How to make Policies and Forms available to the HIPAA Compliance Officer

Of course, it is important for the HIPAA Compliance Officer to be familiar with all the policies and forms that are included in your package. It is recommended to download your package and extract all files. Below are some files that you may want close at hand in addition to the files made available to the employees above:

Step 2: Security Incident Procedures and Breach Notification Plan

         Security Incident Policy

         Security Incident Plan

         State Law Requirements

         Security Incident Report – Breach Notification Report 

Step 3: HIPAA Policies and Procedures

         Employee (Workforce) Security – Clearance and Termination Policy

         Workstation (Inventory) Security Policy

         Social Media Policy

Step 4: HIPAA Forms and Documentation:

         Employee (Workforce) Clearance Checklist

         Employee (Workforce) Termination Checklist

         HIPAA Security Reminder Log

         Information Activity Review Forms (if you do not receive reports from your IT department or download access logs from your EHR)

         Social Media and Marketing Agreement

Step 6: Contingency Plan

         Contingency Plan (even if you have one from your IT vendor, you must know how to respond to emergencies and disasters)

Step 7: Information, Laws, and Resources

         Review each area to choose what to download. There is a wealth of information in this Step to help you to understand the laws and share with the staff.

  • 0 Users Found This Useful
Was this answer helpful?

Related Articles

How to make Policies and Forms available to Employees?

It is recommended to download your package and extract all files. Below are some of the policies...

What to do in the event of a data breach?

A breach is defined as an impermissible use or disclosure of Protected Health Information (PHI)....

What are audit logs and why do I need them?

Audit logs are sometimes called access logs. They are located in a variety of places, depending...

What type of reports do I need from my IT department/vendor?

The IT department/vendor should be sending the HIPAA Compliance Officer monthly reports. These do...