Regional power outage lasting 8 hours
Generators cover the clinic, but ISP fails. CP-2 activates downtime EHR procedures, routes phones, and prioritizes restoring identity + cloud EHR access ahead of nonclinical file shares.
CP-2 requires developing a contingency plan for the information system that identifies essential missions and business functions, provides recovery objectives, addresses roles and restoration priorities, and is reviewed, approved, and updated on a defined frequency and after plan tests or system changes. For clinics and hospitals this is the parent plan covering how ePHI systems continue or recover when disasters, outages, or ransomware hit.
Maintain an approved, current contingency plan so critical clinical and ePHI-supporting systems can be restored to agreed RTO/RPO targets with clear ownership.
How this control shows up in healthcare and HIPAA-covered environments.
Generators cover the clinic, but ISP fails. CP-2 activates downtime EHR procedures, routes phones, and prioritizes restoring identity + cloud EHR access ahead of nonclinical file shares.
Contingency plan separates IR containment from CP recovery: validated backups, restore order (domain → imaging → shares), and clinical communication scripts.
Vendor status page shows degraded performance. CP-2 vendor annex triggers downtime workflows and executive communications while IT monitors vendor RTO commitments.
HIPAA assessors expect a living contingency plan covering data backup, disaster recovery, and emergency mode — CP-2 is the umbrella. Specificity to real systems matters.
How this NIST control supports HIPAA Security Rule expectations.
No. Backups are CP-9. CP-2 is the overall plan for continuity/recovery including roles, priorities, and activation.
Yes — cover vendor dependencies, downtime workflows, identity, and local systems that still hold ePHI.
At least annually and after tests, incidents, or major system changes.
Related controls that commonly accompany CP-2.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.