HIPAA rule and data backup location
Health IT and Electronic Health Activate your FREE membership today |  Log-in
25 pts.
0
Q:
HIPAA rule and data backup location

Where in the HIPAA rule or updates does it say that covered
entities must keep data backups a minimum of five miles away from the original
site? Or, does it not say this? I’ve heard this in conversation and am looking
for a confirmation from any HIPAA experts.

ASKED: Dec 15 2011  2:34 PM GMT
0
250 pts.
0
A:
 RATE THIS ANSWER
0
Click to Vote:
  •   0
  •  0
  • AddThis Social Bookmark Button
HIPAA requires covered entities to develop plans and implement procedures to back up data and otherwise enable disaster recovery and continuity of operations, all under the contingency planning standard within the administrative safeguards described in 45 CFR 164.308. There is also language in the physical safeguards in 45 CFR 164.310 that data backups should include retrievable, exact copies of PHI before moving equipment, but this is an addressable standard, not a mandatory requirement. Nothing in the regulations specifies how backups must be performed, or where backup data must be stored. There are many backup service vendors that claim that HIPAA requires offsite storage of backed up data, but this simply isn't part of the security rule. This is not to say that offsite backup storage isn't a good idea - it's a well established security practice and arguably an essential component of a disaster recovery strategy. There is no statutory requirement covering offsite backup, and certainly no rule on the distance between offsite storage and the operational site.
Last Answered: Dec 16 2011  3:53 PM GMT by SteveGonHIT   250 pts.
0
0
Discuss This Answer:
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _



0