Retaliatory Action Against Complainant, v1.0

Specifies that a covered entity must have policies and procedures to not intimidate, threaten, coerce, discriminate against, or take other retaliatory action against any individual.

Assessment Steps (2)

1
Intimidation Prohibition (IntimidationProhibition)
Does the covered entity have policies and procedures to not intimidate, threaten, coerce, discriminate against, or take other retaliatory action against any individual for the exercise by the individual of any right established, or for participation in any process provided for by Section 164.400-499 and 500-599, including the filing of a complaint?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
2
Retaliation Prohibition (RetaliationProhibition)
Does the covered entity have policies and procedures to refrain from intimidation and retaliation as provided in Section 160.316?
Artifact
A2
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.

Conformance Criteria (2)

May Not Intimidate
The covered entity must have policies and procedures to not intimidate, threaten, coerce, discriminate against, or take other retaliatory action against any individual.
Citation
HIPAA-Privacy-Rule
45 CFR Section 164.530(g)(1)
May Not Retaliate
The covered entity must have policies and procedures to refrain from intimidation and retaliation as provided in Section 160.316.
Citation
HIPAA-Privacy-Rule
45 CFR Section 164.530(g)(2)