ASTM E2682-09(2014)
(Guide)Standard Guide for Developing a Disaster Recovery Plan for Medical Transcription Departments and Businesses (Withdrawn 2023)
Standard Guide for Developing a Disaster Recovery Plan for Medical Transcription Departments and Businesses (Withdrawn 2023)
SIGNIFICANCE AND USE
4.1 This guide acknowledges the importance of a well-designed disaster recovery plan that will protect health information and business information from damage, minimize disruption, ensure integrity of data, and provide for orderly recovery.
4.2 This guide suggests methods to protect the confidentiality and security of healthcare documentation during a disaster.
4.3 It is intended that this guide will contribute to compliance with laws and regulations to improve protection of health information documentation and data integrity with the development of the contingency plan requirement.
4.4 This guide will explain key points to include in preparing a disaster recovery plan to resume operations and minimize losses due to unscheduled interruption of critical services if a disaster would occur.
4.5 This guide is intended to assist in the development of appropriate policies and procedures that provide protection for individually identifiable health information in a secure environment in the event of a disaster.
SCOPE
1.1 This guide applies across multiple medical transcription settings in which healthcare documents are generated and stored: medical transcription departments, home offices, and medical transcription service organizations (MTSOs). Currently there is no standard disaster recovery plan in the medical transcription industry to provide guidelines for individuals, departments, and businesses to use for designing a disaster recovery plan for their medical transcription environment.
1.2 A disaster is when a sudden event brings great damage, loss, destruction, or interruption of critical services. These guidelines could assist in developing an organized response to reduce the time for loss of services, maintain continuity of workflow, and speed the overall business recovery process.
1.3 This guide supports the HIPAA Security Rule for ensuring data integrity with a contingency plan to include a data backup plan, a disaster recovery plan, and an emergency mode operational plan.2
1.4 This guide is consistent with the requirement for disaster planning and recovery procedures as stated in Guide E1959.
1.5 This guide is not intended as a disaster recovery plan for Health Information Management Departments or for an entire healthcare facility.
WITHDRAWN RATIONALE
This guide applies across multiple medical transcription settings in which healthcare documents are generated and stored: medical transcription departments, home offices, and medical transcription service organizations (MTSOs).
Formerly under the jurisdiction of Committee E31 on Healthcare Informatics, this guide was withdrawn in January 2023 in accordance with section 10.6.3 of the Regulations Governing ASTM Technical Committees, which requires that standards shall be updated by the end of the eighth year since the last approval date.
General Information
Standards Content (Sample)
NOTICE: This standard has either been superseded and replaced by a new version or withdrawn.
Contact ASTM International (www.astm.org) for the latest information
Designation: E2682 − 09 (Reapproved 2014)
Standard Guide for
Developing a Disaster Recovery Plan for Medical
Transcription Departments and Businesses
This standard is issued under the fixed designation E2682; the number immediately following the designation indicates the year of
original adoption or, in the case of revision, the year of last revision. A number in parentheses indicates the year of last reapproval. A
superscript epsilon (´) indicates an editorial change since the last revision or reapproval.
1. Scope 2. Referenced Documents
2.1 ASTM Standards:
1.1 This guide applies across multiple medical transcription
E1869 Guide for Confidentiality, Privacy, Access, and Data
settings in which healthcare documents are generated and
SecurityPrinciplesforHealthInformationIncludingElec-
stored: medical transcription departments, home offices, and
tronic Health Records (Withdrawn 2017)
medical transcription service organizations (MTSOs). Cur-
E1959 Guide for Requests for Proposals Regarding Medical
rentlythereisnostandarddisasterrecoveryplaninthemedical
Transcription Services for Healthcare Institutions
transcription industry to provide guidelines for individuals,
2.2 Other Documents:
departments, and businesses to use for designing a disaster
Public Law 104-191 Health Insurance Portability and Ac-
recovery plan for their medical transcription environment.
countability Act of 1996 (HIPAA)
1.2 Adisaster is when a sudden event brings great damage,
45 CFR Part 142 Security and Electronic Signature Stan-
loss, destruction, or interruption of critical services. These
dards
guidelines could assist in developing an organized response to
3. Terminology
reduce the time for loss of services, maintain continuity of
workflow, and speed the overall business recovery process.
