{"id":24487,"date":"2020-09-22T06:54:16","date_gmt":"2020-09-22T06:54:16","guid":{"rendered":"https:\/\/www.process.st\/templates\/hipaa-privacy-risk-assessment-checklist\/"},"modified":"2024-02-29T02:55:03","modified_gmt":"2024-02-29T02:55:03","slug":"hipaa-privacy-risk-assessment-checklist","status":"publish","type":"post","link":"https:\/\/www.process.st\/templates\/hipaa-privacy-risk-assessment-checklist\/","title":{"rendered":"HIPAA Privacy Risk Assessment Checklist"},"content":{"rendered":"<section id=\"introduction\">\n<h2>Introduction:<\/h2>\n<div class=\"image-content\">\n<figure> <a href=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/qpT8uegkEM3YpGH005ZFvw.png\" alt=\"Introduction:\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/qpT8uegkEM3YpGH005ZFvw.png\"> <\/a><br \/>\n  <\/figure>\n<\/p><\/div>\n<div class=\"text-content\">\n<p>The <strong>requirement for covered entities to conduct a HIPAA risk assessment<\/strong> was introduced in 2003 with the original HIPAA Privacy Rule.<\/p>\n<p>Conducting periodic risk assessments is not only required by law, but will also help you <strong>avoid potential violations<\/strong> that can be incredibly costly.<\/p>\n<p><em>\"More recently, the majority of fines have been under the \u201cWillful Neglect\u201d HIPAA violation category, where organizations knew \u2013 or should have known \u2013 they had a responsibility to safeguard their patients\u00b4 personal information. Many of the largest fines \u2013 including the record $5.5 million fine issued against the Advocate Health Care Network \u2013 are attributable to organizations failing to identify where risks to the integrity of PHI existed.\" - <\/em><a href=\"https:\/\/www.hipaajournal.com\/\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Journal<\/a>, <a href=\"https:\/\/www.hipaajournal.com\/hipaa-risk-assessment\/\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Risk Assessment<\/a><\/p>\n<p>Facing a sudden data breach by a group of skilled cyber-crime attackers would be a lot more damaging if an investigation showed that the breach could have been avoided, and was <strong>largely due to a failure to identify and safeguard risks.<\/strong><\/p>\n<p>This checklist is designed to guide you through a <strong>comprehensive evaluation of your compliance with the HIPAA Privacy Rule<\/strong>, and to identify areas that need to be addressed to improve PHI security.<\/p>\n<p>The template is split up into the following sections:<\/p>\n<ul>\n<li>Check-in procedures (patient identity verification, insurance etc.)<\/li>\n<li>Clinical areas (ensuring no PHI is visible\/accessible)<\/li>\n<li>Medical records (staff access, physical security, patient authorization)<\/li>\n<li>General security (computer monitors, paper records)<\/li>\n<li>Personnel policies (employee training, documentation)<\/li>\n<\/ul>\n<p>Once the checklist is complete, you will have an accurate understanding of how well your organization is protecting PHI. You will also identify areas that need to be addressed and set out <strong>clear action items to optimize security measures.<\/strong><\/p>\n<p>Let's get started!<\/p>\n<h4>A little info about Process Street<\/h4>\n<p>Process Street is&nbsp;<strong>superpowered checklists<\/strong>. By using our software to document your processes, you are instantly creating an actionable workflow in which tasks can be assigned to team members, automated, and monitored in real-time to ensure they are being executed as intended, each and every time.<\/p>\n<p>The point is to&nbsp;<strong>minimize human error, increase accountability<\/strong>, and&nbsp;<strong>provide employees with all of the tools and information necessary<\/strong>&nbsp;to complete their tasks as effectively as possible.<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"enter-basic-details\">\n<h2>Enter basic details<\/h2>\n<div class=\"text-content\">\n<p>First, enter some <strong>basic details regarding your organization.<\/strong><\/p>\n<\/p><\/div>\n<div class=\"text-field-content form-field-content\">\n<div class=\"form-group\"> <label> Company Name <\/label><br \/>\n   <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\">\n  <\/div>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\"> <label> Company Address <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<div class=\"text-field-content form-field-content\">\n<div class=\"form-group\"> <label> Company Main Contact - Name <\/label><br \/>\n   <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\">\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"checkin-procedures\">\n<h2>Check-in procedures:<\/h2>\n<\/section>\n<section id=\"ensure-assistance-is-provided-for-new-patient-form-completion\">\n<h2>Ensure assistance is provided for new patient form completion<\/h2>\n<div class=\"text-content\">\n<p>When a new patient enters your medical institution, they <strong>may be unsure as to what information they are required to provide<\/strong>, and which form(s) they need to fill out.&nbsp;<\/p>\n<p>It is therefore important that the <strong>appropriate staff provide assistance<\/strong> when the patient is filling out the forms necessary for them to be admitted.&nbsp;<\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\"> <label> Is assistance provided for new patient form completion? <\/label> <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"ensure-patient-insurance-is-verified\">\n<h2>Ensure patient insurance is verified<\/h2>\n<div class=\"text-content\">\n<p>Its essential that <strong>patient insurance is verified<\/strong> for each and every patient that is admitted to your medical institution.&nbsp;<\/p>\n<p>To do so, you must<strong> carry out the process of checking a patients active coverage with the insurance company<\/strong> and verifying the eligibility of his or her insurance claims.&nbsp;<\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\"> <label> Is patient insurance being verified? <\/label> <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\"> <label> Summary of patient insurance verification procedure <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<div class=\"text-content\">\n<p class=\"style-warning\">Patients would be<strong> ineligible for benefits<\/strong> when they provide<strong> wrong or outdated information<\/strong>, or when their policies have been terminated or modified. A <strong>simple error can result in claim rejection or denial<\/strong>, so you have to be sure it is being done correctly.