Walk into many skilled nursing facilities and you will find a large HIPAA binder on a shelf, bought years ago from a template vendor and never opened since. When a surveyor, an auditor or an insurance underwriter asks about your policies, an unread binder is not much comfort.
The goal is not a bigger binder. It is a smaller, accurate set of policies that match what your staff actually do. Here is a practical way to decide what belongs in yours.
HIPAA has three rules that drive policy needs: the Privacy Rule, the Security Rule and the Breach Notification Rule. Between them, a covered entity needs written policies and procedures covering at least the topics below. Business associates have their own obligations under the Security Rule and parts of the others.
Uses and disclosures of protected health information, including the minimum necessary standard
Notice of Privacy Practices and how residents receive it
Individual rights: access to records, amendments, accounting of disclosures and restrictions
Handling of requests from family members and representatives
Authorizations, including marketing and photography rules
Complaint process and non-retaliation
Security management, including risk analysis and risk management
Workforce security, access authorization and termination procedures
Information access management and role-based access
Security awareness and training
Security incident procedures
Contingency planning: data backup, disaster recovery and emergency mode operation
Device and media controls, including disposal and reuse
Facility access controls and workstation security
Audit controls, integrity and transmission security
How to identify and report a suspected breach internally
How your organization assesses whether notification is required
Timelines and content of notices to residents, regulators and, in some cases, the media
A policy says what you will do. A procedure explains how. "Access is removed promptly when employment ends" is a policy. "HR emails the IT helpdesk the same day, and IT disables the account and badge within one business day" is a procedure. Surveyors and auditors usually care more about the procedure and about evidence that people follow it.
Every policy should have a named role responsible for it, not just a department. A typical split in a long-term care facility might be:
Privacy Officer, often the administrator or director of compliance: privacy and breach policies
Security Officer, which may be IT leadership or your managed provider's designated contact: security policies
Director of Nursing: clinical workflow policies such as shared workstation use and family communication
HR: workforce, onboarding and termination policies
HIPAA requires you to designate privacy and security officials. Make sure the names in your documents are current.
HIPAA requires that policies be reviewed and updated as needed in response to environmental or operational changes. A simple rule is to review everything at least once a year, and again whenever you change your EHR, add a location, change IT vendors or have an incident. Record the date, the reviewer and a summary of what changed. HIPAA documentation must be retained for six years from the date it was created or last in effect, so keep old versions rather than overwriting them.
It names people who no longer work for you
It refers to systems you no longer use
It describes controls you cannot actually demonstrate, such as quarterly access reviews that have never happened
Staff cannot tell you where to find it
It has no mention of remote work, texting, personal phones or cloud services
An inaccurate policy can be worse than a missing one, because it shows you knew what to do and did not do it.
Store policies in a shared location staff can search, not just a paper binder. Keep a short one-page quick reference for common questions, such as what to do when a family member asks for a resident's information over the phone. Link training to specific policies so staff learn what is actually expected of them.
We help healthcare organizations compare their written policies against their real systems and workflows, and close the gaps. If you would like a second set of eyes on your security policies in particular, UnityCare IT can walk through them with you and flag anything that no longer matches how your facility actually runs.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172