Phoenix Health Systems'
HIPAA Privacy Policies Template Suite
For Healthcare Providers
Overview
HIPAA requires healthcare providers to implement a comprehensive
approach to protecting the privacy of personal health information.
For many organizations, this necessitates a major overhaul of their
policies, procedures and processes for handling protected health
information.
The huge task of developing or revising the organization's privacy
policies may be the single most difficult aspect of HIPAA privacy
implementation. Each policy must be specific relative to the privacy
regulations' complex requirements, yet be worded simply enough to
be understood and applied across the workforce. Each policy must
also set the foundation for the individual departmental procedures
needed to support and implement the policy.
Phoenix Health Systems has developed a "near-camera-ready"
suite of privacy policies to help hospitals and other providers
meet these daunting objectives. The Phoenix HIPAA Privacy Policies
Templates are intended to jump-start privacy officials' efforts
in tailoring privacy policies and procedures to reflect their organizations'
specific needs and operating environments, in order to:
- satisfy regulatory mandates, and
- define an organizational culture and policy framework to drive
HIPAA privacy implementation.
Phoenix' HIPAA Privacy Policies Templates are mapped to the final
federal HIPAA privacy regulations of December 28, 2000 and as modified
August 14, 2002. They are written from a hospital perspective, but
are also useful for skilled nursing facilities and other provider
environments. Each template is presented in a standard format reflecting
critical organizational functions to consider in HIPAA remediation:
|
Policy Administration:
|
Provides space for reviews, approvals, numbering
|
|
Policy Summary:
|
Generally summarizes the scope and intent of the policy.
|
|
Purpose:
|
Describes what the organization is trying to accomplish through
execution of the policy.
|
|
Policy:
|
Provides suggested wording for the policy detail. The templates
are written to incorporate all of the relevant regulatory
requirements in each policy.
|
|
Scope/Applicability:
|
Provides for listing of all departments to which the policy
would apply. Users should identify applicable departments
and areas and insert this information here.
|
| Regulatory Reference: |
Cites the section(s) of the HIPAA administrative simplification
regulations to which the template relates. |
| Definitions: |
Related definitions are included in every policy to ensure
that each policy will "stand on its own", and to minimize
misinterpretation. |
| Responsible Department: |
Provides space for listing the department responsible for
implementing the policy. |
| Authority/Enforcement: |
Offers space for listing of personnel responsible for monitoring
and enforcing the policy. This section generically includes
the Privacy Official. Users may incorporate titles to match
their organization's terminology, organizational structure and
division of duties. |
| Related Policies: |
Provides references to other HIPAA policies that relate in
content or intent. |
| Renewal/Review: |
Provides opportunity for organization to outline a schedule
and/or circumstances under which policy is to be reviewed and
updated. |
| Procedures: |
Offers space for organization to reference procedures that
are put in place to support and implement the policy. Templates
include the generic "TBD" (to be determined). |
| Notes: |
Additional notes are set apart in courier type to provide
users with additional direction in drafting policies and procedures.
|
Providers may obtain a perpetual license for indefinite use and
customization of the Phoenix HIPAA Privacy Policies Templates Suite
within their organization. Policies are delivered immediately via
CD.
|