<\/p>\n<p class=\"style-success\">To take the stress out of managing patient insurance, it is better to outsource&nbsp;<a href=\"https:\/\/www.outsourcestrategies.com\/medical-billing\/insurance-verification-services.htm\" rel=\"nofollow noopener\" target=\"_blank\" title=\"Insurance Verification Services\"><strong>insurance verification services<\/strong><\/a>&nbsp;to an outsourcing company that can get your claims billed and processed accurately.&nbsp;<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"ensure-patients-sign-the-notice-of-privacy-practices-acknowledgement\">\n<h2>Ensure patients sign the Notice of Privacy Practices Acknowledgement<\/h2>\n<div class=\"text-content\">\n<p>The Notice of Privacy Practices Acknowledgement is provided to the patient and <strong>details how the healthcare provider may use and share your health information.<\/strong>&nbsp;<\/p>\n<p>The law requires that the doctor, hospital, or healthcare provider <strong>must ask the patient to state in writing that they received the notice.<\/strong><\/p>\n<hr>\n<h4>What is in the Notice?<\/h4>\n<p>As stated on the <a href=\"https:\/\/www.hhs.gov\/hipaa\/for-individuals\/notice-privacy-practices\/index.html\" rel=\"nofollow noopener\" target=\"_blank\">HHS website<\/a>, the notice must describe:<\/p>\n<ul>\n<li>How the Privacy Rule allows provider to use and disclose protected health information. It must also explain that your permission (authorization) is necessary before your health records are shared for any other reason<\/li>\n<li>The organization\u2019s duties to protect health information privacy<\/li>\n<li>Your privacy rights, including the right to complain to HHS and to the organization if you believe your privacy rights have been violated<\/li>\n<li>How to contact the organization for more information and to make a complaint<\/li>\n<\/ul>\n<p class=\"style-warning\">The patient can ask for a copy of the notice at any time.<\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\"> <label> Do all patients sign the Notice of Privacy Practices Acknowledgement? <\/label> <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"evaluate-process-for-sending-appointment-reminders\">\n<h2>Evaluate process for sending appointment reminders<\/h2>\n<div class=\"image-content\">\n<figure> <a href=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/u-sStfdQl79VHD3OEWlB3g.jpg\" alt=\"Evaluate process for sending appointment reminders\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/u-sStfdQl79VHD3OEWlB3g.jpg\"> <\/a><br \/>\n  <\/figure>\n<\/p><\/div>\n<div class=\"text-content\">\n<p>According to the U.S. Department of Health &amp; Human Services, <a href=\"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/faq\/286\/are-appointment-reminders-allowed-under-hipaa-without-authorization\/index.html\" rel=\"nofollow noopener\" target=\"_blank\">medical&nbsp;appointment reminders are allowed<\/a> under HIPAA privacy rules, which state:<\/p>\n<p><em>\u201cAppointment reminders are considered part of the treatment of an individual and, therefore, can be made without authorization.\u201d&nbsp;<\/em><\/p>\n<p class=\"style-warning\">When sending a HIPAA text message appointment reminder, it is <strong>best to avoid being too specific<\/strong>. Keep in mind that practice names can infer types of treatment or conditions. For example, \u201cOncology Clinic\u201d clearly indicates that the patient has cancer.<\/p>\n<p>Generic reminders include:<\/p>\n<ul>\n<li><strong>Appointment date and time<\/strong><\/li>\n<li><strong>Provider\u2019s first and last name<\/strong><\/li>\n<li><strong>Location of the appointment<\/strong><\/li>\n<\/ul><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\"> <label> Is your process for sending appointment reminders HIPAA compliant? <\/label> <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\"> <label> Summary of process for sending appointment reminders <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<div class=\"text-content\">\n<p class=\"style-danger\"><strong>Ensure your NPP (Notice of Privacy Practices) is updated<\/strong> and includes information about opting-in for appointment reminders by SMS and\/or email.<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"evaluate-identity-verification-procedure-upon-patient-arrival\">\n<h2>Evaluate identity verification procedure upon patient arrival<\/h2>\n<div class=\"text-content\">\n<p>In order to ensure HIPAA compliance, during check-in, a patient should <strong>verify their identity in the following ways,<\/strong>&nbsp;depending on the method of verification:<\/p>\n<h4>In-Person:<\/h4>\n<ul>\n<li>Photo ID<\/li>\n<li>Driver's License<\/li>\n<li>Passport<\/li>\n<\/ul>\n<h4>Mail:<\/h4>\n<ul>\n<li><strong>Signature validation:<\/strong> Compare the signature on the mailed request with the patient\u2019s signature on file in the medical record. Most patients will have signed having been offered the Notice of Privacy Practices (NPP)<\/li>\n<li>When possible, it is preferable to have the records mailed to the address on file for the patient.<\/li>\n<\/ul>\n<h4>Phone<\/h4>\n<ul>\n<li>Request full name and at least two other identifiers such as date of birth, address, emergency contact name, phone number, last 4 digits of their social security number.<\/li>\n<li>Request most recent date of service or invoice number for billing questions.<\/li>\n<li>If the request is not from the patient but by someone who may have appropriate authority to make a request such as another treatment provider, ask that the request be made in writing on letterhead.<\/li>\n<\/ul><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\"> <label> Is your identity verification procedure HIPAA compliant? <\/label> <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<div class=\"text-content\">\n<p class=\"style-success\">To ensure HIPAA compliance when verifying patient identity, and in general to make the process more efficient, it is recommended to use a third-party service provider, such as <a href=\"https:\/\/www.transunion.com\/product\/healthcare-patient-identity-verification\" rel=\"nofollow noopener\" target=\"_blank\">TransUnion<\/a>, to do it for you.