Skip to content. | Skip to navigation

Personal tools
You are here: Home Policies and Standards HIPAA Privacy Policies

HIPAA Privacy Policies

If you would like to be notified when changes to the HIIPAA Privacy Policies page occur, please complete this form.

TABLE OF CONTENTS

DEFINITIONS

Breach
Business Associate
Correctional Institution
Covered Entity
Covered Function
Data Aggregation
Designated Record Set
Direct Treatment Relationship
Disclosure
Electronic Protected Health Information
Employer
Health Care
Health Care Clearinghouse
Health Care Operations
Health Care Provider
Health Information
Health Oversight Agency
Health Plan
Indirect Treatment Relationship
Individually Identifiable Health Information
Inmate
Law Enforcement Official
Marketing
Organized Health Care Arrangement
Payment
Protected Health Information
Psychotherapy Notes
Public Health Authority
Required by Law
Research
Secretary
Treatment
Unsecured Protected Health Information
Use
Workforce

AR-01 TRAINING

PURPOSE
POLICY
Training Requirements
General HIPAA Training
Clinic-specific Policies and Procedures
Consideration of HIPAA Training from Previous Jobs or Experience
Training for Temporary or Short-Term Workforce Members
Training Documentation

AR-02 SHADOWING

PURPOSE
POLICY

AR-03 NOTICE OF PRIVACY PRACTICES

PURPOSE
POLICY

NPP Document
Provision of Notice
Acknowledgment
Documentation
Organized Health Care Arrangements

AR-03.1 - NPP ELEMENTS
Required Elements
Optional Element

AR-04 BUSINESS ASSOCIATES

PURPOSE
POLICY
Determining a Business Associate Relationship
Establishing the Business Associate Agreement
AR-04.1 - BAA DECISION FLOW CHART FOR COVERED ENTITIES
AR-04.2 - BAA DECISION FLOW CHART FOR BUSINESS ASSOCIATES
AR-04.3 - BAA ELEMENTS
Required Elements
Optional Elements
Desired Elements

AR-05 MINIMUM NECESSARY

PURPOSE
POLICY
Workforce Requirements
Use and Disclosure Requirements
Exceptions
AR-05.1 HIPAA ROLE-BASED ACCESS
AR-05.2 ROUTINE REQUESTS AND DISCLOSURES

AR-06 VERIFICATION REQUIREMENTS

PURPOSE
POLICY
Conditions on Disclosures
Disclosures to Public Officials

AR-07 SAFEGUARDS FOR STORAGE, TRANSMISSION, AND DISPOSAL OF PHI

PURPOSE
POLICY
Storage
Facsimile Transmissions
Email Transmissions
Confidentiality Statement
Other Safeguards
Disposal

AR-08 BUSINESS CONTINUITY AND DISASTER RECOVERY PLANS

PURPOSE
POLICY

AR-09 DESIGNATION OF PRIVACY OFFICIAL

PURPOSE
POLICY

AR-10 SANCTIONS

PURPOSE
POLICY

AR-11 NO RETALIATION POLICY

PURPOSE
POLICY

AR-12 MITIGATION POLICY

PURPOSE
POLICY

AR-13 POLICIES AND PROCEDURES

PURPOSE
POLICY
Changes to Policies or Procedures
Changes to Privacy Practices Stated in the Notice of Privacy Practices

AR-14 DOCUMENTATION

PURPOSE
POLICY

AR-15 DESIGNATED RECORD SET

PURPOSE
POLICY

AR-16 BREACH RESPONSE AND NOTIFICATION

PURPOSE
POLICY
Investigation
Discovery
Notification
Methods of Individual Notification
Notification to the Media
Notification to the Secretary
Law Enforcement Delay
Documentation
ATTACHMENT AR-16 – BREACH NOTIFICATION CONTENT

PR-01 PATIENT ACCESS TO PROTECTED HEALTH INFORMATION

PURPOSE
POLICY
Right of Access
Access to PHI held by Business Associates or Others
Personal Representatives: Verification and Authority
Timely Action
Provision of Access
Denial of Access
Documentation

PR-02 REQUESTS FOR RESTRICTIONS ON THE USE OR DISCLOSURE  OF PROTECTED HEALTH INFORMATION

PURPOSE
POLICY
Emergency Treatment
Terminating a Restriction

PR-03 REQUESTS FOR CONFIDENTIAL COMMUNICATIONS

PURPOSE
POLICY

PR-04 ACCOUNTING OF DISCLOSURES

PURPOSE
POLICY
Suspension
Provision of the Accounting
Fees
Documentation
PR-04 – CONTENT OF THE ACCOUNTING OF DISCLOSURES
Content of the Accounting

