Documentation Retention - Maintain Policies and Procedures, v1.0

Specifies that a health care provider organization must maintain the policies and procedures and privacy notice in written or electronic form.
Does the covered entity have policies and procedures for document retention to meet the following requirement(s).

Assessment Step

1
Documentation Retention (DocumentationRetention)
Does the covered entity maintain the policies and procedures provided for in Section 164.530(i) in written or electronic form?

Such documents include, but are not limited to:

  1. policies and procedures with respect to PHI to comply with the requirements of subpart D (Section 164.450-499 - Notification in the Case of Breach of Unsecured PHI),
  2. policies and procedures with respect to PHI to comply with the requirements of subpart E (Section 164.500-599 - Privacy of Individually Identifiable Health Information),
  3. any changes to the policies and procedures it deems necessary or to comply with changes in the law,
  4. changes to privacy practices stated in the privacy notice
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.

Conformance Criteria (1)

Maintain Policies and Procedures
The covered entity must maintain the policies and procedures provided for in paragraph Section 164.530(i) of this section in written or electronic form.
Citations
HIPAA-Privacy-Rule
45 CFR Section 164.530(j)(1)(i)
HIPAA-Privacy-Rule
45 CFR Section 164.530(i)