&nbsp;<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"approval-checkin-procedures\">\n<h2>Approval: Check-in procedures<\/h2>\n<div class=\"approval-content\">\n<div class=\"header\">\n<div class=\"list-title\">\n    Will be submitted for approval:\n   <\/div>\n<\/p><\/div>\n<div class=\"approval-rule-subject-tasks-list\">\n<ul class=\"list\">\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Ensure assistance is provided for new patient form completion<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Ensure patient insurance is verified<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Ensure patients sign the Notice of Privacy Practices Acknowledgement<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Evaluate process for sending appointment reminders<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Evaluate identity verification procedure upon patient arrival<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"clinical-areas\">\n<h2>Clinical areas:<\/h2>\n<\/section>\n<section id=\"evaluate-if-staff-discuss-patient-information-in-clinical-areas\">\n<h2>Evaluate if staff discuss patient information in clinical areas<\/h2>\n<div class=\"text-content\">\n<p>Even in our world of digital interaction, word-of-mouth still plays a huge role.&nbsp;<\/p>\n<p>When it comes to sensitive patient information, a<strong> serious breach of HIPAA compliance can arise<\/strong> if staff in your medical institution are discussing private patient information in clinical areas.&nbsp;<\/p>\n<p><strong>Ensure that all staff are fully aware of the risks and are properly trained<\/strong> to know that discussing patient information in clinical areas is not acceptable.&nbsp;<\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\"> <label> Do staff discuss patient information in clinical areas? <\/label> <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"assess-if-phone-calls-are-made-mentioning-patient-information\">\n<h2>Assess if phone calls are made mentioning patient information<\/h2>\n<div class=\"text-content\">\n<p>Similar to in-person discussions amongst staff, <strong>phone calls also present a risk of a breach to the HIPAA privacy rule<\/strong>, and therefore need to be assessed to ensure staff members on phone calls are not disclosing private patient information.<\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\"> <label> Are phone calls made mentioning patient information? <\/label> <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"ensure-exam-room-doors-are-shut-during-patient-encounters\">\n<h2>Ensure exam room doors are shut during patient encounters<\/h2>\n<div class=\"text-content\">\n<p>To protect patient privacy, <strong>exam room doors must be shut during patient encounters.<\/strong><\/p>\n<p>This is a simple task that can be <strong>easily completed with sufficient training and security awareness<\/strong> by the medical staff.&nbsp;<\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\"> <label> Are all exam rooms shut during patient encounters? <\/label> <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"ensure-lab-and-xray-logs-are-covered-to-protect-phi\">\n<h2>Ensure lab and X-ray logs are covered to protect PHI<\/h2>\n<div class=\"image-content\">\n<figure> <a href=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/olhHwuX9ImvlZcBLn1hBbg.jpg\" alt=\"Ensure lab and X-ray logs are covered to protect PHI\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/olhHwuX9ImvlZcBLn1hBbg.jpg\"> <\/a><br \/>\n  <\/figure>\n<\/p><\/div>\n<div class=\"text-content\">\n<p>If<strong> lab and X-ray logs<\/strong> are not covered properly, they can <strong>display PHI, which could potentially result in a breach.&nbsp;<\/strong><\/p>\n<p>An important preventative measure that protects PHI and complies with HIPAA regulations, is to <strong>cover the logs when they are left unattended.&nbsp;<\/strong><\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\"> <label> Are lab and X-ray logs covered to protect PHI? <\/label> <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"ensure-no-phi-is-visible-in-clinical-workstations-while-unattended\">\n<h2>Ensure no PHI is visible in clinical workstations while unattended<\/h2>\n<div class=\"text-content\">\n<p>Just like with lab and X-ray logs, all <strong>clinical workstations must protect PHI while unattended.&nbsp;<\/strong><\/p>\n<p>Hard-copy files must be securely stored and computers locked.<\/p>\n<p>Any open screens displaying PHI while no staff are present <strong>breaks HIPAA regulations<\/strong> and presents a <strong>significant security risk.&nbsp;<\/strong><\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\"> <label> Is any PHI visible in clinical workstations while unattended? <\/label> <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"ensure-phi-shred-bins-are-emptied-and-not-overfilled\">\n<h2>Ensure PHI shred bins are emptied and not overfilled<\/h2>\n<div class=\"text-content\">\n<p>A final, easily overlooked step when conducting a privacy risk assessment in clinical areas is to <strong>ensure PHI shred bins are being emptied regularly.<\/strong><\/p>\n<p>A <strong>simple task<\/strong> that can prevent an <strong>easily avoidable<\/strong> privacy breach.&nbsp;<\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\"> <label> Are PHI shred bins emptied before being overfilled? <\/label> <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"approval-clinical-areas\">\n<h2>Approval: Clinical areas<\/h2>\n<div class=\"approval-content\">\n<div class=\"header\">\n<div class=\"list-title\">\n    Will be submitted for approval:\n   <\/div>\n<\/p><\/div>\n<div class=\"approval-rule-subject-tasks-list\">\n<ul class=\"list\">\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Ensure PHI shred bins are emptied and not overfilled<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Ensure no PHI is visible in clinical workstations while unattended<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Ensure lab and X-ray logs are covered to protect PHI<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Ensure exam room doors are shut during patient encounters<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Assess if phone calls are made mentioning patient information<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Evaluate if staff discuss patient information in clinical areas<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"medical-records\">\n<h2>Medical records:<\/h2>\n<\/section>\n<section id=\"verify-only-appropriate-staff-can-access-medical-records\">\n<h2>Verify only appropriate staff can access medical records<\/h2>\n<div class=\"image-content\">\n<figure> <a href=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/shlyHirw_JmxgMQaTJBNmg.jpg\" alt=\"Verify only appropriate staff can access medical records\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/shlyHirw_JmxgMQaTJBNmg.jpg\"> <\/a><br \/>\n  <\/figure>\n<\/p><\/div>\n<div class=\"text-content\">\n<p>Medical records are, of course, the <strong>gold mine of private patient information<\/strong>. They must be securely stored and only staff with the appropriate security clearance should have access to them.