PR-05 AMENDMENT OF PROTECTED HEALTH INFORMATION

PURPOSE
POLICY
Accepting the Amendment
Denying the Amendment
Actions on Notices of Amendment
Documentation
PR-05-REQUEST FORMS
ATTACHMENT PR-05.1 REQUEST FOR AMENDMENT (Word document)
ATTACHMENT PR-05.2 RESPONSE TO REQUEST FOR AMENDMENT (Word Document)

PR-06 PATIENT COMPLAINTS

PURPOSE
POLICY

UD-01 USES AND DISCLOSURES OF PROTECTED HEALTH INFORMATION

PURPOSE
POLICY
Whistleblowers
Workforce Member Crime Victims

UD-02 TREATMENT, PAYMENT, AND OPERATIONS

PURPOSE
POLICY

UD-02 – OPERATIONS DEFINITION (45 CFR § 164.501 Definitions)

UD-03 AUTHORIZATIONS

PURPOSE
POLICY
Revocation of Authorizations
Psychotherapy Notes
Defective Authorizations
Compound Authorizations
Prohibition on Conditioning of Authorizations
UD-03 - CHECKLIST FOR A VALID AUTHORIZATION
Attachment UD-03 Checklist for a Valid Authorization (PDF)

UD-04 DISCLOSURES TO FAMILY, FRIENDS, AND OTHERS

PURPOSE
POLICY
Limited Uses and Disclosures when the Individual is not Present
Notification
Other Element

UD-05 DISCLOSURES TO PERSONAL REPRESENTATIVES

PURPOSE
POLICY
Personal Representatives: Verification and Authority

UD-06 REQUIRED BY LAW

PURPOSE
POLICY
Other Element

UD-07 PUBLIC HEALTH ACTIVITIES

PURPOSE
POLICY
Other Elements

UD-08 VICTIMS OF ABUSE, NEGLECT, OR DOMESTIC VIOLENCE

PURPOSE
POLICY
Other Elements

UD-09 HEALTH OVERSIGHT ACTIVITIES

PURPOSE
POLICY
Other Elements

UD-10 JUDICIAL AND ADMINISTRATIVE PROCEEDINGS

PURPOSE
POLICY
Court Order
Subpoena, Discovery Request, or Other Lawful Process
Qualified Protective Order
Disclosures without Satisfactory Assurance
Other Elements

UD-11 LAW ENFORCEMENT

PURPOSE
POLICY
Required by Law
Limited Information for Identification and Location Purposes
Victims of a Crime
Decedents
Crime on Premises
Reporting Crime in Emergencies
Other Elements

UD-12 DECEDENT INFORMATION

PURPOSE
POLICY
Coroners and Medical Examiners
Funeral Directors
Uses and Disclosures for Cadaveric Organ, Eye or Tissue Donation Purposes
Uses and Disclosures for Research Purposes
Other Elements

UD-13 RESEARCH

PURPOSE
POLICY
De-identified Data
Limited Data Set
Authorization
Waiver or Alteration of Authorization
Preparatory to Research
Information on Decedents
Effect of Prior Permission for Research
UD-13.1 - REQUIRED ELEMENTS, DOCUMENTATION OF WAIVER APPROVAL
ATTACHMENT UD-13.2 - CHECKLIST FOR THE PREPARATORY TO RESEARCH EXCEPTION
ATTACHMENT UD-13.3 - CHECKLIST FOR THE RESEARCH ON DECEDENTS EXCEPTION

UD-14 TO AVERT A SERIOUS THREAT OR INJURY

PURPOSE
POLICY
Use or Disclosure not Permitted
Other Elements

UD-15 SPECIALIZED GOVERNMENT FUNCTIONS

PURPOSE
POLICY
Military and Veterans Activities
National Security and Intelligence Activities
Protective Services for the President and Others
Correctional Institutions and Other Law Enforcement Custodial Situations
Covered Entities that are Government Programs Providing Public Benefits
Other Elements

UD-16 WORKER’S COMPENSATION

PURPOSE
POLICY
Other Elements

UD-17 USES AND DISCLOSURES OF DE-IDENTIFIED  PROTECTED HEALTH INFORMATION

PURPOSE
POLICY
Requirements for De-identification of PHI
Re-identification
ATTACHMENT UD-17 - DE-IDENTIFIED DATA SET

UD-18 USES AND DISCLOSURES OF LIMITED DATA SETS

PURPOSE
POLICY
UD-18.1 - LIMITED DATA SET
UD-18.2 - DATA USE AGREEMENT

UD-19 FUNDRAISING

PURPOSE
POLICY

UD-20 MARKETING

PURPOSE
POLICY

UD-21 PROHIBITION ON SALE OF PROTECTED HEALTH INFORMATION

PURPOSE
POLICY

Exceptions

HIPAA Privacy PolicyDOWNLOAD HIPAA PRIVACY POLICIES IN OFFICIAL FORMAT (PDF) FOR PRINTING (Requires ULink Login)

Document Actions
Personal tools