HIPAA Backup and Recovery Requirements for 2026
Updated:
August 26, 2026
Only 51% of healthcare organizations hit by ransomware in 2025 used backups to recover encrypted data, down from 72% the previous year, according to Sophos. That decline puts greater pressure on healthcare organizations to maintain backups that can actually support recovery when systems or ePHI become unavailable.
The HIPAA Security Rule requires covered entities and business associates to maintain a data backup plan, disaster recovery plan, and emergency mode operation plan as part of their contingency planning. Backup frequency, restore testing, storage architecture, encryption, and recovery priorities require further decisions based on risk and operational needs.
This guide explains the HIPAA backup and recovery requirements for 2026, what is currently required or addressable, and the practices healthcare organizations should use to keep ePHI recoverable after an incident.
What Does HIPAA Require for Data Backup and Recovery?
HIPAA requires covered entities and business associates to maintain procedures for backing up ePHI, restoring lost data, and protecting critical operations during emergencies.
These requirements fall under the Contingency Plan standard at 45 CFR § 164.308(a)(7). HIPAA does not prescribe a specific backup technology, backup frequency, or retention period for backup copies.
The key backup and recovery requirements are covered in the three areas below:
1. The Contingency Plan Standard Under 45 CFR 164.308(a)(7)
The Contingency Plan standard requires policies and procedures for responding to emergencies or other events that damage systems containing ePHI. It contains five implementation specifications:
| Implementation Specification | Status | Requirement |
| Data Backup Plan | Required | Create and maintain retrievable exact copies of ePHI. |
| Disaster Recovery Plan | Required | Maintain procedures to restore lost data. |
| Emergency Mode Operation Plan | Required | Continue critical processes that protect ePHI during emergency operations. |
| Testing and Revision Procedures | Addressable | Periodically test contingency plans and revise them when appropriate. |
| Applications and Data Criticality Analysis | Addressable | Assess the relative importance of applications and data for recovery planning. |
2. Required Versus Addressable Implementation Specifications
A required implementation specification must be implemented. The data backup plan, disaster recovery plan, and emergency mode operation plan therefore apply directly to HIPAA regulated organizations.
An addressable implementation specification is not optional. The organization must assess whether the specification is reasonable and appropriate for its environment. A reasonable alternative may be implemented when the specified measure is not appropriate, and the organization must document its decision and rationale. Testing and revision procedures and applications and data criticality analysis remain addressable under the current Security Rule.
3.How Long HIPAA Requires ePHI Backups to Be Retained
HIPAA does not set a specific retention period for ePHI backups. Backup retention periods should reflect the organization’s recovery requirements, retention policies, and laws governing the underlying records.
The commonly cited six year HIPAA retention rule applies to required HIPAA documentation, not every ePHI backup. Security Rule documentation must generally be retained for six years from its creation or from the date it was last in effect, whichever is later.
HIPAA does not impose a general retention period for medical records either. HHS states that state laws generally determine how long medical records must be retained, while HIPAA safeguards continue to apply for as long as the organization maintains the information.
When Do HIPAA Backup Requirements Apply?
HIPAA backup requirements apply before an incident occurs, so retrievable copies of ePHI are available when systems or data are damaged or lost. The Contingency Plan standard requires organizations to maintain backup procedures and implement recovery procedures as needed when an emergency or other occurrence affects systems containing ePHI.

The most common situations that require backup or recovery capabilities include:
- Ransomware or cyberattacks: Backups may be needed when an attack encrypts, corrupts, or makes ePHI unavailable. HHS specifically recognizes backups as critical to ransomware recovery.
- System or hardware failures: Recovery procedures may be needed when a system failure causes data loss or prevents access to ePHI.
- Power outages and operational disruptions: Contingency procedures should support continued access to ePHI when critical systems or operations are disrupted.
- Fires, floods, and natural disasters: HIPAA contingency planning specifically covers events that physically damage systems containing ePHI. HHS guidance includes fires, floods, hurricanes, tornadoes, earthquakes, and similar emergencies.
- Data loss or compromise: Disaster recovery procedures must support restoration when an event such as a disruption, compromise, or failure causes data to be lost.
The key distinction is that HIPAA requires the backup capability to exist before these events happen. The disaster recovery and emergency procedures are then implemented when an incident disrupts access to ePHI or damages the systems that contain it.
What Is the Difference Between Backup and Disaster Recovery?
A backup is a retrievable copy of ePHI, while disaster recovery is the process for restoring lost data and returning affected systems to operation. HIPAA treats them as separate required components of the Contingency Plan under 45 CFR § 164.308(a)(7).