&nbsp;<\/p>\n<p>Evaluate which staff members can access patients medical records and <strong>verify that they all have the appropriate clearance.&nbsp;<\/strong><\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\"> <label> Can only appropriate staff access medical records? <\/label> <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\"> <label> Notes on staff accessibility of medical records <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"assess-physical-security-of-medical-records\">\n<h2>Assess physical security of medical records<\/h2>\n<div class=\"text-content\">\n<p>Assess the <strong>physical storage<\/strong> of all medical records and ensure they are HIPAA compliant.<\/p>\n<p>The room they are in should be<strong> secured, monitored, and only accessible by qualified staff members.&nbsp;<\/strong><\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\"> <label> Are all physical medical records stored securely? <\/label> <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"ensure-patient-authorization-is-received-before-release-of-phi\">\n<h2>Ensure patient authorization is received before release of PHI<\/h2>\n<div class=\"text-content\">\n<p>This is an incredibly <strong>important requirement of the HIPAA Privacy Rule.<\/strong><\/p>\n<p>Before PHI is released (e.g. to a business associate), you must receive authorization from the patient, in the form of a <strong>signed HIPAA release\/authorization form.<\/strong><\/p>\n<p>In order for an release form to be legally valid, it must inform the patient of the following:<\/p>\n<ul>\n<li>The patient has the right to revoke an authorization at any time.<\/li>\n<li>Authorization forms are completely voluntary.<\/li>\n<li>There is a chance that the person you are choosing to trust with your information might disclose it to someone else.<\/li>\n<\/ul>\n<p class=\"style-warning\">HIPAA\u2019s privacy rule demands that, in order for authorization to be considered valid, the release form must <strong>A) provide specific legal information about HIPAA\u2019s Privacy Rule, <\/strong>and<strong> B) detail the nature of information being disclosed, the purpose, to who, and for how long.<\/strong><\/p>\n<p class=\"style-info\">Have more questions about how and when you need to use the HIPAA release form? <a href=\"https:\/\/www.hipaajournal.com\/hipaa-release-form\/\" rel=\"nofollow noopener\" target=\"_blank\">Read through this article<\/a> for a full breakdown.<\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\"> <label> Is a HIPAA authorization form completed for each patient before releasing their PHI? <\/label> <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"ensure-authorizations-are-filed-in-patients-medical-record\">\n<h2>Ensure authorizations are filed in patients medical record<\/h2>\n<div class=\"text-content\">\n<p>In addition to ensuring an authorization form is completed for each patient prior to the release of their PHI, the next step is to ensure <strong>all of the forms are securely filed<\/strong> in the patients medical record.&nbsp;<\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\"> <label> Are authorization forms filed in patient medical records? <\/label> <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"ensure-phi-can-be-destroyed-after-the-retention-period\">\n<h2>Ensure PHI can be destroyed after the retention period<\/h2>\n<div class=\"text-content\">\n<p>According to HIPAA, medical records must be kept for either:<\/p>\n<ul>\n<li><strong>Six years from their creation; or<\/strong><\/li>\n<li><strong>Six years from their last use<\/strong><\/li>\n<\/ul>\n<p class=\"style-info\">Most states have data retention laws, too. If the state\u2019s law specifies a shorter retention period than HIPAA, the HIPAA regulation prevails. If the state requires a longer retention period, then providers must adhere to the state law and destroy the records according to the state\u2019s schedule.<\/p>\n<p>Here are some suggestions from HIPAA for the destruction of medical records:<\/p>\n<ul>\n<li>PHI in paper records may be shredded, burned, pulped, or pulverized so the PHI is unreadable, indecipherable, and may not be reconstructed.<\/li>\n<li>PHI in electronic media may be cleared by overwriting it, purged by degaussing or exposing the media to a magnetic field, or otherwise destroyed by disintegration, pulverization, melting, incinerating, or shredding.<\/li>\n<\/ul>\n<p class=\"style-warning\">They also state that it\u2019s acceptable to maintain PHI in opaque bags in a secured area while it waits for destruction. The key is that any medical records you get rid of must be destroyed in a manner that prevents them from being reconstructed or otherwise accessed.<\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\"> <label> Can PHI be destroyed after the retention period? <\/label> <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"approval-medical-records\">\n<h2>Approval: Medical records<\/h2>\n<div class=\"approval-content\">\n<div class=\"header\">\n<div class=\"list-title\">\n    Will be submitted for approval:\n   <\/div>\n<\/p><\/div>\n<div class=\"approval-rule-subject-tasks-list\">\n<ul class=\"list\">\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Verify only appropriate staff can access medical records<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Assess physical security of medical records<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Ensure patient authorization is received before release of PHI<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Ensure authorizations are filed in patients medical record<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Ensure PHI can be destroyed after the retention period<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"general-security\">\n<h2>General security:<\/h2>\n<\/section>\n<section id=\"ensure-computer-monitors-are-positioned-appropriately\">\n<h2>Ensure computer monitors are positioned appropriately<\/h2>\n<div class=\"image-content\">\n<figure> <a href=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/v7mL3llm_7rdAS42lidPYA.jpg\" alt=\"Ensure computer monitors are positioned appropriately\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/v7mL3llm_7rdAS42lidPYA.jpg\"> <\/a><br \/>\n  <\/figure>\n<\/p><\/div>\n<div class=\"text-content\">\n<p>It may seem obvious that computer monitors need to be positioned appropriately, but a simple mistake could lead to a breach.