Privacy Policies
This policy addresses the requirement to document the personnel designation.
The purpose of this policy is to set forth procedures that establish or enhance protections needed to limit unnecessary or inappropriate access to individually identifiable health information (IIHI) and protected health information (PHI) and to make reasonable efforts to safeguard use and/or inadvertent disclosure to persons other than the intended recipient.
To establish guidelines for the workforce to communicate health information with patients or authorized representative via text messaging.
Defines requirements for preparing records for scanning, operating scanning hardware to scan designated records, conducting quality checks, and appropriate follow-up of scanned documents effectively and efficiently.
The purpose of this policy is to set forth procedures that establish sanctions for failure to comply with organizational privacy rules and requirements.
To set forth requirements for making reasonable efforts to safeguard IIHI from unauthorized use and/or inadvertent disclosure to persons other than the intended recipient.
The purpose of this policy is to clearly define what steps are involved in a HIPAA risk assessment for both the privacy and security of protected health information.
The purpose of this policy is to set forth guidelines for responding to requests for medical records.
The purpose of this policy is to clearly define the steps involved in a HIPAA review of research, documentation of research and record management and retention.
To establish protocols that prevent unauthorized access to ePHI and ensure privacy during remote work settings.
This policy sets forth requirements for making reasonable efforts to protect those persons reporting violators of HIPAA rules and regulations.
The purpose of this policy is to specify requirements for processing the acknowledgment of NOPP including a refusal to sign.
This policy addresses the requirements to designate Privacy Officer and Privacy Officials to serve as the primary point of contact for all privacy related issues.
This policy recognizes personal representatives who are are authorized by individuals, the courts or by state or federal law to act on behalf of patients or authorized representative regarding their individually identifying health information in a manner consistent with all requirements within this policy.
The purpose of this policy is to set forth requirements to reasonably ensure all patients or authorized representatives receive and acknowledge receipt of the Notice of Privacy Practices when conducting outreach.
To ensure that a Notice of Privacy Practices (NOPP) is provided to and acknowledged by each patient or their personal representative upon first visit to the practice or company.
This policy outlines the procedures for archiving documents and destroying paper and electronic medical records that have been digitized.
The purpose of this policy is to set forth the requirements of the company in regard the disclosure of individually identifiable health information for purposes of marketing or fundraising activities.
This policy establishes requirements for disclosing individually identifiable health information when responding to judicial and administrative proceedings, court orders (including protective orders), subpoenas, law enforcement, and other legal mandates.
The purpose of this policy is to set forth procedures for scheduling workforce for HIPAA training.
This policy describes the process that will be used by a company in the development and approval process for its privacy policies. This process reflects state and federal laws, county rules and regulations, and current business practices.
This policy is used to protect the electronic transmission of PHI as well as to fulfill the duty to protect the confidentiality and integrity of patient’s PHI as required by law, professional ethics, and accreditation requirements.
The purpose of this policy is to set forth requirements to reasonably ensure a fair and efficient process for resolving noncompliance of HIPAA regulation.
To ensure that any medium containing Protected Health Information is properly destroyed.
The HIPAA Privacy Rule requires that patients or authorized representatives be permitted to request access and amendment to their Protected Health Information ("PHI") that is maintained in a Designated Record Set. This policy documents the contents of the Designated Record Set.
The purpose of this policy is to set forth procedures to obtain a signed agreement and questionnaires from our Business Associates to ensure they are HIPAA compliant.
It is the policy is used to report suspected HIPAA Privacy and Security Breaches to be investigated, and notification provided for breaches of unsecured Protected Health Information (PHI).
The purpose of this policy is to specify requirements for obtaining authorization to use and disclose protected health information (PHI) for purposes other than treatment, payment, and health care operations.
The purpose of this policy is to set forth procedures to establish documentation and accounting requirements for disclosures of protected health information (PHI).