3.1 Definitions:
3.1.1 author, n—the person originating content for a health-
1.3 This guide supports the HIPAA Security Rule for
care document.
ensuring data integrity with a contingency plan to include a
3.1.2 backups, n—retrievable, exact copies of data. The
data backup plan, a disaster recovery plan, and an emergency
primary method for ensuring that organizations can recover
mode operational plan.
from a system crash or disaster.
1.4 Thisguideisconsistentwiththerequirementfordisaster
3.1.3 confidential, adj—status accorded to data or informa-
planning and recovery procedures as stated in Guide E1959.
tion indicating that it is sensitive for some reason, and
therefore, it needs to be protected against theft, disclosure, or
1.5 Thisguideis notintendedasadisasterrecovery plan for
improper use, or a combination thereof, and must be dissemi-
Health Information Management Departments or for an entire
nated only to authorized individuals or organizations with a
healthcare facility.
need to know. E1869
1.6 This international standard was developed in accor-
3.1.4 confidentiality, n—the property that information is not
dance with internationally recognized principles on standard-
made available or disclosed to unauthorized individuals,
ization established in the Decision on Principles for the
entities, or processes. 45 CFR Part 142
Development of International Standards, Guides and Recom-
3.1.5 contingency plan, n—an alternate way of doing busi-
mendations issued by the World Trade Organization Technical
ness when established routines are disrupted.
Barriers to Trade (TBT) Committee.
For referenced ASTM standards, visit the ASTM website, www.astm.org, or
This guide is under the jurisdiction of ASTM Committee E31 on Healthcare contact ASTM Customer Service at service@astm.org. For Annual Book of ASTM
Informatics and is the direct responsibility of Subcommittee E31.15 on Healthcare Standards volume information, refer to the standard’s Document Summary page on
Information Capture and Documentation. the ASTM website.
CurrenteditionapprovedJune1,2014.PublishedJuly2014.Originallyapproved The last approved version of this historical standard is referenced on
in 2009. Last previous edition approved in 2009 as E2682- 09. DOI: 10.1520/ www.astm.org.
E2682-09R14. Available from the U.S. Department of Health & Human Services, 200
AvailablefromU.S.GovernmentPrintingOfficeSuperintendentofDocuments, Independence Avenue, S.W., Washington, D.C., 20201, www.hhs.gov.
732 N. Capitol St., NW, Mail Stop: SDE, Washington, DC 20401. See also Medical Records Disaster Planning, A Health Information Manager’s Survival
http://aspe.hhs.gov/admnsimp. Guide, AHIMA, Chicago, IL.
Copyright © ASTM International, 100 Barr Harbor Drive, PO Box C700, West Conshohocken, PA 19428-2959. United States
E2682 − 09 (2014)
3.1.6 disaster, n—a sudden event bringing great damage, 4.4 This guide will explain key points to include in prepar-
loss, destruction or interruption of critical services. ingadisasterrecoveryplantoresumeoperationsandminimize
losses due to unscheduled interruption of critical services if a
3.1.7 individually identifiable health information, n—any
disaster would occur.
information, including demographic information collected
4.5 This guide is intended to assist in the development of
from an individual, that (1) is created or received by a health
appropriate policies and procedures that provide protection for
care provider, health plan, employer, or health care clearing-
individually identifiable health information in a secure envi-
house; and (2) relates to the past, present, or future physical or
ronment in the event of a disaster.
mental health or condition of an individual, the provision of
health care to an individual, or the past, present, or future
5. Elements of Disaster Recovery Planning
payment for the provision of health care to an individual, and
NOTE 1—Disaster recovery planning includes the identification of key
(i) identifies the individual, or (ii) with respect to which there
components of a disaster recovery plan, gathering the necessary informa-
isareasonablebasistobelievethattheinformationcanbeused
tion to provide the details to tailor the plan to meet the organization’s
to identify the individual. Public Law 104-191, needs, formalization and approval of the disaster recovery plan, annual
testing of the implementation of the requisite disaster recovery action, and
Section 1171 (6)
formal review and necessary revision of the disaster recovery plan.
