CP-11 Contingency Planning

Alternate Communications Protocols

High Risk Complex Medium Cost

CP-11 requires providing the capability to employ alternative communications protocols in support of maintaining continuity of operations. When primary HL7/TLS paths, VPN concentrators, or cloud interconnects fail, hospitals need tested alternate protocols to preserve care coordination involving ePHI.

Control Objective

Establish and test alternate communications protocols for critical ePHI exchanges so contingency operations can continue when primary protocols or paths are unavailable.

Implementation Guidance

  1. Identify critical communications that carry ePHI or enable care (EHR-remote clinic, HIE, cloud EHR).
  2. Define alternate protocols/paths (secondary VPN, cellular backup, alternate message formats, offline secure courier procedures).
  3. Document when to invoke alternates and who authorizes.
  4. Pre-stage credentials/config for alternates under change control.
  5. Test alternates during CP exercises without exposing extra ePHI unnecessarily.
  6. Train operators on degraded-mode communications.
  7. Ensure alternates still meet encryption/auth requirements or document risk acceptance.
  8. Review after major network architecture changes.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Primary MPLS to clinics fails

CP-11 cellular/IPSec backup brings ambulatory EHR sessions back within RTO targets.

HIE protocol outage

Alternate secure file drop with encryption replaces real-time feed temporarily under documented protocol.

Cloud IdP unreachable

Break-glass local auth path (limited) activates with enhanced logging — alternate communications for authentication services.

Best Practices

  • Documented alternate protocols for critical links.
  • Pre-staged configurations.
  • Tested in CP exercises.
  • Maintain security requirements in degraded mode.
  • Clear invocation authority.
  • Train operators.

Common Gaps & Violations

  • Alternates exist only on a whiteboard.
  • Backup VPN never tested.
  • Degraded mode sends ePHI in clear text.
  • No owner for alternate paths.
  • Clinics unaware of failover steps.

Required Documentation

  • Alternate communications procedure (CP-11)
  • Inventory of critical links and alternates
  • Test/exercise results
  • Invocation criteria and contacts
  • Security requirements for degraded modes

How to Test & Validate

  1. List critical ePHI communications and named alternates.
  2. Review last test of an alternate path.
  3. Verify encryption/auth on alternate.
  4. Interview clinic IT on failover awareness.
  5. Confirm configs are pre-staged and current.

Audit Considerations

Contingency audits ask how you communicate when the primary path dies. CP-11 evidence should show tested alternates — not hope.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(7) Contingency Plan — establish procedures for responding to emergencies that damage systems with ePHI.
  • 164.308(a)(7)(ii)(B) Disaster Recovery — restore lost data and operations including communications.
  • 164.312(e) Transmission Security — alternate paths should still protect ePHI in transit when feasible.
  • 164.310(a)(2)(i) Contingency Operations — facility/comms access for restoration.

Compliance Tips

  • Include CP-11 tests in annual contingency exercises.
  • Prefer secure alternates over fax-by-default when possible.
  • Document any cleartext contingency with time limits and approvals.

Frequently Asked Questions

Is a secondary ISP enough for CP-11?

It can be part of alternate communications; also consider protocol/application-level failovers for clinical messaging.

Do offline paper procedures count?

They can be an alternate communications mode for care continuity; still document return-to-electronic reconciliation of ePHI.

Must alternates match primary throughput?

Size to contingency needs and RTO/RPO — degraded capacity may be acceptable if documented.

References & Resources

  • NIST SP 800-53 Rev. 5 — CP-11
  • Related controls: CP-2, CP-8, CP-13, SC-7

Need Help Implementing CP-11?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.