Applications and Data Criticality Analysis Clause Samples

Applications and Data Criticality Analysis. (Addressable) SECURITY POLICIES AND PROCEDURES: EVALUATION Background: Purpose:
Applications and Data Criticality Analysis. GCHD will assess the relative criticality of specific applications and data in formulating its contingency plan. a. GCHD will determine which applications and data are essential to maintain patient care, life safety, and other essential functions. b. In evaluating the criticality of information, GCHD will consider, among other things, the difficulty of replicating the data if lost, sensitivity of the data, and consequences to patients if data is unavailable or corrupted. c. Those applications and databases identified as critical to GCHD’s patient care mission will be given priority in the contingency plan. d. GCHD will devote appropriate resources to recovering critical functions in the event of a disaster. AS 3.1.1, Risk Analysis AS 3.1.2, Risk Management PS 4.1.1, Contingency Operations PS 4.4.4, Data Back-up and Storage TS 5.1.2, Emergency Access Procedure 45 C.F.R. § 164.308(a)(7) GCHD will perform periodic technical and non-technical evaluations to establish the extent that GCHD’s security policies and procedures meet the requirements of the Security Rule (45 CFR Part 160 and Subparts A and C of Part 164) based upon the standards implemented under the Security Rule and in response to environmental or operational changes affecting the security of electronic protected health information.