CP-7 Contingency Planning

Alternate Processing Site

High Risk Complex High Cost

CP-7 requires establishing an alternate processing site including necessary agreements to permit transfer and resumption of system operations for essential missions/business functions within organization-defined time periods when the primary site is unavailable, ensuring equivalent security controls, and preparing the site for readiness consistent with the recovery time objective. For healthcare this is the warm/hot site, secondary data center, or cloud DR region where ePHI workloads resume.

Control Objective

Resume essential clinical and ePHI system processing at an alternate site within defined RTOs when the primary facility or environment cannot operate.

Implementation Guidance

  1. Identify essential functions that need alternate processing (EHR access, e-prescribing, lab interfaces, identity, telephony) vs deferrable workloads.
  2. Choose site type (hot/warm/cloud DR) matching RTO/RPO from CP-2; document capacity and licensing.
  3. Execute agreements for space, power, network, cloud capacity, and physical/logical access.
  4. Apply security controls equivalent to primary (AC, AU, SC, PE as applicable).
  5. Keep configurations, runbooks, and credentials available for activation; automate replication where RTO is aggressive.
  6. Include network paths to BAs, HIEs, and cloud EHR from the alternate site.
  7. Test failover/failback under CP-4; measure time to clinical usability, not only VM power-on.
  8. Plan workforce access: VPN, badge access to DR location, or remote clinical workflows.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Primary data center cooling failure

Critical VMs fail over to the secondary region within RTO; clinicians reconnect via VPN; CP-7 agreements already covered burst cloud capacity.

Flood closes the ambulatory hub

Staff relocate to a contracted warm site with pre-staged workstations and printed downtime kits while identity and EHR tenant remain reachable.

DR site missing lab interface routes

Failover test shows EHR up but reference-lab MLLP routes absent. CP-7 corrective action adds interconnection readiness to the alternate site checklist.

Best Practices

  • Match site capability to published RTOs.
  • Equivalent security controls at the alternate site.
  • Pre-stage licensing, DNS, certs, and BA routes.
  • Test clinical usability after failover.
  • Document failback criteria.
  • Cover people access to the alternate site.

Common Gaps & Violations

  • DR site named in a plan but never provisioned.
  • Replication exists; nobody can authenticate from the alternate path.
  • Weaker security at DR 'because it is temporary'.
  • No agreements for surge capacity.
  • Failover never timed with real clinical workflows.

Required Documentation

  • Alternate processing site designation and site type
  • Contracts/capacity agreements
  • Equivalent control attestation
  • Activation/failback runbooks
  • Failover test results vs RTO

How to Test & Validate

  1. Verify agreements and capacity cover essential systems.
  2. Confirm security controls at alternate site meet policy.
  3. Review last failover test timing against RTO.
  4. Trace BA/HIE connectivity from the alternate path.
  5. Check workforce access procedures for DR activation.

Audit Considerations

Disaster recovery plan credibility hinges on a real alternate processing capability. Assessors ask for site evidence, contracts, and successful exercise results — not aspirational diagrams.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(7)(ii)(B) Disaster Recovery Plan — establish processes to restore lost data/operations; alternate processing enables restoration of essential functions.
  • 164.308(a)(7)(ii)(C) Emergency Mode Operation Plan — continue critical business processes that protect ePHI during emergencies.
  • 164.310(a)(2)(i) Contingency Operations — facility access procedures for restoration/alternate operations.
  • 164.312(a)(2)(ii) Emergency Access Procedure — access to ePHI during emergency processing at alternate sites.

Compliance Tips

  • Put alternate-site activation criteria in one page clinicians and executives can follow.
  • Include identity and DNS in the first restore wave — apps fail without them.
  • Revisit cloud DR spend against actual RTO annually with clinical leaders.

Frequently Asked Questions

Is cloud DR an alternate processing site?

Yes, when agreements, capacity, security controls, and tested activation meet CP-7 intent for your essential functions.

How does CP-7 differ from CP-6?

CP-6 stores backups/media offsite; CP-7 is where systems actually run again.

Do we need a second building if we use cloud EHR?

You still need alternate paths for identity, local systems, connectivity, and any on-prem dependencies that block clinical work.

References & Resources

  • NIST SP 800-53 Rev. 5 — CP-7
  • NIST SP 800-34 Contingency Planning Guide
  • Related controls: CP-2, CP-6, CP-8, CP-10, CP-9

Need Help Implementing CP-7?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.