&nbsp;<\/p>\n<p>Check all workstations and <strong>confirm that each monitor is positioned so that they cannot be viewed by patients<\/strong> and other individuals that do not have the appropriate clearance.<\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\"> <label> Are computer monitors positioned appropriately? <\/label> <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"ensure-unattended-computers-are-properly-secured\">\n<h2>Ensure unattended computers are properly secured<\/h2>\n<div class=\"text-content\">\n<p>All unattended computers must be<strong> properly secured, both physically and digitally.&nbsp;<\/strong><\/p>\n<p>This means that they need to be<strong> secured to the desk they are on and the screen needs to lock automatically<\/strong> when left unattended.&nbsp;<\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\"> <label> Are all unattended computers properly secured? <\/label> <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"ensure-paper-records-are-stored-appropriately\">\n<h2>Ensure paper records are stored appropriately<\/h2>\n<div class=\"text-content\">\n<p>Although it is estimated that <a href=\"https:\/\/securerecordssolutions.com\/how-does-the-hipaa-privacy-rule-apply-to-paper-medical-records\/\" rel=\"nofollow noopener\" target=\"_blank\">95% of practitioners will have&nbsp;started <\/a><a href=\"https:\/\/securerecordssolutions.com\/how-does-the-hipaa-privacy-rule-apply-to-paper-medical-records\/\" rel=\"nofollow noopener\" target=\"_blank\">the conversion to electronic records<\/a>, many healthcare providers have both hard copy and electronic records.<\/p>\n<p>To <strong>best protect your records<\/strong>, your&nbsp;<a href=\"https:\/\/storage.tab.com\/products\/high-density-mobile-storage-systems\/tab-trac-ultra-secure\/\" rel=\"nofollow noopener\" target=\"_blank\">file room should be secured<\/a>&nbsp;by a<strong> monitoring or card entry system<\/strong>. At a minimum, it should be <strong>supervise<\/strong>d during working hours.<\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\"> <label> Are paper records stored and monitored appropriately? <\/label> <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<div class=\"text-content\">\n<p class=\"style-info\">Larger organizations with sufficient resources should appoint a risk manager responsible for protecting the&nbsp;<a href=\"https:\/\/www.tab.com\/products_services\/services-consulting-software\/records-management-service-rmaas\/\" rel=\"nofollow noopener\" target=\"_blank\">records storage site<\/a>.&nbsp;<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"approval-general-security\">\n<h2>Approval: General security<\/h2>\n<div class=\"approval-content\">\n<div class=\"header\">\n<div class=\"list-title\">\n    Will be submitted for approval:\n   <\/div>\n<\/p><\/div>\n<div class=\"approval-rule-subject-tasks-list\">\n<ul class=\"list\">\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Ensure computer monitors are positioned appropriately<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Ensure unattended computers are properly secured<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Ensure paper records are stored appropriately<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"personnel-policies\">\n<h2>Personnel policies:<\/h2>\n<\/section>\n<section id=\"ensure-hipaa-privacy-policies-are-in-the-employee-handbook\">\n<h2>Ensure HIPAA privacy policies are in the employee handbook<\/h2>\n<div class=\"image-content\">\n<figure> <a href=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/h4Zyr4-F6InUqEkvJJxA_A.jpg\" alt=\"Ensure HIPAA privacy policies are in the employee handbook\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/h4Zyr4-F6InUqEkvJJxA_A.jpg\"> <\/a><br \/>\n  <\/figure>\n<\/p><\/div>\n<div class=\"text-content\">\n<p>Your medical institution should have an <strong>employee handbook<\/strong> that contains all of the information regarding the HIPAA privacy policies and how they apply to your organization.&nbsp;<\/p>\n<p>This handbook should be<strong> easily accessible by all staff members.<\/strong><\/p>\n<p class=\"style-danger\">Also ensure that all privacy policies are <strong>up to date.<\/strong><\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\"> <label> Are HIPAA privacy policies in your employee handbook? <\/label> <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\"> <label> Are all privacy policies up to date? <\/label> <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"ensure-employees-receive-privacy-training\">\n<h2>Ensure employees receive privacy training<\/h2>\n<div class=\"text-content\">\n<p>Employees need to be <strong>trained to understand HIPAA regulations regarding patient privacy.<\/strong><\/p>\n<p>Any kind of security breach is <strong>more likely to be caused my human error than anything else<\/strong>, and so with a comprehensive training program, the risk of getting in trouble is minimized.&nbsp;<\/p>\n<p class=\"style-info\"><a href=\"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/training\/index.html\" rel=\"nofollow noopener\" target=\"_blank\">Visit the HHS.gov website<\/a> for training materials.<\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\"> <label> Have all employees received the appropriate level of privacy training? <\/label> <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\"> <label> Summary of employee training plan\/schedule <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"ensure-training-is-documented\">\n<h2>Ensure training is documented<\/h2>\n<div class=\"text-content\">\n<p>Ensure that <strong>all training is documented<\/strong>. This is incredibly important in the event of an<strong> external audit or investigation.<\/strong><\/p>\n<p class=\"style-blockquote\"><em>HIPAA requires that training be documented.&nbsp; It doesn\u2019t say much else on how training must be documented.&nbsp; In the event of an OCR investigation or audit, it is best to be able to produce the content of the training as well as when it was administered, to whom, and how frequently.&nbsp; You should also keep track of who completed it successfully and what successful completion entailed. - <\/em><a href=\"https:\/\/teachprivacy.com\/hipaa-training-requirements\/#:~:text=HIPAA%20requires%20that%20training%20be,to%20whom%2C%20and%20how%20frequently.