CP-2 Contingency Planning

Contingency Plan

High Risk Moderate Medium Cost

CP-2 requires developing a contingency plan for the information system that identifies essential missions and business functions, provides recovery objectives, addresses roles and restoration priorities, and is reviewed, approved, and updated on a defined frequency and after plan tests or system changes. For clinics and hospitals this is the parent plan covering how ePHI systems continue or recover when disasters, outages, or ransomware hit.

Control Objective

Maintain an approved, current contingency plan so critical clinical and ePHI-supporting systems can be restored to agreed RTO/RPO targets with clear ownership.

Implementation Guidance

  1. Inventory critical systems (EHR, PACS, lab, pharmacy, identity, networking, voice) and rank restoration priority.
  2. Define RTO/RPO per system with clinical leadership — not IT alone.
  3. Document activation criteria, command roles, communications, and dependencies (power, ISP, cloud EHR, BA hosts).
  4. Link detailed procedures for backup restore (CP-9), recovery/reconstitution (CP-10), and alternate processing.
  5. Address paper downtime procedures for charting/meds when systems are offline.
  6. Approve the plan with leadership; version-control and distribute offline copies.
  7. Review at least annually and after tests, major incidents, or EHR migrations.
  8. Coordinate with IR-8 so ransomware/outage handoffs are clear.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Regional power outage lasting 8 hours

Generators cover the clinic, but ISP fails. CP-2 activates downtime EHR procedures, routes phones, and prioritizes restoring identity + cloud EHR access ahead of nonclinical file shares.

Ransomware encrypts on-prem file and imaging servers

Contingency plan separates IR containment from CP recovery: validated backups, restore order (domain → imaging → shares), and clinical communication scripts.

Cloud EHR regional degradation

Vendor status page shows degraded performance. CP-2 vendor annex triggers downtime workflows and executive communications while IT monitors vendor RTO commitments.

Best Practices

  • Get clinical sign-off on RTO/RPO.
  • Keep offline/printed plan extracts for ransomware.
  • Include BA/cloud dependencies explicitly.
  • Test the plan (CP-3/CP-4) — do not shelfware it.
  • Align with HIPAA contingency plan implementation specs.
  • Update after every major system change.

Common Gaps & Violations

  • Generic DR template with no EHR specifics.
  • RTO/RPO never validated with clinicians.
  • Plan not approved or years outdated.
  • No downtime procedures for clinical staff.
  • Ignoring cloud SaaS as in-scope contingency.

Required Documentation

  • Approved contingency plan (versioned)
  • System priority / RTO-RPO table
  • Roles and contact tree
  • Downtime procedures annex
  • Review and approval records

How to Test & Validate

  1. Confirm approval date within review cycle.
  2. Interview charge nurse: can they find downtime procedures?
  3. Trace one critical system from priority list to restore steps.
  4. Verify offline copy accessibility.
  5. Check last plan update after a major change.

Audit Considerations

HIPAA assessors expect a living contingency plan covering data backup, disaster recovery, and emergency mode — CP-2 is the umbrella. Specificity to real systems matters.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(7) Contingency Plan — standard requiring policies/procedures for responding to emergencies that damage systems with ePHI.
  • 164.308(a)(7)(ii)(A)–(C) — data backup, disaster recovery, and emergency-mode operation specs map into CP-2 content.
  • 164.310(a)(2)(i) Contingency Operations — facility access for restoration supports plan execution.
  • 164.312(a)(2)(ii) Emergency Access Procedure — emergency access during contingency events.

Compliance Tips

  • Put RTO/RPO decisions in a one-page table clinicians can understand.
  • Store the plan with HIPAA policies and assign a named owner.
  • After EHR go-live, schedule a CP-2 update within 30 days.

Frequently Asked Questions

Is CP-2 the same as a backup policy?

No. Backups are CP-9. CP-2 is the overall plan for continuity/recovery including roles, priorities, and activation.

Do cloud EHR customers still need CP-2?

Yes — cover vendor dependencies, downtime workflows, identity, and local systems that still hold ePHI.

How often should we update the plan?

At least annually and after tests, incidents, or major system changes.

References & Resources

  • NIST SP 800-53 Rev. 5 — CP-2
  • NIST SP 800-34 Contingency Planning Guide
  • HIPAA § 164.308(a)(7)
  • Related controls: CP-9, CP-10, IR-8, CP-3

Need Help Implementing CP-2?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.