I don't think there is any way we can ever meet all HiPAA requirements -- it's a moving target on an uneven playing field in the dark.
However, writing something -- almost anything --down and putting it in a notebook titled "recovery plan for ePHI data loss" will at least get us to first base. If there is ever an inspection, we can be faulted for being "inadequate" -- which goes without saying-- and get assessed hefty fines, but not for "failure to comply." Which could be jail.