Standard Guide for Developing a Disaster Recovery Plan for Medical Transcription Departments and Businesses

SIGNIFICANCE AND USE
This guide acknowledges the importance of a well-designed disaster recovery plan that will protect health information and business information from damage, minimize disruption, ensure integrity of data, and provide for orderly recovery.
This guide suggests methods to protect the confidentiality and security of healthcare documentation during a disaster.
It is intended that this guide will contribute to compliance with laws and regulations to improve protection of health information documentation and data integrity with the development of the contingency plan requirement.
This guide will explain key points to include in preparing a disaster recovery plan to resume operations and minimize losses due to unscheduled interruption of critical services if a disaster would occur.
This guide is intended to assist in the development of appropriate policies and procedures that provide protection for individually identifiable health information in a secure environment in the event of a disaster.
SCOPE
1.1 This guide applies across multiple medical transcription settings in which healthcare documents are generated and stored: medical transcription departments, home offices, and medical transcription service organizations (MTSOs). Currently there is no standard disaster recovery plan in the medical transcription industry to provide guidelines for individuals, departments, and businesses to use for designing a disaster recovery plan for their medical transcription environment.
1.2 A disaster is when a sudden event brings great damage, loss, destruction, or interruption of critical services. These guidelines could assist in developing an organized response to reduce the time for loss of services, maintain continuity of workflow, and speed the overall business recovery process.
1.3 This guide supports the HIPAA Security Rule for ensuring data integrity with a contingency plan to include a data backup plan, a disaster recovery plan, and an emergency mode operational plan.  
1.4 This guide is consistent with the requirement for disaster planning and recovery procedures as stated in Guide E 1959.
1.5 This guide is not intended as a disaster recovery plan for Health Information Management Departments or for an entire healthcare facility.

General Information

Status
Historical
Publication Date
31-Mar-2009
Current Stage
Ref Project

Buy Standard

Guide
ASTM E2682-09 - Standard Guide for Developing a Disaster Recovery Plan for Medical Transcription Departments and Businesses
English language
8 pages
sale 15% off
Preview
sale 15% off
Preview

Standards Content (Sample)


