Which HIPAA Policies Should Actually Be in Your Binder?

Walk into many skilled nursing facilities and you will find a large HIPAA binder on a shelf, bought years ago from a template vendor and never opened since. When a surveyor, an auditor or an insurance underwriter asks about your policies, an unread binder is not much comfort.

The goal is not a bigger binder. It is a smaller, accurate set of policies that match what your staff actually do. Here is a practical way to decide what belongs in yours.

Start with what the rules require

HIPAA has three rules that drive policy needs: the Privacy Rule, the Security Rule and the Breach Notification Rule. Between them, a covered entity needs written policies and procedures covering at least the topics below. Business associates have their own obligations under the Security Rule and parts of the others.

Privacy policies

Uses and disclosures of protected health information, including the minimum necessary standard

Notice of Privacy Practices and how residents receive it

Individual rights: access to records, amendments, accounting of disclosures and restrictions

Handling of requests from family members and representatives

Authorizations, including marketing and photography rules

Complaint process and non-retaliation

Security policies

Security management, including risk analysis and risk management

Workforce security, access authorization and termination procedures

Information access management and role-based access

Security awareness and training

Security incident procedures

Contingency planning: data backup, disaster recovery and emergency mode operation

Device and media controls, including disposal and reuse

Facility access controls and workstation security

Audit controls, integrity and transmission security

Breach notification policies

How to identify and report a suspected breach internally

How your organization assesses whether notification is required

Timelines and content of notices to residents, regulators and, in some cases, the media

Policies versus procedures

A policy says what you will do. A procedure explains how. "Access is removed promptly when employment ends" is a policy. "HR emails the IT helpdesk the same day, and IT disables the account and badge within one business day" is a procedure. Surveyors and auditors usually care more about the procedure and about evidence that people follow it.

Assign an owner to each policy

Every policy should have a named role responsible for it, not just a department. A typical split in a long-term care facility might be:

Privacy Officer, often the administrator or director of compliance: privacy and breach policies

Security Officer, which may be IT leadership or your managed provider's designated contact: security policies

Director of Nursing: clinical workflow policies such as shared workstation use and family communication

HR: workforce, onboarding and termination policies

HIPAA requires you to designate privacy and security officials. Make sure the names in your documents are current.

Review cycle and version control

HIPAA requires that policies be reviewed and updated as needed in response to environmental or operational changes. A simple rule is to review everything at least once a year, and again whenever you change your EHR, add a location, change IT vendors or have an incident. Record the date, the reviewer and a summary of what changed. HIPAA documentation must be retained for six years from the date it was created or last in effect, so keep old versions rather than overwriting them.

Signs your binder is out of date

It names people who no longer work for you

It refers to systems you no longer use

It describes controls you cannot actually demonstrate, such as quarterly access reviews that have never happened

Staff cannot tell you where to find it

It has no mention of remote work, texting, personal phones or cloud services

An inaccurate policy can be worse than a missing one, because it shows you knew what to do and did not do it.

Make it usable

Store policies in a shared location staff can search, not just a paper binder. Keep a short one-page quick reference for common questions, such as what to do when a family member asks for a resident's information over the phone. Link training to specific policies so staff learn what is actually expected of them.

Where UnityCare IT can help

We help healthcare organizations compare their written policies against their real systems and workflows, and close the gaps. If you would like a second set of eyes on your security policies in particular, UnityCare IT can walk through them with you and flag anything that no longer matches how your facility actually runs.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172