3.1.8 privacy, n—the right of an individual to be left alone 7
5.1 Activation of Response Plan:
and to be protected against physical or psychological invasion
5.1.1 Policy Statement:
or misuse of their property. It includes freedom from intrusion
5.1.1.1 To ensure that the plan is effective and that all
or observation into one’s private affairs, the right to maintain
involved understand its purpose, there must be a clearly
control over certain personal information, and the freedom to
defined policy statement. This statement should define the
act without outside interference. E1869
scope and overall objectives of the plan.
5.1.2 Table of Contents.
3.1.9 provider, n—a business entity which furnishes health
5.1.3 Introduction:
care to a consumer; it includes a professionally licensed
5.1.3.1 Use of the document.
practitioner who is authorized to operate a healthcare delivery
5.1.3.2 How it is to be revised.
system. E1869
5.1.3.3 Training requirements.
3.1.10 secure environment, n—free from access by unau-
5.1.3.4 Exercise and testing schedules.
thorized persons and from unauthorized or accidental altera-
5.1.3.5 Plan maintenance schedule.
tion.
5.1.3.6 Roles and responsibilities.
5.1.3.7 General information about the facility.
3.1.11 security, n—encompasses all of the safeguards in an
5.1.3.8 Compliance with federal, state, local, and health
information system, including hardware, software, personnel
regulatory agencies.
policies, information practice policies, disaster preparedness,
5.1.4 Emergency Information Sheet:
and the oversight of all these areas. The purpose is to protect
5.1.4.1 Fire/police departments.
both the system and the information it contains from unauthor-
5.1.4.2 Hospitals.
ized access from without and from misuse from within.
5.1.4.3 Emergency shut-off.
45 CFR Part 142
5.1.4.4 Utility companies.
3.2 Acronyms:
5.1.4.5 Other agencies needed for an emergency.
3.2.1 HIPAA—Health Insurance Portability and Account-
5.1.4.6 Telephone/reporting tree.
ability Act
5.1.4.7 List of assistance/equipment vendors.
5.1.5 Resource Priorities:
3.2.2 MT—medical transcriptionist
5.1.5.1 Personnel.
3.2.3 MTSO—medical transcription service organization
5.1.5.2 Records.
5.1.5.3 Technology.
4. Significance and Use
5.1.6 Plan Activation with Response Outline:
5.1.6.1 Lead personnel responsibilities.
4.1 This guide acknowledges the importance of a well-
5.1.6.2 Assessing the situation.
designed disaster recovery plan that will protect health infor-
5.1.6.3 Organizing/prioritizing efforts.
mation and business information from damage, minimize
5.1.6.4 Establishing a command post.
disruption, ensure integrity of data, and provide for orderly
5.1.6.5 Eliminating hazards.
recovery.
5.1.6.6 Controlling the environment.
4.2 This guide suggests methods to protect the confidenti-
5.1.6.7 Dealing with media.
ality and security of healthcare documentation during a disas-
5.1.6.8 Obtaining emergency services/supplies.
ter.
5.1.6.9 Providing security.
4.3 It is intended that this guide will contribute to compli-
ance with laws and regulations to improve protection of health
The U.S. National Archives & Records Administration. www.archives.gov.
information documentation and data integrity with the devel-
Vital Records and Records Disaster Mitigation and Recovery: An Instructional
opment of the contingency plan requirement. Guide.
E2682 − 09 (2014)
5.1.6.10 Providing personnel needs. 5.2.1.3 Designation of the individual position/department in
5.1.7 Activation of Recovery Procedures: charge of making short-term emergency decisions.
5.1.7.1 Obtaining authorization to access damaged facilities 5.2.1.4 Designation of the individual position/department in
or geographic areas or both. charge of transitioning from emergency mode back to normal
5.1.7.2 Notifying personnel. business mode.
5.1.7.3 Notifying utilities and other agencies required for 5.2.2 The essence of writing a disaster recovery plan is to
resuming business. think ahead and create a unified plan that addresses all defined
5.1.7.4 Obtaining supplies needed for business. disaster scenarios (internal and external). Be aware that during
5.1.7.5 Obtaining and installing necessary hardware com- adisaster,individualsmaynotbeabletocallin,login,orwalk
ponents. in.
