Privacy Policies and Procedures - Changes to Policies and Procedures, v1.0

Specifies that a health care related organization must change its policies and procedures as necessary and appropriate to comply with changes in the law with respect to the HIPAA Privacy Rule.
For this assessment, the assessor should determine if the organization has policies and procedures to meet the general requirements stated in the Criterion Description for changes to privacy-related policies and procedures of PHI and if the organization is specifically aware of and follows these policies and procedures. The existence and use of privacy-related policy and procedure documents based on HIPAA can satisfy this assessment.

Assessment Step

1
Changes to Policies and Procedures (ChangestoPoliciesandProcedures)
Does the covered entity have policies and procedures to change its policies and procedures as necessary and appropriate to comply with changes in the law, including the standards, requirements, and implementation specifications of Section 164.400-499 and 500-599, as described in Section 164.530(i)(2) through (i)(5)?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.

Conformance Criteria (1)

Change Policies and Procedures
The covered entity must change its policies and procedures as necessary and appropriate to comply with changes in the law, including the standards, requirements, and implementation specifications of Section 164.400-499 and 500-599.
Citation
HIPAA-Privacy-Rule
45 CFR Section 164.530(i)(2)(i)