hipaa.systems
Security Rule · 45 CFR 164.316, 164.530(i)

HIPAA policies and procedures

What written policies and procedures HIPAA requires, how to keep them current, and how long to keep them — for small practices and business associates.

Checked 2026-10-06Sources 2

HIPAA policies and procedures at a glance

HIPAA requires covered entities to have written policies and procedures implementing the Privacy and Security Rules, and business associates to have them for the Security Rule and the Privacy and Breach duties that apply to them; keep them up to date when laws or practices change, make them available to the staff who use them, and retain each version for six years (45 CFR 164.316 and 164.530(i)–(j)). Policies must be reasonable for the organization's size and activities and backed by training and sanctions.

Rules45 CFR 164.316 (Security) and 164.530(i)–(j) (Privacy)
FormWritten, which may be electronic
Keep6 years from creation or last effective date
UpdateWhen laws, operations or risks change; periodic review
Make availableTo the people responsible for carrying them out

What the rules require

  • Security Rule (164.316): implement reasonable and appropriate policies and procedures to comply with each standard, keep them in writing, keep records of required actions and assessments, retain both for six years, make them available to those who implement them, and review and update them periodically.
  • Privacy Rule (164.530(i)–(j)): policies and procedures for PHI designed to comply with the Privacy Rule and reasonable for your size and activities; change them when the law changes; document and retain them for six years.

A typical small-organization set

Area Covers
Privacy Uses and disclosures, minimum necessary, authorizations, patient rights
Security Risk analysis, access control, encryption, audit logs, devices, backups and contingency
Vendors BAAs and vendor review
People Training, sanctions, access changes when staff join or leave
Incidents Incident response and breach notification
Records Documentation retention

Making them real

Policies only count if they match what you actually do. Adapt any template to your tools and workflows, train staff on them, and record each version.

Frequently asked questions

What policies does HIPAA require?

Policies covering how PHI is used and disclosed, patient rights, minimum necessary, safeguards, workforce training and sanctions, complaints, breach response, and the Security Rule's administrative, physical and technical safeguards.

Can I use HIPAA policy templates?

Yes, as a starting point. They must be adapted to how your organization actually works, and staff must be trained on them.

How often should HIPAA policies be reviewed?

The rules require updates whenever needed to stay compliant and periodic review; most organizations review them at least yearly.