Maintaining backups alone does not satisfy the HIPAA disaster recovery requirement. Organizations need both recoverable ePHI copies and documented procedures for restoring lost data when an emergency occurs.
Why Data Backup Matters in Healthcare
Data backup matters in healthcare because the loss or unavailability of ePHI can disrupt patient care and critical business operations. HHS specifically requires contingency planning that supports backing up ePHI, restoring lost data, and continuing critical processes when systems are damaged or unavailable.

Backups are particularly important during ransomware incidents. HHS states that frequent backups and the ability to recover from them are crucial to ransomware recovery and recommends periodically testing restorations. It further advises organizations to consider offline backups because some ransomware variants can damage or delete network-connected backups.
This risk is significant in healthcare. Sophos found that attackers attempted to compromise backups in 95% of healthcare ransomware incidents in its 2024 study, succeeding in 66% of those attempts. Its 2025 research found that the average healthcare ransomware recovery cost, excluding ransom payments, was still $1.02 million.
A healthcare backup strategy therefore needs to do more than store copies of data. Backups should remain protected, recoverable, and regularly tested so the organization can restore ePHI when its primary systems fail.
What Features Must a HIPAA Compliant Backup System Include?
A HIPAA compliant backup system must support retrievable exact copies of ePHI and protect the confidentiality, integrity, and availability of that data. HIPAA does not prescribe a specific backup product or feature list, so organizations must select safeguards based on the Security Rule and their risk analysis.

These safeguards come from the HIPAA Contingency Plan and technical safeguard requirements in 45 CFR §§ 164.308 and 164.312.
Cloud backup services require another compliance control. A cloud provider that stores ePHI is generally a business associate, even when the provider cannot decrypt the data. The covered entity or business associate must have a HIPAA compliant Business Associate Agreement with that provider.
Features such as immutable backups, offline copies, geographic redundancy, and automated recovery can substantially improve ransomware resilience, but the current HIPAA Security Rule does not explicitly mandate those technologies.
How to Choose a HIPAA Compliant Backup Service
Choose a HIPAA compliant backup service that will sign a Business Associate Agreement (BAA), supports reliable ePHI recovery, and provides safeguards appropriate to your risk analysis. HHS does not certify or endorse specific cloud products as “HIPAA compliant,” so the organization remains responsible for assessing whether the service meets its HIPAA obligations.

1. Confirm the Provider Will Sign a BAA
Require a HIPAA compliant BAA before the provider stores, processes, or maintains ePHI. A cloud backup provider handling ePHI is generally a business associate, even when the data is encrypted and the provider does not possess the decryption key.
2. Evaluate Backup and Recovery Capabilities
Confirm that the service can create retrievable exact copies of ePHI and restore them within recovery timeframes appropriate to your operations. Review backup frequency, data coverage, storage locations, media reliability, data integrity checks, and restoration testing. These are factors HHS examines in its HIPAA audit protocol.
3. Review Security Controls
Assess how the provider protects ePHI at rest and in transit, manages access, records system activity, protects encryption keys, and prevents unauthorized alteration or deletion. The controls should address the risks documented in your HIPAA risk analysis.
4. Check Availability and Service Levels
Review the service level agreement for system availability, reliability, backup responsibilities, recovery procedures, and incident response expectations. HHS specifically notes that SLAs can define backup and data recovery obligations for ransomware attacks and other emergencies.
5. Request Evidence of Security Practices
Request relevant security documentation, independent audit reports, recovery test results, and information about subcontractors that may handle ePHI. HIPAA does not require cloud providers to give customers audit rights, but organizations may require additional assurances through contracts or SLAs based on their risk management needs.
6. Plan for Data Access and Provider Exit
Confirm how ePHI can be retrieved, transferred, or securely deleted when the contract ends. The organization should avoid arrangements that could prevent timely access to ePHI during an emergency or make migration to another provider difficult.
The selection should ultimately support the organization’s HIPAA risk analysis, contingency plan, recovery objectives, and contractual obligations, not a vendor’s “HIPAA compliant” marketing claim alone.
Best Practices for HIPAA Backup and Recovery
HIPAA backup and recovery best practices should make ePHI recoverable, protected, and available after an incident. The Security Rule provides the compliance baseline, while HHS and CISA recommend additional measures such as offline backups, redundant copies, and regular restoration testing to reduce ransomware and disaster recovery risk.

