Orange County NC Website
Policy 25: Policy on Contingency Planning <br /> North State Medical Transport <br /> Contingency Planning Policy <br /> Purpose <br /> The Health Insurance Portability and Accountability Act of 1996 ("HIPAA") requires <br /> North State Medical Transport to implement a policy to ensure that we effectively protect the <br /> integrity of protected health information ("PHI")that we hold in the event of an emergency. <br /> This policy ensures that our response to an emergency or other occurrence that threatens or <br /> damages our computer, electronic, or other information systems is appropriate and provides <br /> for the contingencies necessary to protect and preserve PHI in accordance with the HIPAA. <br /> Scope <br /> This policy contains procedures for protecting the integrity of PHI (including e-PHI) and <br /> other essential patient information, billing and business information, and confidential <br /> information in the event of an emergency or other occurrence (i.e.,fire,vandalism, system <br /> failure and natural disaster). The HIPAA Compliance Officer shall oversee the implementation <br /> of these procedures. <br /> Procedure <br /> Applications and Data Criticality Analysis <br /> 1. North State Medical Transport will assess the relative criticality of specific applications <br /> and data within the company for purposes of developing its Data Backup Plan, its <br /> Disaster Recovery Plan and its Emergency Mode Operation Plan. <br /> 2. The assessment of data and application criticality should be conducted periodically and <br /> at least annually as part of the Security Risk Analysis to ensure that appropriate <br /> procedures are in place for data and applications at each level of risk. <br /> Data Backup Plan <br /> 1. Each functional area of North State Medical Transport (Operations, Billing, <br /> Administration, etc.) will establish and implement a Data Backup Plan that ensures that <br /> each area of North State Medical Transport will create and maintain retrievable exact <br /> copies of all PHI and other essential business information that is at a medium to high <br /> risk for destruction or disruption. <br />