Documentation Retention - Meet Burden of Proof, v1.0

Specifies that a health care provider organization must maintain documentation sufficient to meet its burden of proof to demonstrate that all required notifications were made in the event of a data breach.
Section 164.414(b) states: In the event of a use or disclosure in violation of subpart E (Section 164.500-599 - Privacy of PHI), the covered entity or business associate, as applicable, shall have the burden of demonstrating that all notifications were made as required by subpart D (Section 164.450-499 - Notification in the Case of Breach of Unsecured PHI) or that the use or disclosure did not constitute a breach, as defined at Section 164.402.

Assessment Step

1
Documentation Retention (DocumentationRetention)
Does the covered entity have policies and procedures to maintain documentation sufficient to meet its burden of proof under Section 164.414(b)?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.

Conformance Criteria (1)

Meet Burden of Proof
A covered entity must maintain documentation sufficient to meet its burden of proof under Section 164.414(b). Burden of Proof is to demonstrate that all required notifications were made in the event of an unauthorized use or disclosure of PHI or that a breach did not occur.
Citation
HIPAA-Privacy-Rule
45 CFR Section 164.530(j)(1)(iv) and Section 164.414(b)