Linking HIPAA Contingency Plans to CMS Emergency Preparedness

Skilled nursing and long-term care facilities are familiar with emergency preparedness. CMS requires an emergency plan, a risk assessment, communication procedures, policies and training, and annual testing. Those same facilities also have to meet HIPAA's contingency planning requirements for electronic protected health information. Too often the two live in separate binders, written by different people, with the IT portion missing from one or both.

Connecting them saves effort and closes gaps.

The Two Requirements in Brief

CMS Emergency Preparedness

The CMS Emergency Preparedness Requirements for long-term care facilities call for an all-hazards approach. A facility must have an emergency plan based on a risk assessment, policies and procedures, a communication plan, and training and testing. Facilities are expected to review these at least annually.

HIPAA Contingency Plan

The HIPAA Security Rule requires a contingency plan covering several parts:

A data backup plan, which is required

A disaster recovery plan, which is required

An emergency mode operation plan, which is required

Testing and revision procedures, which are addressable

An applications and data criticality analysis, which is addressable

Where They Overlap

Both ask the same underlying questions: what could disrupt operations, how will you keep caring for residents, how will you communicate, and how will you restore normal service. The IT dimension is the shared thread. A hurricane, tornado, ice storm, fire, power failure or cyberattack can all take systems offline, and Oklahoma, Texas and Arkansas facilities face severe weather regularly.

Step 1: Add Technology to Your Risk Assessment

Your CMS hazard vulnerability assessment likely lists weather, fire, pandemic and utility failures. Add technology-specific hazards such as ransomware, loss of internet, loss of the EHR vendor, server failure and loss of phone service. Rate each by likelihood and impact, as you do for other hazards.

Step 2: Identify Critical Systems

HIPAA's applications and data criticality analysis asks which systems are essential. Create a ranked list:

Medication administration and the resident record

Nurse call and communication systems

Phones and internet access

Pharmacy and lab connections

Billing, payroll and scheduling

Everything else

For each, record who owns it, how long it can be down and how it is restored.

Step 3: Document Backup and Recovery

For every critical system, note where backups are stored, how often they run, who can restore them, how long restoration takes and when it was last tested. Include contact details for vendors and the IT provider, and keep a printed copy offsite or in a place that does not depend on the network.

Step 4: Plan for Emergency Mode Operation

HIPAA requires procedures for continuing critical business processes while operating in emergency mode. Translate that into practical downtime procedures: paper medication administration records, printed census and emergency contact lists, offline copies of key resident information such as allergies and code status, and a clear process for entering information once systems are restored.

Step 5: Align Communications

Your CMS communication plan lists contacts for staff, families, physicians and authorities. Add IT contacts, the EHR vendor, the internet and phone carriers, and your cyber insurance hotline. Decide how staff will be reached if email and phones fail.

Step 6: Test Together

CMS requires annual exercises. Include a technology scenario in one of them, such as an extended internet outage or a ransomware event. Observe how staff switch to paper, how quickly IT responds and how well communication works. Record lessons learned and update both plans.

Step 7: Review on One Calendar

Schedule one annual review that covers both documents, with the administrator, director of nursing, maintenance lead, security officer and IT provider in the room. Update after any real event or significant change.

Keep Evidence

Document test results, attendance and plan revisions. Surveyors and auditors appreciate seeing that the plans are used and revised rather than shelved.

Practical Help

UnityCare IT can help inventory critical systems, document recovery steps and run a technology tabletop exercise, so your emergency plan and your HIPAA contingency plan tell one consistent story.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034