Redress - Complaints, v1.0

Defines privacy requirements related to organizations monitoring their ability to receive and act on complaints with respect to sensitive information.

Assessment Step

1
Redress - Complaints (Redress-Complaints)
Does the organization require persons and entities, that participate in a network for the purpose of electronic exchange of sensitive information, to address monitoring for the ability to receive and act on complaints, including taking corrective measures?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Information Typesrequired
ENUM_MULTI : Select the type(s) of sensitive information that apply.
  • PII
  • PHI
  • III
  • IIHI
  • Other

Conformance Criteria (1)

C-1
Persons and entities, that participate in a network for the purpose of electronic exchange of individually identifiable health information, should address monitoring for the ability to receive and act on complaints, including taking corrective measures.
Citation
HHS-PSF
Section II, Accountability