Call Us (877) 740-5028
Disaster Prevention is typically thought of in terms of “High Availability” – or redundant systems to assure that there is no single point of failure on the delivery of the application or data. Examples of high availability at the data center level include high availability power delivery through redundant generators, uninterruptible power supplies (UPSs), power distribution units (PDUs), and redundant power supplies in the servers. With high availability power, the failure of any element (generator, UPS, or power supply) does not affect the availability of the application – since the entire infrastructure is redundant.
Redundancy can also be delivered in the cloud server platform. For example, HIPAA compliant cloud servers run on redundant hardware hosts with multiple power supplies, multiple network connections to SANs, redundant controllers and redundant RAID drives. Again, any hardware failure or even complete shutdown of a hardware hosts will not affect the availability of the application and the PHI data.
Disaster Recovery is typically thought of in terms of Recovery Time Objective (RTO) and Recovery Point Objective (RPO). RTO is the amount of time it takes to spin up the servers, network, application and data as a separate data center in the case that the application is shut down from a disaster.
RTOs can range from minutes to weeks depending on the technology selected. RPO is defined as how close to the disaster the data can be recovered, which is tied to how often the data is backed up. If backups are made every night, then the RPO is 24 hours (up to 24 hours of data can be lost). If continuous replication is used, the loss may be as short as a few minutes. The shorter the RTO and RPO, the better.
As a minimum, all HIPAA applications should use offsite backup. That way, if the production data center has a disaster or is destroyed, the PHI isn’t lost. The backup should be located a significant distance away to assure the same disaster doesn’t strike both sites. Every region of the country has a recommended best practices for geographic separation; in the Midwest, it’s at least 50 miles apart.
For critical PHI, a warm site disaster recovery infrastructure is ideal. Warm site disaster recovery means that the entire server environment is replicated including operating systems, applications, data, network and firewall setttings so that it is ready and waiting to take over at a moment’s notice. Several years ago, warm site disaster recovery was difficult and expensive.
Now, with the advent of cloud computing, disaster recovery has become very cost-effective. The advent of Disaster Recovery as a Service has made disaster recovery easier and more simple than before, with a service provider managing and maintaining all of the components that come with a proper disaster recovery site.
When you evaluate meeting HIPAA availability requirements for your health care applications and PHI, ask two key questions:
How you answer these questions is critical to compliance with the availability criteria of HIPAA and the HITECH Act.
Next week we will look at an organizations security training and knowing where to find your security policy documents.
References:
Disaster Recovery for HIPAA Applications – It’s All About Availability of PHI
HIPAA Glossary of Terms
HIPAA Resources: Policies, Procedures and Training Materials
For HIPAA Compliant hosting, call 877.740.5028 or email contactus@onlinetech.com