HIPAA policies and procedures
What written policies and procedures HIPAA requires, how to keep them current, and how long to keep them — for small practices and business associates.
HIPAA policies and procedures at a glance
HIPAA requires covered entities to have written policies and procedures implementing the Privacy and Security Rules, and business associates to have them for the Security Rule and the Privacy and Breach duties that apply to them; keep them up to date when laws or practices change, make them available to the staff who use them, and retain each version for six years (45 CFR 164.316 and 164.530(i)–(j)). Policies must be reasonable for the organization's size and activities and backed by training and sanctions.
| Rules | 45 CFR 164.316 (Security) and 164.530(i)–(j) (Privacy) |
|---|---|
| Form | Written, which may be electronic |
| Keep | 6 years from creation or last effective date |
| Update | When laws, operations or risks change; periodic review |
| Make available | To the people responsible for carrying them out |
What the rules require
- Security Rule (164.316): implement reasonable and appropriate policies and procedures to comply with each standard, keep them in writing, keep records of required actions and assessments, retain both for six years, make them available to those who implement them, and review and update them periodically.
- Privacy Rule (164.530(i)–(j)): policies and procedures for PHI designed to comply with the Privacy Rule and reasonable for your size and activities; change them when the law changes; document and retain them for six years.
A typical small-organization set
| Area | Covers |
|---|---|
| Privacy | Uses and disclosures, minimum necessary, authorizations, patient rights |
| Security | Risk analysis, access control, encryption, audit logs, devices, backups and contingency |
| Vendors | BAAs and vendor review |
| People | Training, sanctions, access changes when staff join or leave |
| Incidents | Incident response and breach notification |
| Records | Documentation retention |
Making them real
Policies only count if they match what you actually do. Adapt any template to your tools and workflows, train staff on them, and record each version.
Related requirements
- HIPAA documentation retention →§ 164.316(b)(2)
- HIPAA training requirements →§ 164.530(b)
- Security risk analysis →§ 164.308(a)(1)(ii)(A)
Frequently asked questions
What policies does HIPAA require?
Policies covering how PHI is used and disclosed, patient rights, minimum necessary, safeguards, workforce training and sanctions, complaints, breach response, and the Security Rule's administrative, physical and technical safeguards.
Can I use HIPAA policy templates?
Yes, as a starting point. They must be adapted to how your organization actually works, and staff must be trained on them.
How often should HIPAA policies be reviewed?
The rules require updates whenever needed to stay compliant and periodic review; most organizations review them at least yearly.