120+ action items, templates, and worksheets to establish and maintain a complete HIPAA compliance program.
The Privacy Rule establishes standards for the use and disclosure of PHI. Verify each item below with your Privacy Officer.
Administrative safeguards are policies and procedures designed to manage the selection and implementation of security measures.
Physical safeguards limit physical access to information systems and the facilities housing them.
Technical safeguards are the technology and policy controls that protect ePHI and control access to it.
A breach is any impermissible use or disclosure that compromises the security or privacy of PHI. Follow this checklist for incident response.
A Business Associate Agreement is required with any vendor or third party that creates, receives, maintains, or transmits PHI on your behalf.
Every HIPAA-compliant BAA must include these 7 elements (per 45 CFR §164.504(e)):