HIPAA requires everyone to have a recovery or contingency plan for ePHI data loss like an emergency or theft of a laptop or power loss, etc.

For those of us out here with small physician practices, is there any example or set of example documents that a practice has created that would show you step by step how to compose your own flavor of document that outlines all your security procedures and protocols to ensure that patient health info is never breached at any point? I believe that September is the fed deadline to have a document or set of documents that a practice uses to make sure all data is safe and establishes a strict procedure to follow in any event of data loss.

Has anyone built their own document that covers this and satisfies the government requirement? The government seems to want to insist that everyone have these documents, but there's not a whole lot of material giving you examples of what something like that would actually look like for a real-world clinic situation.

Has someone out there already built this? It would help us establish our own...thnx..