Primary data center cooling failure
Critical VMs fail over to the secondary region within RTO; clinicians reconnect via VPN; CP-7 agreements already covered burst cloud capacity.
CP-7 requires establishing an alternate processing site including necessary agreements to permit transfer and resumption of system operations for essential missions/business functions within organization-defined time periods when the primary site is unavailable, ensuring equivalent security controls, and preparing the site for readiness consistent with the recovery time objective. For healthcare this is the warm/hot site, secondary data center, or cloud DR region where ePHI workloads resume.
Resume essential clinical and ePHI system processing at an alternate site within defined RTOs when the primary facility or environment cannot operate.
How this control shows up in healthcare and HIPAA-covered environments.
Critical VMs fail over to the secondary region within RTO; clinicians reconnect via VPN; CP-7 agreements already covered burst cloud capacity.
Staff relocate to a contracted warm site with pre-staged workstations and printed downtime kits while identity and EHR tenant remain reachable.
Failover test shows EHR up but reference-lab MLLP routes absent. CP-7 corrective action adds interconnection readiness to the alternate site checklist.
Disaster recovery plan credibility hinges on a real alternate processing capability. Assessors ask for site evidence, contracts, and successful exercise results — not aspirational diagrams.
How this NIST control supports HIPAA Security Rule expectations.
Yes, when agreements, capacity, security controls, and tested activation meet CP-7 intent for your essential functions.
CP-6 stores backups/media offsite; CP-7 is where systems actually run again.
You still need alternate paths for identity, local systems, connectivity, and any on-prem dependencies that block clinical work.
Related controls that commonly accompany CP-7.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.