Orange County NC Website
2. The Data Backup Plan must apply to all medium and high risk files, records, images, <br /> voice or video files that may contain PHI and other essential business information. <br /> 3. The Data Backup Plan must require that all media used for backing up PHI and other <br /> essential business information be stored in a physically secure environment such as a <br /> secure, off-site storage facility or cloud server. Where backup media remains on site, it <br /> will be kept in a physically secure location, different from the location of the computer <br /> systems have been backed up. <br /> 4. If an off-site storage facility or backup service is used, a written Business Associate <br /> Agreement must entered into with the outside party maintaining the data to ensure <br /> that the Business Associate will safeguard any PHI and other essential business <br /> information in an appropriate manner. <br /> 5. Data backup procedures and contingency plan shall be tested on a periodic basis to <br /> ensure that exact copies of PHI and other essential business information can be <br /> retrieved and made available whenever it is needed. <br /> 6. The HIPAA Compliance Officer will ensure that each functional area of the Company <br /> with medium and high risk to PHI has an appropriate Data Backup Plan in place. <br /> Disaster Recovery Plan <br /> 1. To ensure that each functional area of North State Medical Transport can recover from <br /> the loss of data due to an emergency or disaster such as fire,vandalism,terrorism, <br /> system failure, or natural disaster affecting information systems containing PHI or other <br /> essential business information, each functional area will establish and implement a <br /> Disaster Recovery Plan. <br /> 2. The Plan must ensure that each area can restore or recover any loss of this information <br /> and the systems needed to make that information available in a timely manner. <br /> 3. The Disaster Recovery Plan will include procedures to restore PHI and other essential <br /> business information from data backups in the case of a disaster causing data loss. <br /> 4. The Disaster Recovery Plan will include procedures to log system outages, failures, and <br /> data loss to critical systems, and procedures to train the appropriate personnel to <br /> implement the disaster recovery plan. <br /> 5. The Disaster Recovery Plan must be documented and easily available to the necessary <br /> personnel at all time, who should be trained to implement the Disaster Recovery Plan. <br />