NOTICE: This standard has either been superseded and replaced by a new version or withdrawn.
Contact ASTM International (www.astm.org) for the latest information
Designation: E2682 − 09 AnAmerican National Standard
Standard Guide for
Developing a Disaster Recovery Plan for Medical
Transcription Departments and Businesses
This standard is issued under the fixed designation E2682; the number immediately following the designation indicates the year of
original adoption or, in the case of revision, the year of last revision. A number in parentheses indicates the year of last reapproval. A
superscript epsilon (´) indicates an editorial change since the last revision or reapproval.
1. Scope E1959 Guide for Requests for Proposals Regarding Medical
Transcription Services for Healthcare Institutions
1.1 This guide applies across multiple medical transcription
2.2 Other Documents:
settings in which healthcare documents are generated and
Public Law 104-191 Health Insurance Portability and Ac-
stored: medical transcription departments, home offices, and
countability Act of 1996 (HIPAA)
medical transcription service organizations (MTSOs). Cur-
45 CFR Part 142 Security and Electronic Signature Stan-
rentlythereisnostandarddisasterrecoveryplaninthemedical
dards
transcription industry to provide guidelines for individuals,
departments, and businesses to use for designing a disaster
3. Terminology
recovery plan for their medical transcription environment.
3.1 Definitions:
1.2 Adisaster is when a sudden event brings great damage,
3.1.1 author, n—the person originating content for a health-
loss, destruction, or interruption of critical services. These
care document.
guidelines could assist in developing an organized response to
3.1.2 backups, n—retrievable, exact copies of data. The
reduce the time for loss of services, maintain continuity of
primary method for ensuring that organizations can recover
workflow, and speed the overall business recovery process.
from a system crash or disaster.
1.3 This guide supports the HIPAA Security Rule for
3.1.3 confidential, adj—status accorded to data or informa-
ensuring data integrity with a contingency plan to include a
tion indicating that it is sensitive for some reason, and
data backup plan, a disaster recovery plan, and an emergency
therefore, it needs to be protected against theft, disclosure, or
mode operational plan.
improper use, or a combination thereof, and must be dissemi-
1.4 Thisguideisconsistentwiththerequirementfordisaster
nated only to authorized individuals or organizations with a
planning and recovery procedures as stated in Guide E1959.
need to know. E1869
1.5 Thisguideisnotintendedasadisasterrecoveryplanfor
3.1.4 confidentiality, n—the property that information is not
Health Information Management Departments or for an entire
made available or disclosed to unauthorized individuals,
healthcare facility.
entities, or processes. 45 CFR Part 142
3.1.5 contingency plan, n—an alternate way of doing busi-
2. Referenced Documents
ness when established routines are disrupted.
2.1 ASTM Standards:
3.1.6 disaster, n—a sudden event bringing great damage,
E1869 Guide for Confidentiality, Privacy, Access, and Data
loss, destruction or interruption of critical services.
SecurityPrinciplesforHealthInformationIncludingElec-
3.1.7 individually identifiable health information, n—any
tronic Health Records
information, including demographic information collected
from an individual, that (1) is created or received by a health
care provider, health plan, employer, or health care clearing-
This guide is under the jurisdiction of ASTM Committee E31 on Healthcare
house; and (2) relates to the past, present, or future physical or
Informatics and is the direct responsibility of Subcommittee E31.15 on Healthcare
mental health or condition of an individual, the provision of
Information Capture and Documentation.
Current edition approved April 1, 2009. Published May 2009. DOI: 10.1520/
health care to an individual, or the past, present, or future
E2682-09.
payment for the provision of health care to an individual, and
AvailablefromU.S.GovernmentPrintingOfficeSuperintendentofDocuments,
732 N. Capitol St., NW, Mail Stop: SDE, Washington, DC 20401. See also
http://aspe.hhs.gov/admnsimp.
3 4
For referenced ASTM standards, visit the ASTM website, www.astm.org, or Available from the U.S. Department of Health & Human Services, 200
contact ASTM Customer Service at service@astm.org. For Annual Book of ASTM Independence Avenue, S.W., Washington, D.C., 20201, www.hhs.gov.
Standards volume information, refer to the standard’s Document Summary page on Medical Records Disaster Planning, A Health Information Manager’s Survival
the ASTM website. Guide, AHIMA, Chicago, IL.
Copyright © ASTM International, 100 Barr Harbor Drive, PO Box C700, West Conshohocken, PA 19428-2959. United States
E2682 − 09
needs, formalization and approval of the disaster recovery plan, annual
