New charge nurse on nights
Within two weeks of assuming the role, she completes CP-3 downtime module: paper MAR, downtime EHR login, and who to call when cloud EHR is unreachable — before the next planned outage.
CP-3 requires providing contingency training to system users consistent with assigned roles and responsibilities, within a defined period of assuming a contingency role, when required by system changes, and at a defined frequency thereafter. Training covers how people execute the contingency plan — not only that a plan document exists. Clinics and hospitals need role-specific downtime and recovery training for charge nurses, HIM, registration, pharmacy, IT, and leadership.
Ensure workforce members with contingency roles can perform their downtime and recovery duties for systems that create, receive, maintain, or transmit ePHI.
How this control shows up in healthcare and HIPAA-covered environments.
Within two weeks of assuming the role, she completes CP-3 downtime module: paper MAR, downtime EHR login, and who to call when cloud EHR is unreachable — before the next planned outage.
After go-live, registration and billing staff receive updated contingency training on the new vendor status page, downtime forms, and identity failover — CP-3 triggers on system change.
Front-desk leads train on activating ISP failover and printed schedules so contingency roles work when the sole technician is unavailable.
HIPAA contingency plan effectiveness depends on people who can execute it. Assessors look for role-based training evidence, not only a signed plan.
How this NIST control supports HIPAA Security Rule expectations.
No. CP-3 is role-specific contingency training for people who execute the plan, beyond general awareness (AT-2).
Anyone with a contingency role in CP-2 — clinical downtime leads and IT recoverers, not only the CISO.
CP-3 builds knowledge; CP-4 tests the plan. Exercises both validate training and identify retraining needs.
Related controls that commonly accompany CP-3.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.