Privacy Policies and Procedures - Changes to Privacy Practices in Notice - C, v1.0

Specifies requirements and restrictions for health care related organizations on how to change the privacy practices in the privacy notice if revisions are necessary.
Note: See related trustmark for criteria A and B.

Assessment Step

1
Document Changes in Notice (DocumentChangesinNotice)
Does the covered entity have policies and procedures to change a privacy practice documented in the privacy notice?


These policies and procedures must meet the follow requirements:

  1. Does the covered entity revise the privacy notice as required by Section 164.520(b)(3) (Revisions to the notice) to state the changed practice and make the revised notice available as required by Section 164.520(c) (Provision of notice). The covered entity may not implement a change to a policy or procedure prior to the effective date of the revised notice.
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.

Conformance Criteria (1)

Privacy Practice Changes
To implement a change in a privacy practice that is stated in the privacy notice as provided by Section 164.530(i)(2)(ii) (changing a privacy practice that is stated in the privacy notice), a covered entity must:
  1. Ensure that the revised policy or procedure reflects a change in the covered entity's privacy practice as stated in its notice, and complies with the standards, requirements, and implementation specifications of subpart E (Section 164.500-599);
  2. Document the revised policy or procedure, as required by Section 164.530(j) (Maintain policies and procedures; communications; actions, activities, and designations; documentation sufficient to meet burden of proof; in written or electronic form); and
  3. Revise the privacy notice as required by Section 164.520(b)(3) (Revisions to the notice) to state the changed practice and make the revised notice available as required by Section 164.520(c) (Provision of notice). The covered entity may not implement a change to a policy or procedure prior to the effective date of the revised notice.
Citation
HIPAA-Privacy-Rule
45 CFR Section 164.530(i)(4)(i)(C)