Privacy Policies and Procedures - Implementation, v1.0

Specifies that a health care related organization must implement policies and procedures with respect to protected health information that are designed to comply with the standards, implementation specifications, or other requirements of the Privacy Rule.
For this assessment, the assessor should determine if the organization has documented and follows (i.e., implemented) the general requirements stated in the Criterion Description for protection of PHI and if the organization is specifically aware of and follows the HIPAA Privacy Rule. The existence and use of privacy-related policy and procedure documents based on HIPAA can satisfy this assessment. Other trustmarks will test the specific requirements of the Privacy Rule.

Assessment Steps (2)

1
Must Document (MustDocument)
Does the covered entity have documented policies and procedures with respect to protected health information that are designed to comply with the standards, implementation specifications, or other requirements of Section 164.400-499 and 500-599?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
2
Must Implement (MustImplement)
Does the covered entity implement policies and procedures with respect to protected health information that are designed to comply with the standards, implementation specifications, or other requirements of Section 164.400-499 and 500-599?
Artifact
A2
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.

Conformance Criteria (1)

Implementation Standard
The covered entity must implement policies and procedures with respect to protected health information that are designed to comply with the standards, implementation specifications, or other requirements of Section 164.400-499 and 500-599. The policies and procedures must be reasonably designed, taking into account the size and the type of activities that relate to protected health information undertaken by a covered entity, to ensure such compliance. This standard is not to be construed to permit or excuse an action that violates any other standard, implementation specification, or other requirement of this subpart.
Citation
HIPAA-Privacy-Rule
45 CFR Section 164.530(i)(1)