(i) identifies the individual, or (ii) with respect to which there
testing of the implementation of the requisite disaster recovery action, and
isareasonablebasistobelievethattheinformationcanbeused
formal review and necessary revision of the disaster recovery plan.
to identify the individual. Public Law 104-191,
5.1 Activation of Response Plan:
Section 1171 (6)
5.1.1 Policy Statement:
3.1.8 privacy, n—the right of an individual to be left alone
5.1.1.1 To ensure that the plan is effective and that all
and to be protected against physical or psychological invasion
involved understand its purpose, there must be a clearly
or misuse of their property. It includes freedom from intrusion
defined policy statement. This statement should define the
or observation into one’s private affairs, the right to maintain
scope and overall objectives of the plan.
control over certain personal information, and the freedom to
5.1.2 Table of Contents.
act without outside interference. E1869
5.1.3 Introduction:
3.1.9 provider, n—a business entity which furnishes health
5.1.3.1 Use of the document.
care to a consumer; it includes a professionally licensed
5.1.3.2 How it is to be revised.
practitioner who is authorized to operate a healthcare delivery
5.1.3.3 Training requirements.
system. E1869
5.1.3.4 Exercise and testing schedules.
3.1.10 secure environment, n—free from access by unau- 5.1.3.5 Plan maintenance schedule.
thorized persons and from unauthorized or accidental altera-
5.1.3.6 Roles and responsibilities.
tion. 5.1.3.7 General information about the facility.
5.1.3.8 Compliance with federal, state, local, and health
3.1.11 security, n—encompasses all of the safeguards in an
regulatory agencies.
information system, including hardware, software, personnel
5.1.4 Emergency Information Sheet:
policies, information practice policies, disaster preparedness,
5.1.4.1 Fire/police departments.
and the oversight of all these areas. The purpose is to protect
5.1.4.2 Hospitals.
both the system and the information it contains from unauthor-
5.1.4.3 Emergency shut-off.
ized access from without and from misuse from within.
5.1.4.4 Utility companies.
45 CFR Part 142
5.1.4.5 Other agencies needed for an emergency.
3.2 Acronyms:
5.1.4.6 Telephone/reporting tree.
3.2.1 HIPAA—Health Insurance Portability and Account-
5.1.4.7 List of assistance/equipment vendors.
ability Act
5.1.5 Resource Priorities:
3.2.2 MT—medical transcriptionist
5.1.5.1 Personnel.
5.1.5.2 Records.
3.2.3 MTSO—medical transcription service organization
5.1.5.3 Technology.
4. Significance and Use
5.1.6 Plan Activation with Response Outline:
5.1.6.1 Lead personnel responsibilities.
4.1 This guide acknowledges the importance of a well-
5.1.6.2 Assessing the situation.
designed disaster recovery plan that will protect health infor-
5.1.6.3 Organizing/prioritizing efforts.
mation and business information from damage, minimize
5.1.6.4 Establishing a command post.
disruption, ensure integrity of data, and provide for orderly
5.1.6.5 Eliminating hazards.
recovery.
5.1.6.6 Controlling the environment.
4.2 This guide suggests methods to protect the confidenti-
5.1.6.7 Dealing with media.
ality and security of healthcare documentation during a disas-
5.1.6.8 Obtaining emergency services/supplies.
ter.
5.1.6.9 Providing security.
4.3 It is intended that this guide will contribute to compli- 5.1.6.10 Providing personnel needs.
ance with laws and regulations to improve protection of health
5.1.7 Activation of Recovery Procedures:
information documentation and data integrity with the devel- 5.1.7.1 Obtaining authorization to access damaged facilities
opment of the contingency plan requirement.
or geographic areas or both.
5.1.7.2 Notifying personnel.
4.4 This guide will explain key points to include in prepar-
5.1.7.3 Notifying utilities and other agencies required for
ingadisasterrecoveryplantoresumeoperationsandminimize
resuming business.
losses due to unscheduled interruption of critical services if a
5.1.7.4 Obtaining supplies needed for business.
disaster would occur.
5.1.7.5 Obtaining and installing necessary hardware com-
4.5 This guide is intended to assist in the development of
ponents.
appropriate policies and procedures that provide protection for
5.1.7.6 Obtaining and loading backup media.
individually identifiable health information in a secure envi-
ronment in the event of a disaster.
The U.S. National Archives & Records Administration. www.archives.gov.
5. Elements of Disaster Recovery Planning
Vital Records and Records Disaster Mitigation and Recovery: An Instructional
NOTE 1—Disaster recovery planning includes the identification of key
Guide.
components of a disaster recovery plan, gathering the necessary informa- National Institute of Standards and Technology, Contingency Planning Guide
tion to provide the details to tailor the plan to meet the organization’s for Information Technology Systems.
E2682 − 09
