HIPAA Privacy Rule checklist

The following HIPAA Privacy Rule checklist should be regarded as a starting point for any HIPAA compliance checklist that may be appropriate for your organization.

  1. Designate a HIPAA Privacy Officer responsible for the development, implementation, and enforcement of HIPAA compliant policies.
  2. Understand what PHI is, how it can be used and disclosed in compliance with HIPAA, and when an individual's authorization is required.
  3. Identify risks to the privacy of PHI and implement safeguards to minimize risks to a "reasonable and appropriate" level.
  4. Develop policies and procedures for using and disclosing PHI in compliance with HIPAA and for preventing HIPAA violations.
  5. Develop policies and procedures for obtaining authorizations and for giving individuals an opportunity to agree or object when required.
  6. Develop and distribute a Notice of Privacy Practices explaining how the organization uses and discloses PHI and outlining individuals´ rights.
  7. Develop policies and procedures for managing patient access requests (to their PHI), correction requests, and data transfer requests.
  8. Develop procedures for members of the workforce to report HIPAA violations and for the organization to fulfil its breach notification requirements.
  9. Train members of the workforce on the policies and procedures relevant to their roles and on general HIPAA compliance.
  10. Develop and distribute a sanctions policy outlining the sanctions for non-compliance with the organization´s HIPAA policies.
  11. Perform due diligence on Business Associates, review existing Business Associate Agreements, and revise as necessary.
  12. Develop and document a contingency plan for responding to an emergency that damages systems or physical locations in which PHI is maintained.

Did you find this article useful?