CP-6 Contingency Planning

Alternate Storage Site

High Risk Moderate Medium Cost

CP-6 requires establishing an alternate storage site including necessary agreements to permit storage and retrieval of system backup information, and ensuring the alternate site provides security controls equivalent to the primary site. Geographic and logical separation protects ePHI backups when the primary facility, data center, or cloud region is damaged, inaccessible, or ransomware-impacted.

Control Objective

Store protected, retrievable copies of ePHI and system backups at an alternate site that remains accessible when the primary location is unavailable.

Implementation Guidance

  1. Select alternate storage with sufficient geographic/logical separation from the primary site (second region, second provider, or bonded offsite vault).
  2. Execute agreements covering access, retrieval SLAs, encryption, and destruction of media.
  3. Apply security controls equivalent to primary: encryption, access control, environmental protection, and logging.
  4. Align what is stored at the alternate site with CP-9 backup sets needed for RTO/RPO.
  5. Document retrieval procedures for nights/weekends and ransomware scenarios (immutable object storage counts when controls meet intent).
  6. Test retrieval periodically as part of CP-4 — not only replication job status.
  7. Restrict who can delete or alter alternate-site copies; separate credentials from daily domain admins.
  8. Cover imaging archives and system documentation, not only EHR databases.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Clinic fire damages on-prem backup appliances

Nightly replication to an encrypted second-region object store with object lock still holds ePHI backups — CP-6 alternate storage enables CP-10 recovery.

Tape vault retrieval drill

Quarterly test retrieves a sealed tape set within the contracted SLA; custody logs and encryption key access are verified.

Same-building 'offsite' failure

Backups sat in a closet across the hall. A CP-6 review moves copies to a true alternate site so a single facility event cannot destroy both sets.

Best Practices

  • True separation from primary risk events.
  • Equivalent security controls at the alternate site.
  • Written retrieval agreements and SLAs.
  • Immutable/offline copies where ransomware is a threat.
  • Periodic retrieval tests.
  • Separate privileged access to alternate stores.

Common Gaps & Violations

  • Backups only on the same SAN as production.
  • 'Cloud sync' without access controls or immutability.
  • No agreement for after-hours retrieval.
  • Weaker physical/crypto controls at the vault.
  • Never tested whether staff can actually retrieve media.

Required Documentation

  • Alternate storage site designation and rationale
  • Contracts/agreements with retrieval SLAs
  • Security control summary vs primary site
  • Inventory of what is stored offsite
  • Retrieval test records

How to Test & Validate

  1. Confirm geographic/logical separation rationale is documented.
  2. Review contract access and retrieval terms.
  3. Compare encryption/access controls to primary standards.
  4. Perform a sample retrieval or restore from the alternate store.
  5. Verify deletion protection / immutability settings.

Audit Considerations

HIPAA data backup expectations include retrievable copies outside a single point of failure. CP-6 evidence is site designation, agreements, equivalent safeguards, and retrieval proof.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(7)(ii)(A) Data Backup Plan — maintain retrievable exact copies of ePHI; alternate storage supports retrievability after site loss.
  • 164.310(d)(2)(iv) Data Backup and Storage — physical/technical safeguards for backup media and storage locations.
  • 164.312(a)(2)(iv) Encryption — addressable encryption commonly required for offsite backup media/stores.
  • 164.308(a)(1) Risk Analysis — site-loss and ransomware scenarios drive alternate storage design.

Compliance Tips

  • Name the alternate site (or cloud region/account) explicitly in the contingency plan.
  • Put object-lock / immutability on the alternate store used for ransomware resilience.
  • Schedule a retrieval test on the same calendar as CP-4.

Frequently Asked Questions

Does a second availability zone count as CP-6?

It can if it meets separation and equivalent-control intent for your risk scenarios; document why it survives the threats you care about.

How is CP-6 different from CP-9?

CP-9 is performing and protecting backups; CP-6 is the alternate location/agreement that stores those backups away from the primary site.

Do SaaS EHR customers need CP-6?

Confirm the vendor's multi-site backup posture in the BAA/SLA and still apply CP-6 to any local systems and exports you control.

References & Resources

  • NIST SP 800-53 Rev. 5 — CP-6
  • NIST SP 800-34 Contingency Planning Guide
  • Related controls: CP-7, CP-9, MP-4, CP-2

Need Help Implementing CP-6?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.