Five HIPAA Policies Every Care Provider Should Keep Current

HIPAA is built on documentation. The Privacy, Security and Breach Notification Rules all expect covered entities to maintain written policies and procedures, to follow them, and to update them when operations or risks change. Many facilities have a binder of policies written years ago, perhaps purchased as a template, that no longer match how the organization works.

Below are five policies worth reviewing now. For each, we outline what it should cover and what questions to ask during review.

1. Acceptable use of technology

This policy tells staff what they may and may not do with computers, email, internet access and mobile devices.

It should address:

Appropriate use of email and messaging for resident information

Personal devices and whether they can access work systems

Use of removable media such as USB drives

Photos and video taken in the facility, including on personal phones

Social media rules relating to residents and families

Consequences for violations

Review questions: Does it mention text messaging and messaging apps? Does it reflect remote work or tablet use on the floor? Do new hires sign it?

2. Access control and workforce security

The Security Rule requires procedures for authorizing access, supervising workforce members, and terminating access when employment ends.

It should cover:

How access is requested and approved, based on role and the minimum necessary

Unique user IDs and a ban on shared logins

Password and multi-factor authentication requirements

Automatic logoff

Timeline for removing access on termination or role change

Periodic access reviews

Review questions: When did you last compare your user list to your staff roster? Is there a clear owner for terminations?

3. Incident response and breach notification

This policy defines what counts as a security incident, who is notified, and how potential breaches are assessed.

It should include:

How staff report suspected incidents, and a promise of non-retaliation for good-faith reports

Roles and contact details for the privacy officer, security officer, IT, legal and leadership

Steps for containing and investigating incidents

The four-factor breach risk assessment under the Breach Notification Rule

Notification timelines: individuals without unreasonable delay and no later than sixty days after discovery, plus HHS and, when required, the media

Documentation requirements

Coordination with state notification laws and your cyber insurer

Review questions: Are contact numbers current? Have you practiced the plan?

4. Contingency plan: backups, disaster recovery and emergency mode

The Security Rule requires a data backup plan, a disaster recovery plan and an emergency mode operation plan. For long-term care, this also connects to CMS emergency preparedness requirements.

It should state:

What systems are critical, and the maximum acceptable downtime for each

How and where backups are stored, and how often they are tested

Procedures for downtime, including paper forms for medication administration and resident information

Who makes decisions during an outage and how staff are informed

Procedures for restoring and then reconciling paper records afterwards

Review questions: Has the plan been tested in the last year? Are paper downtime forms printed and accessible?

5. Business associate management

This policy covers how you identify vendors who handle protected health information and ensure agreements are in place.

It should describe:

How vendors are identified and risk-ranked

Requirements for signed business associate agreements

Due diligence before onboarding, such as security questionnaires

Breach notification expectations for vendors

Review at renewal and procedures when a vendor relationship ends, including data return or destruction

Review questions: Do you have a current list of all business associates? Is there an agreement for each?

Keeping policies alive

Policies are only useful if they match practice. A few habits help:

Assign an owner and a review date to each policy, at least annually and after major changes

Keep version history, since HIPAA requires you to retain documentation for six years

Make policies easy to find for staff, and summarize them in training

Use real incidents and near misses to refine them

Need a second set of eyes?

UnityCare IT works with healthcare and senior-living organizations to align technical practices with written policies, so the paperwork reflects what you actually do. If you would like help reviewing yours, we are happy to start with a conversation.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172