When the HHS Office for Civil Rights opens an investigation, or a payer, insurer or partner asks for proof of your compliance program, the request is often short and the deadline tight. Organizations that have their documentation organized respond calmly. Those that do not scramble to find or recreate records.
You do not need a perfect program to be ready. You do need to know what exists, where it is and who owns it. A single organized binder, physical or electronic, makes that possible. Think of it as your compliance evidence file.
HIPAA requires covered entities and business associates to maintain written policies and procedures, and to keep documentation of required actions, activities and assessments, generally for six years from creation or last effective date. In an investigation, "we do this" carries much more weight when you can show a record.
Name and contact details of the privacy officer and security officer
Organizational chart showing compliance responsibilities
Meeting notes from compliance or security committee reviews
Privacy policies, including uses and disclosures, minimum necessary, patient rights and the Notice of Privacy Practices
Security policies covering access control, passwords, device and media handling, remote work, contingency planning and sanctions
Version history and approval dates, with evidence of annual review
Your most recent security risk analysis and earlier versions
The risk register with remediation plans, owners and progress
Asset inventory and data flow maps
New hire training dates and content
Annual refresher attendance
Phishing simulation results
Role-specific training, such as for IT or the business office
Signed acknowledgments of policies
A current list of vendors with PHI access
Signed business associate agreements
Security assessments or assurance documents for key vendors
User access lists and the process for approving, changing and removing access
Samples of access reviews performed
Audit log review records
Records of terminated employees and when access ended
Screenshots or reports showing multi-factor authentication, encryption, patch status and endpoint protection
Backup reports and restore test results
Firewall and network diagrams
Vulnerability scan or penetration test summaries, if performed
Data backup plan, disaster recovery plan and emergency mode operations plan
Downtime procedures
Test and exercise records
Contact lists and recovery priorities
Incident response plan
A log of security incidents and how each was handled
Breach risk assessments, including those that concluded no notification was needed
Copies of notifications issued, if any
Sanctions applied for policy violations
Procedures and logs for access requests, amendments, restrictions and accounting of disclosures
Records of timelines met
Information blocking practices consistent with the 21st Century Cures Act, where applicable
Facility access controls, key and badge logs
Workstation use and security policies
Device and media disposal records, including certificates of destruction
A binder full of outdated documents is a risk too. Build a calendar:
Quarterly: access reviews, backup tests, vendor list updates
Semiannually: policy review checkpoints and training updates
Annually: risk analysis refresh, policy approval, tabletop exercise
Whenever something changes: update the relevant documents
Pick a section and pretend an investigator has asked for it. Can you produce the document within a day? Is it current? Does it match what staff actually do? Policies that say one thing while practice says another can be worse than no policy.
Use a consistent naming scheme and folder structure.
Limit editing rights and keep backups of the binder itself.
Store a copy where it can be reached during an outage.
Make sure at least two people know where it is.
If you discover missing items, do not backdate or invent documents. Create them now with the current date and a note of what changed. Honest, current documentation is far better than falsified history.
UnityCare IT helps healthcare organizations gather the technical evidence for their compliance files, from patch and backup reports to access reviews and network diagrams. If you would like a gap check against this list, we can help.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034