or
hazards to the security or integrity of
such information.”
1. Data Backup Plan
2. Disaster Recovery Plan
3. Emergency Mode
Operation Plan
4. Testing and Revision
Procedures
5. Applications and Data
Criticality Analysis
 Staffing
 Physical
facility
 Continuity of
care
 Workflow
Only then will you truly
be ready to manage a
potential type of disaster.
Documented, tested and
communicated to everyone
within your practice.
info@practicemanagersolutions.com
Call 866-492-0481 ext 4
Bringing More Ideas, More Resources and
More Support to your busy medical
practice. Visit
www.practicemanagersolutions.com
Contact Rebecca Morehead
founder

Contingency planning for your medical practice

  • 1.
    What would youdo in the event of a disaster?
  • 2.
     A fire,tornado or other disaster has hit your medical practice.  You can’t get in to the building.
  • 3.
    What do youdo about … • Patients scheduled for that day? • Notifying Staff? • Accessing important patient medical information?
  • 4.
    A medical practice’sunencrypted server was hacked and the data was held hostage. What would you do?
  • 5.
    Under HIPAA law,it’s critical that medical practices have a well thought-out and documented contingency plan. Contingency Planning
  • 6.
    “Establish (and implement asneeded) policies and procedures for responding to an emergency or other occurrence (for example, fire, vandalism, system failure, and natural disaster) that damages systems that contain electronic protected health information.”
  • 7.
     Medical practicesmust “ensure the confidentiality, integrity, and availability of all electronic protected health information the covered entity creates, receives, maintains or transmits” and to “protect against any reasonably anticipated threats or hazards to the security or integrity of such information.”
  • 8.
    1. Data BackupPlan 2. Disaster Recovery Plan 3. Emergency Mode Operation Plan 4. Testing and Revision Procedures 5. Applications and Data Criticality Analysis
  • 9.
     Staffing  Physical facility Continuity of care  Workflow
  • 10.
    Only then willyou truly be ready to manage a potential type of disaster. Documented, tested and communicated to everyone within your practice.
  • 11.
    info@practicemanagersolutions.com Call 866-492-0481 ext4 Bringing More Ideas, More Resources and More Support to your busy medical practice. Visit www.practicemanagersolutions.com Contact Rebecca Morehead founder