1. Building a HIPAA Compliant Backup Strategy
Build the backup strategy around the organization’s risk analysis, data criticality, and recovery requirements. The plan should define:
- Which systems and ePHI are backed up
- How frequently backups occur
- Where backup copies are stored
- Who manages and monitors backups
- How long copies are retained
- Which systems receive priority during recovery
- Expected recovery timeframes
HHS audit guidance examines backup frequency, data scope, backup methods, storage locations, responsible personnel, media reliability, data integrity, and restoration procedures.
Backup frequency should reflect how much recent data the organization can tolerate losing. Critical clinical systems may require more frequent backups than systems with infrequent data changes.
2. Implementing Technical Safeguards
Protect backup systems with the same HIPAA safeguards applied to other systems containing ePHI. Relevant controls include access controls, audit controls, integrity protections, authentication, and transmission security.
Limit backup administration to authorized personnel, log access and administrative activity, protect backup credentials, and monitor for unauthorized changes or deletions.
Cloud backup providers that maintain ePHI generally require a Business Associate Agreement before handling the data.
3. Maintaining Offsite and Redundant Backups
Maintain multiple backup copies so a single ransomware attack, hardware failure, or physical disaster cannot destroy both production data and its backups. HHS recommends considering offline backups that are unavailable from the organization’s network because ransomware can disrupt accessible backup systems.
HHS references CISA’s 3-2-1 backup strategy:
- Keep 3 copies of important data
- Store them on 2 different types of media
- Keep at least 1 copy offsite
CISA recommends keeping recovery copies in physically separate, segmented, and secure locations.
The 3-2-1 model and offsite storage are security best practices, not explicit requirements of the current HIPAA Security Rule.
4. Testing and Verifying Restores
Test backups by restoring data and confirming that the recovered information is complete, usable, and available within the organization’s recovery objectives. A successful backup job does not prove that the data can be restored.
HHS recommends periodic restoration tests to verify backup integrity and recovery capabilities. Its audit protocol examines restore test procedures, results, management review, documentation, and corrective actions taken after failed tests.
Testing and revision procedures remain an addressable implementation specification under the current HIPAA Security Rule. Organizations must assess whether they are reasonable and appropriate and document their decisions when an alternative approach is used.
Frequently Asked Questions
Is “HIPAA Certified” a Real Designation for Backup Services?
No. HHS does not certify, endorse, or recommend specific backup or cloud services as HIPAA compliant. A provider may undergo an independent HIPAA assessment, but that certification does not guarantee compliance. Organizations must evaluate the service, conduct the required risk analysis, and execute a Business Associate Agreement when the provider handles ePHI.
How Often Should Healthcare Organizations Back Up ePHI?
HIPAA does not prescribe a specific backup frequency. Organizations should set backup intervals according to their risk analysis, the importance and rate of change of the data, and the amount of data loss they can tolerate. HHS’s audit protocol specifically examines how frequently backups are performed and whether the schedule supports reliable recovery.
Does HIPAA Require Offsite or Cloud Backups?
No. The current HIPAA Security Rule does not explicitly require backups to be stored offsite or in the cloud. Organizations must maintain retrievable exact copies of ePHI and protect their availability. Cloud backup is permitted when HIPAA requirements are met, including a BAA with a cloud provider that maintains ePHI.
What Is the Difference Between a Backup and an Archive?
A backup is a copy of data maintained primarily for recovery after deletion, corruption, ransomware, or system failure. An archive preserves information for long-term retention, legal, regulatory, or business purposes. Backup copies are typically rotated according to a recovery policy, while archived records may remain for the full retention period applicable to the underlying information.
What Happens If a Backup Fails to Restore During a Disaster?
A failed restore can expose a weakness in the organization’s HIPAA contingency plan and delay access to ePHI. The organization should activate its disaster recovery procedures, use alternative recovery copies where available, document the incident, determine why restoration failed, and correct the problem. HHS’s audit protocol specifically examines restoration testing, documented results, management review, and corrective actions.
Are HIPAA Backups Required to Be Encrypted?
Encryption is addressable under the current HIPAA Security Rule, not universally mandatory. An organization must implement encryption when its risk assessment determines that it is reasonable and appropriate. A documented equivalent safeguard may be used when encryption is not reasonable and appropriate and the Security Rule standard can still be met.
What Are the Penalties for Failing to Meet HIPAA Backup Requirements?
Failure to comply with HIPAA backup and contingency requirements can lead to OCR investigations, corrective action plans, settlements, and civil monetary penalties. Current penalty amounts in 2026 begin at $145 per violation for the lowest culpability tier. Willful neglect that is not timely corrected can carry penalties from $73,011 to $2,190,294 per violation, with a statutory calendar year cap of $2,190,294 for identical violations.
The penalty depends on factors such as the organization’s level of knowledge, reasonable cause, willful neglect, and whether the violation was corrected within the required period.


