HIPAA is built on documentation. The Privacy, Security and Breach Notification Rules all expect covered entities to maintain written policies and procedures, to follow them, and to update them when operations or risks change. Many facilities have a binder of policies written years ago, perhaps purchased as a template, that no longer match how the organization works.
Below are five policies worth reviewing now. For each, we outline what it should cover and what questions to ask during review.
This policy tells staff what they may and may not do with computers, email, internet access and mobile devices.
It should address:
Appropriate use of email and messaging for resident information
Personal devices and whether they can access work systems
Use of removable media such as USB drives
Photos and video taken in the facility, including on personal phones
Social media rules relating to residents and families
Consequences for violations
Review questions: Does it mention text messaging and messaging apps? Does it reflect remote work or tablet use on the floor? Do new hires sign it?
The Security Rule requires procedures for authorizing access, supervising workforce members, and terminating access when employment ends.
It should cover:
How access is requested and approved, based on role and the minimum necessary
Unique user IDs and a ban on shared logins
Password and multi-factor authentication requirements
Automatic logoff
Timeline for removing access on termination or role change
Periodic access reviews
Review questions: When did you last compare your user list to your staff roster? Is there a clear owner for terminations?
This policy defines what counts as a security incident, who is notified, and how potential breaches are assessed.
It should include:
How staff report suspected incidents, and a promise of non-retaliation for good-faith reports
Roles and contact details for the privacy officer, security officer, IT, legal and leadership
Steps for containing and investigating incidents
The four-factor breach risk assessment under the Breach Notification Rule
Notification timelines: individuals without unreasonable delay and no later than sixty days after discovery, plus HHS and, when required, the media
Documentation requirements
Coordination with state notification laws and your cyber insurer
Review questions: Are contact numbers current? Have you practiced the plan?
The Security Rule requires a data backup plan, a disaster recovery plan and an emergency mode operation plan. For long-term care, this also connects to CMS emergency preparedness requirements.
It should state:
What systems are critical, and the maximum acceptable downtime for each
How and where backups are stored, and how often they are tested
Procedures for downtime, including paper forms for medication administration and resident information
Who makes decisions during an outage and how staff are informed
Procedures for restoring and then reconciling paper records afterwards
Review questions: Has the plan been tested in the last year? Are paper downtime forms printed and accessible?
This policy covers how you identify vendors who handle protected health information and ensure agreements are in place.
It should describe:
How vendors are identified and risk-ranked
Requirements for signed business associate agreements
Due diligence before onboarding, such as security questionnaires
Breach notification expectations for vendors
Review at renewal and procedures when a vendor relationship ends, including data return or destruction
Review questions: Do you have a current list of all business associates? Is there an agreement for each?
Policies are only useful if they match practice. A few habits help:
Assign an owner and a review date to each policy, at least annually and after major changes
Keep version history, since HIPAA requires you to retain documentation for six years
Make policies easy to find for staff, and summarize them in training
Use real incidents and near misses to refine them
UnityCare IT works with healthcare and senior-living organizations to align technical practices with written policies, so the paperwork reflects what you actually do. If you would like help reviewing yours, we are happy to start with a conversation.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172