The HHS Office for Civil Rights investigates complaints and breach reports, and conducts compliance reviews. When it opens an inquiry, it typically sends a request for documents with a short deadline. Organizations that have their paperwork in order respond calmly. Others scramble to create documents after the fact, which rarely goes well.
The good news is that being ready is mostly a matter of organizing what a compliance program should already produce. Here is a practical list of what to keep current and easy to find.
Name of your privacy official and security official, with a written designation.
Organizational chart or list of responsibilities for compliance.
Meeting notes showing leadership review of compliance and security issues.
Your most recent security risk analysis, including scope, method, asset inventory and findings.
The risk management plan with owners, dates and status.
Evidence that you updated the analysis after significant changes.
Documentation of decisions to accept risks, with leadership sign-off.
This is the document most commonly requested and most commonly found lacking.
HIPAA requires written policies and procedures that implement the rules. Keep current versions and a record of changes. Typical topics include:
Uses and disclosures of PHI, minimum necessary and patient rights.
Notice of Privacy Practices and its acknowledgment process.
Access control, authentication and automatic logoff.
Device and media controls, including disposal and reuse.
Contingency planning: backup, disaster recovery and emergency mode operation.
Sanctions for workforce violations.
Incident response and breach notification.
Remote work and mobile device use.
Policies must be retained for six years from creation or the date they were last in effect, whichever is later.
Training materials used for HIPAA privacy and security awareness.
Attendance or completion logs for every workforce member, with dates.
New hire training records.
Evidence of periodic reminders.
A current list of business associates.
Signed business associate agreements.
Evidence of vendor reviews for critical vendors.
Procedures and records for granting, changing and removing access.
Samples showing access reviews and terminated user removal.
Audit log review procedures and evidence that reviews take place.
Records of investigations of suspected inappropriate access.
Network and system diagrams.
Encryption status for laptops, mobile devices and backups.
Backup reports and restore test results.
Patch reports and vulnerability scan summaries.
Endpoint protection coverage reports.
MFA coverage reports.
A log of security incidents and responses, including those judged not to be breaches.
Completed breach risk assessments.
Copies of notices to individuals, HHS and the media, when applicable.
Mitigation steps and lessons learned.
Breach records and associated documentation must be retained for six years.
Facility access controls and key or badge logs.
Workstation positioning and security measures.
Inventory of devices and media, with disposal records.
Procedures and logs for access requests, amendments and accounting of disclosures.
Records showing responses were timely.
Complaint handling procedures and records.
Create a single, access-controlled folder, either digital or a binder, with subfolders matching the categories above. Add a short index with a date for each item's last review. Assign someone to review it quarterly.
Once a year, pretend a document request has arrived and see how long it takes to assemble. Note what is missing or out of date, and fix it.
Beyond documents, investigators may interview staff. Employees should know who the privacy and security officials are, how to report a problem and the basics of protecting information. Documents alone do not prove compliance if practice does not match.
UnityCare IT helps healthcare and senior living organizations produce the technical evidence that supports HIPAA compliance, such as risk assessments, backup and patch reports and access reviews. We can help you assemble an audit-ready file.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034