Appropriate Sanctions Against Workforce, v1.0

Specifies that a covered entity must have and apply appropriate sanctions against members of its workforce who fail to comply with the privacy policies and procedures.
A covered entity that is a group health plan is not subject to the standards or implementation specifications in this trustmark, but see Section 164.530(k) for specific exclusions.


This standard does not apply to a member of the covered entity's workforce with respect to actions that are covered by and that meet the conditions of Section 164.502(j) (Disclosures by whistleblowers and workforce member crime victims) or Section 164.530(g)(2) (Refraining from retaliation). The policies and procedures for sanctions must state so.

Assessment Steps (2)

1
Sanctions Policies (SanctionsPolicies)
Does a covered entity have policies and procedures to apply appropriate sanctions against members of its workforce who fail to comply with the privacy policies and procedures of the covered entity or the requirements of Section 164.400-499 (subpart D) and 164.500-599 (subpart E)?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
2
Sanctions Records (SanctionsRecords)
Does a covered entity have policies and procedures to document any sanctions that are applied, as required by Section 164.530(j)?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
This standard does not apply to a member of the covered entity's workforce with respect to actions that are covered by and that meet the conditions of Section 164.502(j) (Disclosures by whistleblowers and workforce member crime victims) or Section 164.530(g)(2) (Refraining from retaliation).

Conformance Criteria (2)

Apply Sanctions
The covered entity must have and apply appropriate sanctions against members of its workforce who fail to comply with the privacy policies and procedures of the covered entity or the requirements of Section 164.500-599 (subpart E) or Section 164.400-499 (subpart D).
Citations
HIPAA-Privacy-Rule
45 CFR Section 164.530(e)(1)
HIPAA-Privacy-Rule
45 CFR Section 164.502(j)
HIPAA-Privacy-Rule
45 CFR Section 164.530(g)(2)
Document Sanctions
The covered entity must have policies and procedures to document any sanctions that are applied, as required by Section 164.530(j).
Citations
HIPAA-Privacy-Rule
45 CFR Section 164.530(e)(2)
HIPAA-Privacy-Rule
45 CFR Section 164.530(j)