Title: Business Continuity Planning
1Business Continuity Planning
- Presentation to LITN
- Mike Ouska, CIO - LSS of Illinois
- October 2006
2Agenda
- Terms
- Justification for writing a BCP
- BCP Content - What we do at Illinois
- What do other agencies do?
- BCP Testing What we did at Illinois
- What do other agencies do?
3My Terms
- Site Safety Plan
- (prevention steps, fire drills, etc.)
- Emergency Response Procedures
- (during the emergency)
- Disaster Recovery Plan
- (recover computers phones)
- Business Continuity Plan
- (resume business / service)
4Justification - HIPAA
- 164.308(a)(7)(i) A Contingency Plan is the
only way to protect the availability, integrity,
and security of data during unexpected negative
events. Data are often most exposed in these
events, since the usual security measures may be
disabled, ignored, or not observed.
5Justification - HIPAA
- 164.308(a)(7)(i) continued While the
contingency plan standard must be met, we agree
that the proposed testing and revision should
be an addressable implementation specification
6Justification - Other
- Learning Experience
- Improves preparedness
- Best practices
- It doesnt take a hurricane or a fire to knock a
site out of commission
7What LSS Illinois Did
8LSS Illinois has these sites
- 20 Senior Housing
- 24 Behavioral Health Services
- 21 Childrens Community Services
- 3 Senior Community Services
- 4 LTC Market Rate Retirement
- 4 Mixed / Other
- 76 total sites, plus satellites
9BCP Development - Illinois
- IT created the template, the first BCP, and
guidelines - Programs wrote the site BCPs (satellites exempt)
- Accountability theoretically correct vs.
practical
10BCP Contents
- Identify Key Services
- Prioritize Services
- Resumption Approach by Service by Outage Length
- which drives staffing levels
11BCP Contents
Service Provided or Internal Function Expected Days Primary Site Unavailable Expected Days Primary Site Unavailable Expected Days Primary Site Unavailable Expected Days Primary Site Unavailable Expected Days Primary Site Unavailable
3 5 10 30 90
1 Billing D D P-1 P-1 P-2
6 Substance Abuse Counseling D RH-4 RH-4 RH-4 P-4
7 Employee Relations D RH-1 RH-1 RH-1 P-1
Total Relocated Home 4 7 5 5 1
Total Relocated to Contingency Site 3 8 13 20 34
Total Working 7 15 18 25 35
12BCP Contents
- Identify Contingency Site based on 30-day outage
13BCP Contents
- Facilities at Contingency Site
- Office Space
- Phones / Computers
- Office Equipment and Furniture
- Other (e.g., Transportation of Staff)
14BCP Contents
- Process Items
- Organization of the Emergency Management Team
- Responsibilities / Expertise
- Response Assessment
- Team Communication Process
- Business Resumption Process
15BCP Contents
- Recovery Materials
- Communication Items
- Command Center
- Call List
- Employee Communications
16Contingency Info Home Page
17Contingency Info Site Employee Page
18BCP Contents
- Other Procedures
- Expenditure procedures
- Convening at Contingency Site
19BCP Contents
- Preparations for Return to Primary Site
- Process for Return to Primary Site
20BCP Contents
- Maintaining Client Information
- Accessing Client Records
- Maintaining Confidential Records
- Regulatory Requirements
21BCP Contents
- Maintaining the BCP
- Testing the BCP
22Contingency Info Site - Emergency Mgmt Team Page
23What are other agencies doing for Plans?
24Testing What LSS Illinois Did
- Conference Room Test
- Facilitated by someone other than CIO
- Test scenario unfolds as more information is
provided over time - Participation of all Senior Management
25What are other agencies doing for testing?