← HIPAA · Administrative safeguards
164.308(a)(7)(ii)(C) — Emergency mode operation plan (R)
medium
business-continuity
Requirement
Establish and implement procedures to enable continuation of critical business processes for protection of the security of electronic protected health information while operating in emergency mode.
What the engine looks for
Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.
Required element 1 — any one of
emergencydegradedcontingency
Required element 2 — any one of
operationcontinuecritical processplan
Supporting terms — specificity signals
break glassmanual processpaper fallbackemergency accessdocumented
Equivalent controls elsewhere
Matched on shared topics. Satisfying this control usually moves these too.
| Framework | Control | Title | Shared topics |
|---|---|---|---|
| SOC 2 | A1.3 | Recovery plan testing | business-continuity |
| ISO 27001 | A.5.29 | Information security during disruption | business-continuity |
| NIST CSF 2.0 | RC.RP-01 | The recovery portion of the incident response plan is executed | business-continuity |
| SOC 2 | CC9.1 | Risk mitigation for business disruption | business-continuity |