Compliance Date for Privacy Implementation - Non-Small Health Plans, v1.0

Specifies rules for determining a health care related organization's starting date of compliance with the privacy rules based on the type of health care organization.
The health care entity must abide by the compliance date depending on the type of entity.


This assessment in only applicable if the health care provider is a health plan that is not a small health plan.

Assessment Step

1
Health Plan Organization (HealthPlanOrganization)
If the health care provider is a health plan that is not a small health plan, does it comply with the applicable requirements of this subpart (Section 164.500-599) no later than April 14, 2003?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Compliance dates for the Privacy Rule vary by type of health care entity.


Conformance Criteria (1)

Organization is a Health Plan
If the organization is a health plan that is not a small health plan, it must comply with the applicable requirements of this subpart (Section 164.500-599) no later than April 14, 2003.
Citation
HIPAA-Privacy-Rule
45 CFR Section 164.534(b)(1)