CP-9 Contingency Planning

Information System Backup

High Risk Moderate Medium Cost

CP-9 requires conducting backups of user-level and system-level information contained in the system, conducting backups of system documentation, and protecting the confidentiality, integrity, and availability of backup information. Under HIPAA this implements the data backup plan specification — backups that cannot be restored, or that attackers can delete, fail the control.

Control Objective

Produce reliable, protected backups of ePHI and supporting systems on a defined schedule, and ensure they can be restored within recovery objectives.

Implementation Guidance

  1. Inventory what must be backed up: EHR databases, imaging, file shares with ePHI, virtual machines, identity configs, and system documentation.
  2. Set backup frequency from RPO (e.g., hourly DB logs, nightly fulls).
  3. Encrypt backups at rest and in transit; restrict admin access to backup consoles.
  4. Keep offline, immutable, or out-of-band copies resistant to ransomware.
  5. Separate backup credentials from daily domain admin accounts.
  6. Document retention aligned with clinical, legal, and HIPAA needs.
  7. Test restores on a schedule (see CP-10) and record results.
  8. Cover SaaS/BA data — confirm contractual backup responsibilities and export options.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Ransomware deletes volume snapshots

Attackers with backup console access wipe on-prem snapshots. CP-9 immutable object-lock / offline copies still allow restore — lessons learned separate backup admins from domain admins.

Corrupted EHR database overnight

Point-in-time backup + transaction logs meet a 15-minute RPO; clinical ops resume after validated restore.

Imaging archive only on one NAS

PACS studies lived on a single array. CP-9 adds replicated encrypted backup to a second site before a disk failure would have caused permanent loss.

Best Practices

  • 3-2-1 (or better) backup rule with immutability.
  • Encrypt and access-control backup media/stores.
  • Test restores, not only backup job 'green' status.
  • Protect backup admin paths with MFA and least privilege.
  • Include configuration/documentation backups.
  • Clarify SaaS shared-responsibility backups in BAAs.

Common Gaps & Violations

  • Backups succeed but never restored in testing.
  • Backup admin is domain admin — ransomware deletes backups.
  • Unencrypted portable backup drives.
  • Cloud EHR assumed 'backed up' with no contractual clarity.
  • No backup of system documentation/runbooks.

Required Documentation

  • Backup policy and job schedules
  • Inventory of protected systems/data classes
  • Encryption and access-control settings for backup stores
  • Retention schedule
  • Restore test records

How to Test & Validate

  1. Inspect last 14 days of backup job results for critical systems.
  2. Perform a sample file and database restore in a non-prod target.
  3. Verify backup encryption and access lists.
  4. Confirm immutable/offline copy existence.
  5. Review SaaS/BA backup commitments vs reality.

Audit Considerations

Assessors ask for restore evidence, not screenshots of backup software. HIPAA data backup plan findings often cite untested or unprotected backups.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(7)(ii)(A) Data Backup Plan — establish and implement procedures to create and maintain retrievable exact copies of ePHI.
  • 164.310(d)(2)(iv) Data Backup and Storage — physical/technical safeguards for backup media when applicable.
  • 164.312(a)(2)(iv) Encryption — addressable encryption commonly applied to backup stores.
  • 164.312(c) Integrity — protect ePHI from improper alteration/destruction including backup copies.

Compliance Tips

  • Schedule quarterly restore tests with sign-off.
  • Put backup console behind MFA and separate tier-0 credentials.
  • Document who owns SaaS backup responsibility in writing.

Frequently Asked Questions

Are cloud provider snapshots enough for CP-9?

Only if they meet your RPO, protection, and restore needs — and responsibilities are clear. Many orgs still need independent exports or immutable copies.

How does CP-9 relate to CP-10?

CP-9 creates protected backups; CP-10 recovers and reconstitutes systems using those backups (and other methods).

Must backups be encrypted?

Encryption is addressable under HIPAA but strongly expected for portable/offsite backup media containing ePHI; document your risk-based decision.

References & Resources

  • NIST SP 800-53 Rev. 5 — CP-9
  • NIST SP 800-34
  • HIPAA §§ 164.308(a)(7)(ii)(A), 164.310(d)
  • Related controls: CP-2, CP-10, MP-4, SC-13

Need Help Implementing CP-9?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.