HIPAA Policies and Procedures: What to Write and Keep

When investigators from the HHS Office for Civil Rights arrive after a complaint or breach, one of their first requests is for your written policies and procedures. Organizations that cannot produce them, or that produce a generic set clearly never used, start from a weak position. But writing policies is only part of the job. They must reflect what you actually do, and they must be kept up to date.

Here is a practical look at what to write, how to organize it and how long to keep it.

What the rules require

Both the Privacy Rule and the Security Rule require covered entities and business associates to implement reasonable and appropriate written policies and procedures. The documentation requirements are specific:

Policies and procedures must be maintained in written or electronic form.

Actions, activities and assessments that the rules require to be documented must be recorded.

Documentation must be retained for six years from the date of creation or the date it was last in effect, whichever is later.

Documentation must be available to the people responsible for implementing the procedures.

Policies must be reviewed periodically and updated in response to environmental or operational changes affecting security.

Core policies to have

Privacy-related

Uses and disclosures of PHI, including minimum necessary.

Notice of Privacy Practices and acknowledgment process.

Patient rights: access, amendment, accounting of disclosures, restrictions and confidential communications.

Authorizations and release of information.

Handling of requests from family members and personal representatives.

Marketing and fundraising rules, if applicable.

Complaint process and non-retaliation.

Security-related

Security management: risk analysis, risk management, sanction policy and information system activity review.

Assigned security responsibility, naming the security officer.

Workforce security: authorization, clearance and termination procedures.

Information access management and access control.

Security awareness and training.

Security incident procedures and breach notification.

Contingency planning: backup, disaster recovery and emergency mode operation.

Device and media controls, including disposal and reuse.

Facility access and workstation use and security.

Authentication, audit controls, integrity and transmission security.

Business associate management.

Operational policies that support these

Acceptable use of technology.

Mobile device and remote work.

Email and secure messaging.

Password and multi-factor authentication standards.

Photography, social media and use of cameras.

Vendor and visitor access.

Make policies usable

A policy that is too long or too vague will not be followed.

Write in plain language and state who is responsible for what.

Separate the policy, which says what must happen, from the procedure, which says how.

Keep each document focused and use consistent headings.

Include an effective date, version number, owner and review date.

Attach forms and checklists staff will actually use.

Avoid the generic template trap

Purchased templates are a reasonable starting point, but they often describe controls you do not have. If your policy says all laptops are encrypted and some are not, you have created evidence against yourself. Edit templates to match your reality, then close the gaps, or write the gap into your risk management plan.

Keep an organized record

Create a simple structure, either a shared folder with controlled access or a compliance platform:

Policies and procedures, with version history.

Risk analyses and risk management plans.

Training records, with dates and attendance.

Business associate agreements.

Incident and breach logs and assessments.

Access reviews and audit reports.

Sanction records, handled with confidentiality.

Evidence of reviews, such as meeting notes.

Review on a schedule

Set a yearly review and trigger additional reviews when something changes: a new EHR, a new location, a breach, a new regulation or a significant vendor change. Record who reviewed and what changed, even if the answer is no changes.

Train on policies

Policies are only effective if the workforce knows them. Provide access at onboarding, summarize key points in training and make them easy to find. Document acknowledgment.

Common mistakes

Policies that exist but no one has read.

No evidence of annual review.

Missing documentation for the risk analysis, training or incidents.

Not naming the privacy and security officers.

Discarding documents before six years have passed.

Support from UnityCare IT

UnityCare IT helps healthcare organizations align written security policies with the technology they actually run, and organizes the supporting records. If your policy binder has not been opened in a while, we can help you refresh it.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172