Primary MFA provider outage
CP-13 backup MFA or temporary cert-based access for clinicians with heightened audit — not open password-only EHR.
CP-13 requires employing alternative or supplemental security mechanisms for satisfying security functions when the primary means are unavailable or compromised. If the primary MFA service, HSM, or SIEM path fails, contingency operations must not silently drop ePHI protections.
Pre-plan alternative security mechanisms that preserve essential ePHI protections when primary security functions fail — with activation criteria and tested procedures.
How this control shows up in healthcare and HIPAA-covered environments.
CP-13 backup MFA or temporary cert-based access for clinicians with heightened audit — not open password-only EHR.
Alternate key ceremony procedures with dual control allow urgent decryption of care-critical data under logged exception.
Local buffered logging plus increased host alerts serve as supplemental mechanisms until SIEM recovers.
Contingencies that turn off security are breach accelerants. CP-13 shows you planned how to stay reasonably secure while recovering.
How this NIST control supports HIPAA Security Rule expectations.
CP-11 focuses on communications protocols; CP-13 focuses on alternative security mechanisms for security functions broadly.
Partially for some workflows; define how paper activity is reconciled into electronic audit after recovery.
They help if configured and tested — document them as your alternative mechanisms.
Related controls that commonly accompany CP-13.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.