Health Information Management

What are the requirements for maintaining HIPAA-related policies and procedures?

HIPAA Weekly Advisor, May 9, 2003

Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!

Q: What are the privacy rule requirements for maintaining HIPAA-related policies and procedures?

A: With respect to protected health information (PHI), covered entities must implement policies and procedures that are designed to comply with the standards, implementation specifications, or other requirements of the rule. (This requirement does not apply to certain group health plans.) The policies and procedures must be reasonably designed, taking into account the size of and the type of activities that relate to PHI, to ensure compliance.

Covered entities must change policies and procedures as necessary to comply with changes in the law, including the standards, requirements, and implementation specifications of the regulations. In addition, the rule states that covered entities may make any other changes to policies and procedures at any time.

Whenever a change in law necessitates a change to a covered entity's policies or procedures, the covered entity must promptly document and implement the revised policy or procedure. If the change in law materially affects the content of the notice of privacy practices, the covered entity must promptly make the appropriate revisions to the notice.

A group health plan that provides benefits solely through an issuer or health maintenance organization (HMO), and does not create, receive, or maintain PHI other than summary health information or information regarding enrollment and disenrollment is exempt from the policies and procedures requirements.

Editor's note: Brought to you by attorneys Marty Baxter and Gretchen McBeath at Bricker and Eckler, LLP and The Quality Management Consulting Group, Ltd.. E-mail: mbaxter@bricker.com or gmcbeath@bricker.com



Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!

  • Briefings on APCs

    Worried about the complexities of the new rules under OPPS and APCs? Briefings on APCs helps you understand the new rules...

  • Medical Records Briefing

    Guiding Health Information Management professionals through the continuously changing field of medical records and toward a...

  • Briefings on Coding Compliance Strategies

    Submitting improper Medicare documentaion can lead to denial of fees, payback, fines, and increased diligence from payers...

  • Briefings on HIPAA

    How can you minimize the impact of HIPAA? Subscribe to Briefings on HIPAA, your health information management resource for...

  • APCs Weekly Monitor

    This HTML-based e-mail newsletter provides weekly tips and advice on the new ambulatory payment classifications regulations...

Most Popular

Related Articles