5.1.7.6 Obtaining and loading backup media. 5.2.2.1 Natural—hurricane, tornado, flood, snow, ice, fire,
5.1.7.7 Restoring critical operating system and application earthquake, etc.
software. 5.2.2.2 Human—disastrous employee error, sabotage, virus,
5.1.7.8 Restoring system data. terrorism, etc.
5.1.7.9 Testing system functionality including security con- 5.2.2.3 Environment—disastrous equipment failure, soft-
trols. ware corruption, telecommunications network outage, electri-
5.1.7.10 Connecting system to network or other external cal failure, etc.
systems.
5.3 The Planning Process:
5.1.7.11 Resume equipment operations.
5.3.1 To be successful, senior management must support the
5.1.8 Termination of Disaster Recovery Operations:
plan and be included in the process to develop the policy
5.1.8.1 Designated authority declares the end of disaster
statement and the plan.
recoveryoperationsanddisseminatesthatannouncementtothe
5.3.2 Whenpoliciesandproceduresaredevelopedrelatedto
communications network.
the disaster recovery plan, they need to be coordinated with
5.1.8.2 Arrange for all personnel to return to work.
relatedorganizationalactivities,includinginformationtechnol-
5.1.8.3 Resume standard operating procedures.
ogy security, physical security, human resources, risk
5.1.8.4 Complete comprehensive post event evaluation,
management, quality assurance, information technology
conduct review of the adequacy of the existing disaster
operations, and administrative services.
recovery plan, and revise the plan if necessary.
5.4 Thedisasterplanningprocessshouldincludethefollow-
5.1.9 Appendices:
ing key steps:
5.1.9.1 Personnel contact information.
5.4.1 Identify and assign responsibility (committee, task
5.1.9.2 Vendor contact information.
forces, or teams).
5.1.9.3 Equipment and system requirements for all
5.4.1.1 Planning.
hardware, software, firmware, and other resources required to
5.4.1.2 Response.
support system operations. Details should be provided for each
5.4.1.3 Recovery.
entry, including model or version number, specifications, and
5.4.2 Train members of the committees, task forces, or
quantity.
teams.
5.1.9.4 Key business records.
5.4.3 Conduct a risk analysis.
5.1.9.5 Directions to and description of any alternate sites
5.4.3.1 Identify potential building problems.
including locations for offsite backup media.
5.4.3.2 Survey fire protection policies and equipment.
5.1.9.6 Other documents or information critical to the orga-
5.4.3.3 Assess ability to protect people.
nization.
5.4.3.4 Evaluate potential source for damage.
5.2 Writing the Plan:
5.4.4 Establish goals and a timeline.
5.2.1 Assign an individual (in case of small organizations)
5.4.5 Develop a reporting schedule.
position/department or a team to create the plan. Particular
5.4.6 Evaluate systems and records and establish priorities.
attention should be paid to the coordination of needed input
5.4.7 Develop recovery strategies.
from various departments. When the team approach is used,
5.4.8 Identify preventive controls and protection needs.
team members should be individuals who serve in a variety of
5.4.9 Review fiscal implications.
organizationalrolesinordertoassureadiversityofperspective
5.4.10 Prepare the plan.
when creating the plan. Be sure to include the following items
5.4.11 Distribute the plan.
within the plan:
5.4.11.1 Training.
5.2.1.1 Designation of the individual position/department
5.4.11.2 Testing.
responsible for maintaining the plan.
5.4.11.3 Drills/Exercises.
5.2.1.2 Designation of the individual position/department
5.4.12 Plan maintenance.
responsiblefordeclaringanemergencyandactivatingtheplan.
5.4.12.1 Evaluate the plan.
5.4.12.2 Update it regularly.
National Institute of Standards and Technology, Contingency Planning Guide
for Information Technology Systems. The U.S. National Archives & Records Administration. Vital Records and
Ibid. Records Disaster Mitigation and Recovery: An Instructional Guide.
E2682 − 09 (2014)
5.4.12.3 Continue to follow the 3 planning principles of 5.6.4.5 Intranet.
de
...








Questions, Comments and Discussion
Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.