\" rel=\"nofollow noopener\" target=\"_blank\">TeachPrivacy<\/a><\/p>\n<p>Provide a brief summary of your HIPAA Privacy Rule training program in the form field below.<\/p>\n<p>You can also <strong>attach and\/or link to training documentation<\/strong> below.<\/p>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\"> <label> Summary of HIPAA Privacy Rule training <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<div class=\"file-field-content form-field-content\">\n<div class=\"form-group\"> <label> Training documentation (file) <\/label> <\/p>\n<div class=\"file-container\"> <button type=\"button\" disabled class=\"btn btn-default\"> <i class=\"fa fa-upload btn-icon\"><\/i> File will be uploaded here <\/button>\n   <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"approval-personnel-policies\">\n<h2>Approval: Personnel policies<\/h2>\n<div class=\"approval-content\">\n<div class=\"header\">\n<div class=\"list-title\">\n    Will be submitted for approval:\n   <\/div>\n<\/p><\/div>\n<div class=\"approval-rule-subject-tasks-list\">\n<ul class=\"list\">\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Ensure HIPAA privacy policies are in the employee handbook<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Ensure employees receive privacy training<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Ensure training is documented<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"final-evaluation\">\n<h2>Final evaluation:<\/h2>\n<\/section>\n<section id=\"summarize-the-privacy-risk-analysis\">\n<h2>Summarize the privacy risk analysis<\/h2>\n<div class=\"text-content\">\n<p>In the form fields below, provide a<strong> summary of the privacy risk analysis<\/strong>, as well as a concise list of the<strong> areas that need to be addressed<\/strong>, and <strong>action items<\/strong>.&nbsp;<\/p>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\"> <label> Summary of the privacy risk analysis <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\"> <label> Areas that need to be addressed <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\"> <label> Specific action items <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"approval-general-risk-analysis-completed\">\n<h2>Approval: General risk analysis completed<\/h2>\n<div class=\"approval-content\">\n<div class=\"header\">\n<div class=\"list-title\">\n    Will be submitted for approval:\n   <\/div>\n<\/p><\/div>\n<div class=\"approval-rule-subject-tasks-list\">\n<ul class=\"list\">\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Summarize the privacy risk analysis<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"sources\">\n<h2>Sources:<\/h2>\n<div class=\"text-content\">\n<ul>\n<li><a href=\"https:\/\/www.hhs.gov\/\" rel=\"nofollow noopener\" target=\"_blank\">HHS<\/a> - <a href=\"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/security\/guidance\/guidance-risk-analysis\/index.html\" rel=\"nofollow noopener\" target=\"_blank\">Guidance on Risk Analysis<\/a><\/li>\n<li><a href=\"https:\/\/www.hhs.gov\/\" rel=\"nofollow noopener\" target=\"_blank\">HHS<\/a> - <a href=\"https:\/\/www.hhs.gov\/hipaa\/for-individuals\/notice-privacy-practices\/index.html\" rel=\"nofollow noopener\" target=\"_blank\">Notice of Privacy Practices<\/a><\/li>\n<li><a href=\"https:\/\/www.hipaajournal.com\/\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Journal<\/a> - <a href=\"https:\/\/www.hipaajournal.com\/hipaa-release-form\/\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Release Form<\/a><\/li>\n<li><a href=\"https:\/\/www.hipaahq.com\/\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA HQ<\/a> - <a href=\"https:\/\/www.hipaahq.com\/hipaa-forms-explained-privacy-and-authorization\/\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Forms Explained: Privacy and Authorization<\/a><\/li>\n<li><a href=\"https:\/\/www.gilmoreservices.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Gilmore Services<\/a> - <a href=\"https:\/\/www.gilmoreservices.com\/blog\/medical-record-destruction-hipaa-mandated\" rel=\"nofollow noopener\" target=\"_blank\">Medical Record Destruction, It's HIPAA Mandated<\/a><\/li>\n<li><a href=\"https:\/\/www.linkedin.com\/company\/tab\/\" rel=\"nofollow noopener\" target=\"_blank\">TAB<\/a> - <a href=\"https:\/\/recordsmanagement.tab.com\/healthcare-patient-chart-services\/how-to-safeguard-paper-medical-records\/\" rel=\"nofollow noopener\" target=\"_blank\">How to Safeguard Paper Medical Records<\/a><\/li>\n<li><a href=\"https:\/\/public-library.safetyculture.io\/\" rel=\"nofollow noopener\" target=\"_blank\">SafetyCulture<\/a> - <a href=\"https:\/\/public-library.safetyculture.io\/products\/hipaa-general-privacy-risk-analysis\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA General Privacy Risk Analysis Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.iu.edu\/\" rel=\"nofollow noopener\" target=\"_blank\">Indiana University<\/a> - <a href=\"https:\/\/policies.iu.edu\/policies\/hipaa-p11-retention-destruction-protected-health-information\/\" rel=\"nofollow noopener\" target=\"_blank\">Retention &amp; Destruction of Protected Health Information<\/a><\/li>\n<li><a href=\"https:\/\/www.bridgepatientportal.com\/blog\/author\/Josh-Orueta\/\" rel=\"nofollow noopener\" target=\"_blank\">Josh Orueta<\/a> - <a href=\"https:\/\/www.bridgepatientportal.com\/blog\/how-to-send-automated-medical-appointment-reminders-without-jeopardizing-patients-data-security\/#:~:text=According%20to%20the%20U.S.%20Department,that%20providers%20don't%20need\" rel=\"nofollow noopener\" target=\"_blank\">How to Send Automated Medical Appointment Reminders Without Jeopardizing Patients\u2019 Data Security<\/a><\/li>\n<\/ul><\/div>\n<\/section>\n<section id=\"related-checklists\">\n<h2>Related checklists:<\/h2>\n<div class=\"text-content\">\n<ul>\n<li><a href=\"https:\/\/www.process.st\/templates\/hipaa-compliance-checklist-for-hr\/\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Compliance Checklist for HR<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/hipaa-omnibus-rule-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Omnibus Rule Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/hipaa-compliance-checklist-for-hr\/\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Security Breach Reporting Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/hipaa-business-associate-agreement-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Business Associate Agreement Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/hipaa-data-backup-plan-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Data