Policy required document Healthcare
HIPAA Privacy Policies and Procedures
The HIPAA Privacy Rule tells a covered entity to write down how it uses and discloses protected health information and how it honors patient rights, then to keep those written policies current and on file. The rule does not hand you a table of contents.
It lists standards (minimum necessary, uses and disclosures, patient access, amendment, accounting, complaints, sanctions, training, mitigation, safeguards) and says the policies must be reasonably designed to comply with each one, taking the size and type of the organization into account.
In practice this is a policy manual of fifteen to thirty documents plus the records that prove they operate: training completions, sanction records, complaint logs, and the six-year archive of every prior version.
When the Office for Civil Rights opens an investigation, its first data request asks for the policies in force on the date of the incident and the training and sanction records that go with them.
Obligation ledger
Who requires it, and what each one says.
| Source | Applies when | What it requires | Status |
|---|---|---|---|
| HIPAA Privacy Rule, administrative requirements 45 CFR 164.530(i) | You are a covered entity, or a business associate to the extent required by 164.504(e) | Implement policies and procedures for PHI reasonably designed to comply with Subpart E, change them when the law changes, and document each change. Legally required. | Mandatory |
| HIPAA Privacy Rule, documentation and retention 45 CFR 164.530(j) | Always, for every covered entity | Maintain the policies in written or electronic form, keep records of every action required to be documented, and retain them six years from creation or from the date last in effect, whichever is later. Legally required. | Mandatory |
| HIPAA Privacy Rule, workforce training 45 CFR 164.530(b) | Always | Train each workforce member on the policies as necessary for their role, within a reasonable time after hire and after any material policy change, and document the training. Legally required. | Mandatory |
| HIPAA Privacy Rule, sanctions 45 CFR 164.530(e) | Always | Have and apply appropriate sanctions against workforce members who violate the policies, and document the sanctions applied. Legally required. | Mandatory |
| OCR investigation data requests OCR practice, not a rule | A complaint or breach report triggers an OCR review | Policies in force on the incident date, evidence of workforce training, the sanction policy and sanctions applied, and the risk analysis. Not stated in the regulation as a list; this is examiner expectation drawn from published resolution agreements. | Implied |
| HHS-OIG General Compliance Program Guidance GCPG, November 2023, element 1 | You participate in federal health care programs | Written policies and procedures, including a code of conduct, as the first element of an effective compliance program. Voluntary guidance; the privacy policies are usually filed inside this larger set. | Market |
Required sections
- Designated privacy official and contact person for complaints (164.530(a))
- Permitted and required uses and disclosures, including treatment, payment and operations (164.502, 164.506)
- Authorization content and handling (164.508)
- Minimum necessary standard and role-based access classes (164.502(b), 164.514(d))
- Patient rights procedures: access within 30 days, amendment, accounting of disclosures, restriction requests, confidential communications (164.524 to 164.528)
- Notice of Privacy Practices distribution and acknowledgment of receipt (164.520)
- Business associate identification and agreement management (164.504(e))
- Complaint intake and handling (164.530(d))
- Workforce training and documentation of training (164.530(b))
- Sanctions for violations, applied and documented (164.530(e))
- Mitigation of harmful effects of a known violation (164.530(f))
- No retaliation and no waiver of rights (164.530(g), (h))
- Breach risk assessment and notification procedures (164.400 to 164.414)
- Documentation, version control and six-year retention (164.530(j))
- Statement on substance use disorder records if you hold Part 2 records (required in the NPP from Feb 16, 2026; policy-level cross reference is best practice)
What the examiner asks for
What changed
Change log.
Frameworks
Where this document is required.
Who looks at it
Where this document gets checked.
No one certifies a document like this on its own. It is read during the audits and inspections below, and by the agency behind each rule.
| Where it is looked at | Who looks at it |
|---|---|
| 42 CFR Part 2 | HHS Office for Civil Rights investigates complaints and breaches and can impose civil money penalties; the Department of Justice can bring criminal cases. State licensing surveys and accreditors (CARF, Joint Commission) check Part 2 practices as part of broader surveys. There is no certification |
| HIPAA | Government enforcement only. OCR investigates complaints and breach reports, conducts compliance reviews and periodic audits, and can impose civil money penalties or resolution agreements; state attorneys general may also sue under HITECH. There is no HIPAA certification recognized by HHS; third-party assessments (including HITRUST) are voluntary |
| OIG 7-element program | No certification. OIG, DOJ, and CMS evaluate program effectiveness during investigations and audits; organizations under a corporate integrity agreement are reviewed annually by an independent review organization. Boards and internal audit typically commission periodic effectiveness reviews |
Who helps write it
Consultants.
Firms that name these standards in their own material.
No firm has claimed a listing for this document yet. Claim yours →
Where it lives
Software.
Tools that hold documents like this one and record who has read them.
Need a hand implementing it?
Find a Consultant for HIPAA Privacy Policies and Procedures
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Manage This Document in AllyMatter
Route it for approval, keep every version, and record a named acknowledgment from everyone who has to read it.
Questions
What people ask.
Does HIPAA give a list of policies I must have?
No. It lists standards and says the policies must be reasonably designed to meet them. The required-sections list above is the union of the standards that generate a document in practice. A one-clinician practice can meet them in a shorter manual than a hospital.
How long do I keep old versions?
Six years from the date the policy was created or last in effect, whichever is later. That means the version replaced in 2024 stays on file until 2030.
Do staff need to sign the privacy policies?
The rule requires documented training, not a signature. Many organizations collect an acknowledgment anyway because OCR asks for proof that a specific employee knew a specific policy. The record of who completed training on which version answers that question.
Did the 2024 reproductive health rule change my policies?
It did for a year, then a federal court vacated most of it in June 2025. The one surviving piece is the Notice of Privacy Practices change for substance use disorder records, due February 16, 2026. Check the current eCFR text before you cut anything.
Who owns this site?
AllyMatter, a policy management tool that may appear in listings on this page. It is labeled every time, excluded from picks, and receives nothing from the matching form unless you name it.