DATA RECOVERY
Data is the life-blood of a healthcare organization. HIPAA has raised the bar on the importance of protecting data even more. Today's healthcare applications focus on patient and customer information that must be protected. If electronic data is lost, a healthcare organization could very well not even know a transaction occurred. In the case of ERP applications, a single transaction could create multiple transactions, all going in different directions. If transactions are lost, they usually must be re-entered in the exact sequence in order to keep everything properly synchronized.Data recovery is the result of policies and procedures that the healthcare organization has established surrounding the backup and storage of data. The needs assessment for backup requirements is the result of information attained in the business impact analysis. During the BIA process, each business unit is queried to assess data sets that are critical, how much of that data set could the healthcare organization afford to loose, and what are the time requirements for the recovery of the data after a disaster. After gathering and consolidating the BIA information, it is possible to develop a well-founded backup strategy for the healthcare organization. In keeping with the tenants of HIPAA, this strategy should include, at a minimum, identification of:Data sets/programs that are to be backed up.
The maximum allowable data recovery time.
How backups will be taken, their frequency, their content, and how they are to be verified for accuracy.
Storage medium, storage locations, retention periods and verification procedures.
Storage devices to be used.
Security standards for stored data including restrictions on who is authorized access to stored data.
Who is responsible for managing and maintaining stored data and what are that person's responsibilities and authorities.
What is the order of data set recovery?The above points should drive the formulation of a sound data recovery strategy which should result in actions and software product acquisition to be used in managing the process.