Security Management Sanction Policy, v1.0

Specifies that a health care related organization must apply appropriate sanctions against employees who fail to comply with the security policies and procedures of the organization.

Assessment Step

1
Workforce Sanctions (WorkforceSanctions)
Does the covered entity or business associate have policies and procedures to apply, in accordance with Section 164.306 (Security standards: General rules), appropriate sanctions against workforce members who fail to comply with the security policies and procedures of the organization?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Standard: Security management process. Implement policies and procedures to prevent, detect, contain, and correct security violations.

Conformance Criteria (1)

Apply Workforce Sanctions
The covered entity or business associate must, in accordance with Section 164.306 (Security standards: General rules), apply appropriate sanctions against workforce members who fail to comply with the security policies and procedures of the organization.
Citation
HIPAA-Security-Rule
45 CFR Section 164.308(a)(1)(ii)(C)