Backup Plan Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/hipaa-compliance-checklist-for-hr\/\" rel=\"nofollow noopener\" target=\"_blank\">Patient Intake Checklist for a Medical Clinic<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/hipaa-compliance-checklist-for-hr\/\" rel=\"nofollow noopener\" target=\"_blank\">Patient Intake Checklist for a Dental Clinic<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/hipaa-compliance-checklist-for-hr\/\" rel=\"nofollow noopener\" target=\"_blank\">Patient Satisfaction Survey Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/hospital-housekeeping-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">Hospital Housekeeping Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/terminal-room-cleaning-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">Terminal Room Cleaning Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/hospital-safety-inspection-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">Hospital Safety Inspection Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/general-infection-control-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">General Infection Control Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/patient-satisfaction-survey-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">Patient Satisfaction Survey Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/home-visit-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">Home Visit Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/mental-health-risk-assessment-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">Mental Health Risk Assessment Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/who-surgical-safety-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">WHO Surgical Safety Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/hipaa-compliance-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Compliance Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-isolation-area-management\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Isolation Area Management<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-disinfection-procedures-for-covid-19-isolation-ward-area\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Disinfection Procedures for COVID-19 Isolation Ward Area<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-lung-transplantation-pre-transplantation-assessment\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Lung Transplantation Pre-Transplantation Assessment<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-nursing-care-during-treatment-alss\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Nursing Care During Treatment (ALSS)<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-protocol-for-donning-and-removing-ppe\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Protocol for Donning and Removing PPE<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-staff-management-workflow-and-health\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Staff Management (Workflow and Health)<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-daily-management-and-monitoring-of-ecmo-audit\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Daily Management and Monitoring of ECMO Audit<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-digital-support-for-epidemic-prevention-and-control\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Digital Support for Epidemic Prevention and Control<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-discharge-standards-and-follow-up-plan-for-covid-19-patients\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Discharge Standards and Follow-up Plan for COVID-19 Patients<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-disinfection-of-covid-19-related-reusable-medical-devices\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Disinfection of COVID-19 Related Reusable Medical Devices<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-disinfection-procedures-for-infectious-fabrics-of-suspected-or-confirmed-patients\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Disinfection Procedures for Infectious Fabrics of Suspected or Confirmed Patients<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-disposal-procedures-for-covid-19-related-medical-waste\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Disposal Procedures for COVID-19 Related Medical Waste<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-disposal-procedures-for-spills-of-covid-19-patient-blood-fluids\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Disposal Procedures for Spills of COVID-19 Patient Blood\/Fluids<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-procedures-for-handling-bodies-of-deceased-suspected-or-confirmed-patients\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Procedures for Handling Bodies of Deceased Suspected or Confirmed Patients<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-procedures-for-taking-remedial-actions-against-occupational-exposure-to-covid-19\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Procedures for Taking Remedial Actions against Occupational Exposure to COVID-19<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-surgical-operations-for-suspected-or-confirmed-patients\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Surgical Operations for Suspected or Confirmed Patients<\/a><\/li>\n<\/ul><\/div>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>Introduction: The requirement for covered entities to conduct a HIPAA risk assessment was introduced in 2003 with the original HIPAA Privacy Rule. Conducting periodic risk assessments is not only required by law, but will also help you avoid potential violations that can be incredibly costly. \"More recently, the majority of fines have been under the [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":24488,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"ep_exclude_from_search":false,"cover_icon_emoji":"","cover_icon_url":"","tasks_count":"39","template_description":"Run this checklist to conduct a comprehensive evaluation of your compliance with the HIPAA Privacy Rule","template_id":"qVgJCIiDL7pA8nEtPeVAEw","task_0":"Introduction:","task_slug_0":"introduction","task_1":"Enter basic details","task_slug_1":"enter-basic-details","task_2":"Check-in procedures:","task_slug_2":"checkin-procedures","task_3":"Ensure assistance is provided for new patient form completion","task_slug_3":"ensure-assistance-is-provided-for-new-patient-form-completion","task_4":"Ensure