5.1.7.7 Restoring critical operating system and application 5.2.2.2 Human—disastrous employee error, sabotage, virus,
software. terrorism, etc.
5.1.7.8 Restoring system data. 5.2.2.3 Environment—disastrous equipment failure, soft-
5.1.7.9 Testing system functionality including security con- ware corruption, telecommunications network outage, electri-
trols. cal failure, etc.
5.1.7.10 Connecting system to network or other external
5.3 The Planning Process:
systems.
5.3.1 To be successful, senior management must support the
5.1.7.11 Resume equipment operations.
plan and be included in the process to develop the policy
5.1.8 Termination of Disaster Recovery Operations:
statement and the plan.
5.1.8.1 Designated authority declares the end of disaster
5.3.2 Whenpoliciesandproceduresaredevelopedrelatedto
recoveryoperationsanddisseminatesthatannouncementtothe
the disaster recovery plan, they need to be coordinated with
communications network.
relatedorganizationalactivities,includinginformationtechnol-
5.1.8.2 Arrange for all personnel to return to work.
ogy security, physical security, human resources, risk
5.1.8.3 Resume standard operating procedures.
management, quality assurance, information technology
5.1.8.4 Complete comprehensive post event evaluation,
operations, and administrative services.
conduct review of the adequacy of the existing disaster
5.4 Thedisasterplanningprocessshouldincludethefollow-
recovery plan, and revise the plan if necessary.
ing key steps:
5.1.9 Appendices:
5.4.1 Identify and assign responsibility (committee, task
5.1.9.1 Personnel contact information.
forces, or teams).
5.1.9.2 Vendor contact information.
5.4.1.1 Planning.
5.1.9.3 Equipment and system requirements for all
5.4.1.2 Response.
hardware, software, firmware, and other resources required to
5.4.1.3 Recovery.
support system operations. Details should be provided for each
5.4.2 Train members of the committees, task forces, or
entry, including model or version number, specifications, and
teams.
quantity.
5.4.3 Conduct a risk analysis.
5.1.9.4 Key business records.
5.4.3.1 Identify potential building problems.
5.1.9.5 Directions to and description of any alternate sites
5.4.3.2 Survey fire protection policies and equipment.
including locations for offsite backup media.
5.4.3.3 Assess ability to protect people.
5.1.9.6 Other documents or information critical to the orga-
5.4.3.4 Evaluate potential source for damage.
nization.
5.4.4 Establish goals and a timeline.
5.2 Writing the Plan:
5.4.5 Develop a reporting schedule.
5.2.1 Assign an individual (in case of small organizations)
5.4.6 Evaluate systems and records and establish priorities.
position/department or a team to create the plan. Particular
5.4.7 Develop recovery strategies.
attention should be paid to the coordination of needed input
5.4.8 Identify preventive controls and protection needs.
from various departments. When the team approach is used,
5.4.9 Review fiscal implications.
team members should be individuals who serve in a variety of
5.4.10 Prepare the plan.
organizationalrolesinordertoassureadiversityofperspective
5.4.11 Distribute the plan.
when creating the plan. Be sure to include the following items
5.4.11.1 Training.
within the plan:
5.4.11.2 Testing.
5.2.1.1 Designation of the individual position/department
5.4.11.3 Drills/Exercises.
responsible for maintaining the plan.
5.4.12 Plan maintenance.
5.2.1.2 Designation of the individual position/department
5.4.12.1 Evaluate the plan.
responsiblefordeclaringanemergencyandactivatingtheplan.
5.4.12.2 Update it regularly.
5.2.1.3 Designation of the individual position/department in
5.4.12.3 Continue to follow the 3 planning principles of
charge of making short-term emergency decisions.
define, document, and demonstrate.
5.2.1.4 Designation of the individual position/department in
5.5 Plan Characteristics:
charge of transitioning from emergency mode back to normal
5.5.1 Recognizing that the logic and order of recovery steps
business mode.
depends on the nature of the organization and its services as
5.2.2 The essence of writing a disaster recovery plan is to
well as on the type of disaster or interruption, the plan should
think ahead and create a unified plan that addresses all defined
have the following characteristics:
disaster scenarios (internal and external). Be aware that during
5.5.1.1 Significant flexibility so that the plan can be utilized
adisaster,individualsmaynotbeabletocallin,login,orwalk
as needed by managers.
in.
5.2.2.1 Natural—hurricane, tornado, flood, snow, ice, fire,
earthquake, etc.
The U.S. National Archives & Records Administration. Vital Records and
Records Disaster Mitigation and Recovery: An Instructional Guide.
HIPAAin Practice, The Health Information Manager’s Perspective.Available
Ibid. from American Health Information Management Association, Chicago, IL.
E2682 − 09
5.5.1.2 Able to be implemente
...

Questions, Comments and Discussion

Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.