CP-13 Contingency Planning

Alternative Security Mechanisms

High Risk Complex Medium Cost

CP-13 requires employing alternative or supplemental security mechanisms for satisfying security functions when the primary means are unavailable or compromised. If the primary MFA service, HSM, or SIEM path fails, contingency operations must not silently drop ePHI protections.

Control Objective

Pre-plan alternative security mechanisms that preserve essential ePHI protections when primary security functions fail — with activation criteria and tested procedures.

Implementation Guidance

  1. Inventory critical security functions supporting ePHI (authN, crypto, logging, boundary filtering).
  2. Define alternatives for each (backup IdP, offline OTP, secondary logging, manual access review).
  3. Ensure alternatives provide comparable protection or document residual risk.
  4. Pre-stage and protect alternate mechanisms.
  5. Test activation during CP/IR exercises.
  6. Time-box use of weaker alternatives with enhanced monitoring.
  7. Train operators on alternate security runbooks.
  8. Review after primary technology changes.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Primary MFA provider outage

CP-13 backup MFA or temporary cert-based access for clinicians with heightened audit — not open password-only EHR.

HSM unavailable

Alternate key ceremony procedures with dual control allow urgent decryption of care-critical data under logged exception.

SIEM ingest failure

Local buffered logging plus increased host alerts serve as supplemental mechanisms until SIEM recovers.

Best Practices

  • Alternatives mapped per critical security function.
  • Comparable protection or accepted risk.
  • Tested activation.
  • Time-boxed weaker modes.
  • Operator runbooks.
  • Enhanced monitoring when alternates used.

Common Gaps & Violations

  • Outage leads to disabling MFA indefinitely.
  • No alternate logging path.
  • Alternates untested.
  • Break-glass becomes standing process.
  • No residual risk documentation.

Required Documentation

  • Alternative security mechanisms procedure (CP-13)
  • Mapping of primary to alternate mechanisms
  • Test records
  • Activation/deactivation logs
  • Risk acceptances for reduced modes

How to Test & Validate

  1. Sample critical security functions for documented alternatives.
  2. Review last activation test.
  3. Verify time limits on degraded auth.
  4. Check logging still occurs in alternate mode.
  5. Confirm residual risks recorded.

Audit Considerations

Contingencies that turn off security are breach accelerants. CP-13 shows you planned how to stay reasonably secure while recovering.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(7) Contingency Plan — maintain protections while restoring operations.
  • 164.312(d) Person or Entity Authentication — authentication must not vanish during outages without a plan.
  • 164.312(b) Audit Controls — continue recording activity when feasible via alternatives.
  • 164.306 Flexible approach — alternative mechanisms can meet reasonable safeguard expectations during contingency.

Compliance Tips

  • Never make password-only the standing backup for EHR without executive risk acceptance and time box.
  • Store alternate mechanism instructions with CP kits.
  • Review CP-13 after changing IdP or crypto providers.

Frequently Asked Questions

How does CP-13 differ from CP-11?

CP-11 focuses on communications protocols; CP-13 focuses on alternative security mechanisms for security functions broadly.

Can paper downtime logs satisfy audit alternatives?

Partially for some workflows; define how paper activity is reconciled into electronic audit after recovery.

Are vendor failover features enough?

They help if configured and tested — document them as your alternative mechanisms.

References & Resources

  • NIST SP 800-53 Rev. 5 — CP-13
  • Related controls: CP-2, CP-11, IA-2, AU-5, SC-12

Need Help Implementing CP-13?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.