Periodic Nontechnical Policies Evaluation, v1.0

Specifies that a health care related organization must perform a periodic nontechnical evaluation that establishes the extent to which the organization's security policies meet requirements.

Assessment Step

1
Nontechnical Evaluation of Policies (NontechnicalEvaluationofPolicies)
Does the covered entity or business associate perform a periodic nontechnical evaluation, based initially upon the standards implemented under this rule and, subsequently, in response to environmental or operational changes affecting the security of electronic protected health information, that establishes the extent to which a covered entity's or business associate's security policies meet the requirements of this subpart (Section 164.300-399)?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
A covered entity or business associate must perform these requirements in accordance with Section 164.306 (Security standards: General rules).

Conformance Criteria (1)

Nontechnical Evaluation of Policies
The covered entity or business associate must perform a periodic nontechnical evaluation, based initially upon the standards implemented under this rule and, subsequently, in response to environmental or operational changes affecting the security of electronic protected health information, that establishes the extent to which a covered entity's or business associate's security policies meet the requirements of this subpart (Section 164.300-399).
Citations
HIPAA-Security-Rule
45 CFR Section 164.308(a)(8)
HIPAA-Security-Rule
45 CFR Section 164.306