Dtc Recovery

816 Words2 Pages

5. Business continuity and disaster recovery
DOTC provides a safe, secure video conferencing IT environment to serve its customers’ requirements, ensures stability of patient records and continuity of the business, and promotes confidence in its ability to not only continuously provide goods and/or services, but also to recover quickly from disaster and minimise disruption.

Statement of Policy
To establish and implement policies and procedures for responding to an emergency or other occurrence (e.g., fire, vandalism, system failure, natural disaster) that damages systems that contain Electronic Protected Health Information (ePHI). DOTC is committed to maintaining formal practices for responding to an emergency or other occurrence that damages …show more content…

The Security Officer shall test backup procedures on an annual basis to ensure that exact copies of ePHI can be retrieved and made available. Such testing shall be documented by the Security Officer. To the extent such testing indicates need for improvement in backup procedures, the Security Officer shall identify and implement such improvements in a timely manner.

2. Disaster Recovery and Emergency Mode Operations Plan

a. The Security Officer shall be responsible for developing and regularly updating the written disaster recovery and emergency mode operations plan for the purpose of:

i. Restoring or recovering any loss of ePHI and/or systems necessary to make ePHI available in a timely manner caused by fire, vandalism, terrorism, system failure, or other emergency; and ii. Continuing operations during such time information systems are unavailable. Such written plan shall have a sufficient level of detail and explanation that a person unfamiliar with the system can implement the plan in case of an emergency or disaster. Copies of the plan shall be maintained on-site and at the off-site locations at which backups are stored or other secure off-site …show more content…

An inventory of hard copy forms and documents needed to record clinical, registration, and financial interactions with patients. iv. Identification of an emergency response team. Members of such team shall be responsible for the following:
1. Determining the impact of a disaster and/or system unavailability on DOTC’s operations.
2. In the event of a disaster, securing the site and providing ongoing physical security.
3. Retrieving lost data.
4. Identifying and implementing appropriate “work-arounds” during such time information systems are unavailable.
5. Taking such steps necessary to restore operations.
v. Procedures for responding to loss of electronic data including, but not limited to retrieval and loading of backup data or methods for recreating data should backup data be unavailable. The procedures should identify the order in which data is to be restored based on the criticality analysis performed as part of DOTC’s risk analysis. vi. Telephone numbers and/or e-mail addresses for all persons to be contacted in the event of a disaster, including the following:
1. Members of the immediate response team,
2. Facilities at which backup data is stored,
3. Information systems vendors, and
4. All current workforce

Open Document