Privacy Policies and Procedures - Changes to Other Policies or Procedures - ii, v1.0

Specifies requirements and restrictions for health care related organizations on how to change the privacy practices in the privacy notice if revisions are necessary.
Note: See related trustmark for criteria i.

Assessment Step

1
Changes to Other Policies and Procedures (ChangestoOtherPoliciesandProcedures)
Does the covered entity have policies and procedures to change, at any time, a policy or procedure that does not materially affect the content of the privacy notice required by Section 164.520? Such policies and procedures to change policies and procedures must meet the following requirements:
  1. Do the policies and procedures require that prior to the effective date of the change, the revised policy or procedure is documented as required by paragraph Section 164.530(j) (Maintain policies and procedures; communications; actions, activities, and designations; documentation sufficient to meet burden of proof; in written or electronic form)?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.

Conformance Criteria (1)

Policy or Procedure Changes
A covered entity may change, at any time, a policy or procedure that does not materially affect the content of the privacy notice required by Section 164.520, provided that:
  1. The revised policy or procedure complies with the standards, requirements, and implementation specifications of subpart E (Section 164.500-599); and
  2. Prior to the effective date of the change, the revised policy or procedure is documented as required by paragraph Section 164.530(j) (Maintain policies and procedures; communications; actions, activities, and designations; documentation sufficient to meet burden of proof; in written or electronic form).
Citation
HIPAA-Privacy-Rule
45 CFR Section 164.530(i)(5)(ii)