patient insurance is verified","task_slug_4":"ensure-patient-insurance-is-verified","task_5":"Ensure patients sign the Notice of Privacy Practices Acknowledgement","task_slug_5":"ensure-patients-sign-the-notice-of-privacy-practices-acknowledgement","task_6":"Evaluate process for sending appointment reminders","task_slug_6":"evaluate-process-for-sending-appointment-reminders","task_7":"Evaluate identity verification procedure upon patient arrival","task_slug_7":"evaluate-identity-verification-procedure-upon-patient-arrival","task_8":"Approval: Check-in procedures","task_slug_8":"approval-checkin-procedures","task_9":"Clinical areas:","task_slug_9":"clinical-areas","task_10":"Evaluate if staff discuss patient information in clinical areas","task_slug_10":"evaluate-if-staff-discuss-patient-information-in-clinical-areas","task_11":"Assess if phone calls are made mentioning patient information","task_slug_11":"assess-if-phone-calls-are-made-mentioning-patient-information","task_12":"Ensure exam room doors are shut during patient encounters","task_slug_12":"ensure-exam-room-doors-are-shut-during-patient-encounters","task_13":"Ensure lab and X-ray logs are covered to protect PHI","task_slug_13":"ensure-lab-and-xray-logs-are-covered-to-protect-phi","task_14":"Ensure no PHI is visible in clinical workstations while unattended","task_slug_14":"ensure-no-phi-is-visible-in-clinical-workstations-while-unattended","task_15":"Ensure PHI shred bins are emptied and not overfilled","task_slug_15":"ensure-phi-shred-bins-are-emptied-and-not-overfilled","task_16":"Approval: Clinical areas","task_slug_16":"approval-clinical-areas","task_17":"Medical records:","task_slug_17":"medical-records","task_18":"Verify only appropriate staff can access medical records","task_slug_18":"verify-only-appropriate-staff-can-access-medical-records","task_19":"Assess physical security of medical records","task_slug_19":"assess-physical-security-of-medical-records","task_20":"Ensure patient authorization is received before release of PHI","task_slug_20":"ensure-patient-authorization-is-received-before-release-of-phi","task_21":"Ensure authorizations are filed in patients medical record","task_slug_21":"ensure-authorizations-are-filed-in-patients-medical-record","task_22":"Ensure PHI can be destroyed after the retention period","task_slug_22":"ensure-phi-can-be-destroyed-after-the-retention-period","task_23":"Approval: Medical records","task_slug_23":"approval-medical-records","task_24":"General security:","task_slug_24":"general-security","task_25":"Ensure computer monitors are positioned appropriately","task_slug_25":"ensure-computer-monitors-are-positioned-appropriately","task_26":"Ensure unattended computers are properly secured","task_slug_26":"ensure-unattended-computers-are-properly-secured","task_27":"Ensure paper records are stored appropriately","task_slug_27":"ensure-paper-records-are-stored-appropriately","task_28":"Approval: General security","task_slug_28":"approval-general-security","task_29":"Personnel policies:","task_slug_29":"personnel-policies","task_30":"Ensure HIPAA privacy policies are in the employee handbook","task_slug_30":"ensure-hipaa-privacy-policies-are-in-the-employee-handbook","task_31":"Ensure employees receive privacy training","task_slug_31":"ensure-employees-receive-privacy-training","task_32":"Ensure training is documented","task_slug_32":"ensure-training-is-documented","task_33":"Approval: Personnel policies","task_slug_33":"approval-personnel-policies","task_34":"Final evaluation:","task_slug_34":"final-evaluation","task_35":"Summarize the privacy risk analysis","task_slug_35":"summarize-the-privacy-risk-analysis","task_36":"Approval: General risk analysis completed","task_slug_36":"approval-general-risk-analysis-completed","task_37":"Sources:","task_slug_37":"sources","task_38":"Related checklists:","task_slug_38":"related-checklists","task_39":"","task_slug_39":"","task_40":"","task_slug_40":"","task_41":"","task_slug_41":"","task_42":"","task_slug_42":"","task_43":"","task_slug_43":"","task_44":"","task_slug_44":"","task_45":"","task_slug_45":"","task_46":"","task_slug_46":"","task_47":"","task_slug_47":"","task_48":"","task_slug_48":"","task_49":"","task_slug_49":"","task_50":"","task_slug_50":"","task_51":"","task_slug_51":"","task_52":"","task_slug_52":"","task_53":"","task_slug_53":"","task_54":"","task_slug_54":"","task_55":"","task_slug_55":"","task_56":"","task_slug_56":"","task_57":"","task_slug_57":"","task_58":"","task_slug_58":"","task_59":"","task_slug_59":"","task_60":"","task_slug_60":"","task_61":"","task_slug_61":"","task_62":"","task_slug_62":"","task_63":"","task_slug_63":"","task_64":"","task_slug_64":"","task_65":"","task_slug_65":"","task_66":"","task_slug_66":"","task_67":"","task_slug_67":"","task_68":"","task_slug_68":"","task_69":"","task_slug_69":"","task_70":"","task_slug_70":"","task_71":"","task_slug_71":"","task_72":"","task_slug_72":"","task_73":"","task_slug_73":"","task_74":"","task_slug_74":"","task_75":"","task_slug_75":"","task_76":"","task_slug_76":"","task_77":"","task_slug_77":"","task_78":"","task_slug_78":"","task_79":"","task_slug_79":"","task_80":"","task_slug_80":"","task_81":"","task_slug_81":"","task_82":"","task_slug_82":"","task_83":"","task_slug_83":"","task_84":"","task_slug_84":"","task_85":"","task_slug_85":"","task_86":"","task_slug_86":"","task_87":"","task_slug_87":"","task_88":"","task_slug_88":"","task_89":"","task_slug_89":"","task_90":"","task_slug_90":"","task_91":"","task_slug_91":"","task_92":"","task_slug_92":"","task_93":"","task_slug_93":"","task_94":"","task_slug_94":"","task_95":"","task_slug_95":"","task_96":"","task_slug_96":"","task_97":"","task_slug_97":"","task_98":"","task_slug_98":"","task_99":"","task_slug_99":"","footnotes":""},"categories":[29,7],"tags":[],"class_list":["post-24487","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-healthcare","category-miscellaneous"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts\/24487","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/comments?post=24487"}],"version-history":[{"count":0,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts\/24487\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/media\/24488"}],"wp:attachment":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/media?parent=24487"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/categories?post=24487"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/tags?post=24487"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}