Ransomware deletes volume snapshots
Attackers with backup console access wipe on-prem snapshots. CP-9 immutable object-lock / offline copies still allow restore — lessons learned separate backup admins from domain admins.
CP-9 requires conducting backups of user-level and system-level information contained in the system, conducting backups of system documentation, and protecting the confidentiality, integrity, and availability of backup information. Under HIPAA this implements the data backup plan specification — backups that cannot be restored, or that attackers can delete, fail the control.
Produce reliable, protected backups of ePHI and supporting systems on a defined schedule, and ensure they can be restored within recovery objectives.
How this control shows up in healthcare and HIPAA-covered environments.
Attackers with backup console access wipe on-prem snapshots. CP-9 immutable object-lock / offline copies still allow restore — lessons learned separate backup admins from domain admins.
Point-in-time backup + transaction logs meet a 15-minute RPO; clinical ops resume after validated restore.
PACS studies lived on a single array. CP-9 adds replicated encrypted backup to a second site before a disk failure would have caused permanent loss.
Assessors ask for restore evidence, not screenshots of backup software. HIPAA data backup plan findings often cite untested or unprotected backups.
How this NIST control supports HIPAA Security Rule expectations.
Only if they meet your RPO, protection, and restore needs — and responsibilities are clear. Many orgs still need independent exports or immutable copies.
CP-9 creates protected backups; CP-10 recovers and reconstitutes systems using those backups (and other methods).
Encryption is addressable under HIPAA but strongly expected for portable/offsite backup media containing ePHI; document your risk-based decision.
Related controls that commonly accompany CP-9.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.