Privacy Policies and Procedures - Changes in Law, v1.0

Specifies that a health care related organization must promptly document and implement a revised policy or procedure, and also promptly revise the privacy notice if there are material changes to it, whenever a change in the law necessitates a change in policies or procedures

Assessment Steps (2)

1
Update Policies and Procedures (UpdatePoliciesandProcedures)
Whenever there is a change in law that necessitates a change to the covered entity's policies or procedures, does the covered entity have policies and procedures to promptly document and implement the revised policy or procedure?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
2
Update Privacy Notice (UpdatePrivacyNotice)
If the change in law materially affects the content of the notice required by Section 164.520 (Notice of Privacy Practices for PHI), does the covered entity have policies and procedures to promptly make the appropriate revisions to the notice in accordance with Section 164.520(b)(3) (Revisions to the notice)?
Artifact
A2
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.

Conformance Criteria (1)

Changes in Law
Whenever there is a change in law that necessitates a change to the covered entity's policies or procedures, the covered entity must promptly document and implement the revised policy or procedure.


If the change in law materially affects the content of the notice required by Section 164.520 (Notice of Privacy Practices for PHI), the covered entity must promptly make the appropriate revisions to the notice in accordance with Section 164.520(b)(3) (Revisions to the notice).


Nothing in this paragraph may be used by a covered entity to excuse a failure to comply with the law.

Citation
HIPAA-Privacy-Rule
45 CFR Section 164.530(i)(3)