{"id":24512,"date":"2020-09-22T07:03:32","date_gmt":"2020-09-22T07:03:32","guid":{"rendered":"https:\/\/www.process.st\/templates\/hipaa-omnibus-rule-checklist\/"},"modified":"2024-02-29T02:55:37","modified_gmt":"2024-02-29T02:55:37","slug":"hipaa-omnibus-rule-checklist","status":"publish","type":"post","link":"https:\/\/www.process.st\/templates\/hipaa-omnibus-rule-checklist\/","title":{"rendered":"HIPAA Omnibus Rule Checklist"},"content":{"rendered":"<section id=\"introduction\">\n<h2>Introduction:<\/h2>\n<div class=\"image-content\">\n<figure> <a href=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/hzK8usJq7sYYMwB-WF5Gxw.png\" alt=\"Introduction:\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/hzK8usJq7sYYMwB-WF5Gxw.png\"> <\/a><br \/>\n  <\/figure>\n<\/p><\/div>\n<div class=\"text-content\">\n<p>The Omnibus Rule was introduced in 2013 as a way to<strong> amend the HIPAA privacy and security rules requirements<\/strong>, including <strong>changes to the obligations of business associates<\/strong> regarding the management of PHI.<\/p>\n<p>The rule merges the following four separate rule makings:<\/p>\n<ul>\n<li>Amendments to HIPAA Privacy and Security rules requirements<\/li>\n<li>HIPAA and HIPAA HITECH under one rule now<\/li>\n<li>Further requirements for data breach notifications and penalty enforcement<\/li>\n<li>Approving the regulations in regards to the HITECH Act\u2019s breach notification rule<\/li>\n<\/ul>\n<p>The Omnibus rule includes regulations that will:<\/p>\n<ul>\n<li>Manage the use of patient information in marketing<\/li>\n<li>Includes a provision that requires healthcare providers to report data breaches that are deemed not harmful<\/li>\n<li>Makes certain that business associates and subcontractors are liable for their own breaches and requires Business Associates to comply with HIPAA<\/li>\n<\/ul>\n<p>Although all healthcare institutions had to make changes and adhere to the Omnibus Rule when it was implemented, this checklist provides you with an <strong>easy way to evaluate compliance on a periodic basis<\/strong>.<\/p>\n<h4>A little info about Process Street<\/h4>\n<p>Process Street is&nbsp;<strong>superpowered checklists<\/strong>. By using our software to document your processes, you are instantly creating an actionable workflow in which tasks can be assigned to team members, automated, and monitored in real-time to ensure they are being executed as intended, each and every time.<\/p>\n<p>The point is to&nbsp;<strong>minimize human error, increase accountability<\/strong>, and&nbsp;<strong>provide employees with all of the tools and information necessary<\/strong>&nbsp;to complete their tasks as effectively as possible.<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"enter-basic-details\">\n<h2>Enter basic details<\/h2>\n<div class=\"text-content\">\n<p>First, enter some <strong>basic details regarding your organization.<\/strong><\/p>\n<\/p><\/div>\n<div class=\"text-field-content form-field-content\">\n<div class=\"form-group\"> <label> Company Name <\/label><br \/>\n   <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\">\n  <\/div>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\"> <label> Company Address <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"team-management\">\n<h2>Team management:<\/h2>\n<\/section>\n<section id=\"designate-a-privacy-and-security-official\">\n<h2>Designate a privacy and security official<\/h2>\n<div class=\"text-content\">\n<p>In order to properly evaluate your compliance with the HIPAA Omnibus Rule, you <strong>must designate a privacy and security official<\/strong> to lead and manage the effort.<\/p>\n<p><strong>Enter their contact details<\/strong> in the form fields below.<\/p>\n<\/p><\/div>\n<div class=\"text-field-content form-field-content\">\n<div class=\"form-group\"> <label> Privacy Official - Name <\/label><br \/>\n   <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\">\n  <\/div>\n<\/p><\/div>\n<div class=\"text-content\">\n<hr>\n<\/p><\/div>\n<div class=\"text-field-content form-field-content\">\n<div class=\"form-group\"> <label> Security Official - Name <\/label><br \/>\n   <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\">\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"amending-documentation\">\n<h2>Amending documentation:<\/h2>\n<\/section>\n<section id=\"update-business-associate-agreements-baas\">\n<h2>Update Business Associate Agreements (BAAs)<\/h2>\n<div class=\"text-content\">\n<p>In short, the Omnibus Rule means that <strong>Business Associates (BA's)<\/strong>&nbsp;are now&nbsp;<strong>directly liable<\/strong>&nbsp;for any non-compliance and any fines associated with HIPAA non-compliance.<\/p>\n<p>For example, the following rules are enforced:<\/p>\n<ul>\n<li>Business associate agreements (BAA's) and policies and procedures must address the prohibition on the sale of patients' PHI without permission.<\/li>\n<li>Covered entities' business associate agreements and policies and procedures must address the expanded rights of individuals to restrict disclosures of PHI.<\/li>\n<\/ul>\n<p>All of your <strong>BAA's must be updated <\/strong>to reflect these new changes.&nbsp;<\/p>\n<p class=\"style-warning\">The Omnibus Rule also <strong>changed the definition of a BA.<\/strong> <a href=\"http:\/\/www.bricker.com\/documents\/publications\/Business%20Associates%20and%20Business%20Associate%20Agreements.pdf\" rel=\"nofollow noopener\" target=\"_blank\">Read through this document<\/a> to see exactly what changed.<\/p>\n<p>You can <strong>attach and\/or link to your updated BAA's<\/strong> below.&nbsp;<\/p>\n<\/p><\/div>\n<div class=\"file-field-content form-field-content\">\n<div class=\"form-group\"> <label> Updated BAA's (file) <\/label> <\/p>\n<div class=\"file-container\"> <button type=\"button\" disabled class=\"btn btn-default\"> <i class=\"fa fa-upload btn-icon\"><\/i> File will be uploaded here <\/button>\n   <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"update-notice-of-privacy-practices-npps\">\n<h2>Update Notice of Privacy Practices (NPPs)<\/h2>\n<div class=\"text-content\">\n<p>In addition to BAA's, you also <strong>need to update your Notice of Privacy Practices<\/strong> to reflect new regulations implemented by the Omnibus Rule.&nbsp;<\/p>\n<p class=\"style-blockquote\"><em>Covered entities' Notice of Privacy Practices forms need to inform patients that they will be notified if their PHI is subject to a breach. NPP's must also inform individuals that a covered entity may contact them to raise funds, and the individual has a right to opt out of receiving such communications. - <\/em><a href=\"https:\/\/twitter.com\/mollygamblehr\" rel=\"nofollow noopener\" target=\"_blank\">Molly Gamble<\/a>, <a href=\"https:\/\/www.beckershospitalreview.com\/legal-regulatory-issues\/15-things-to-know-about-the-hipaa-omnibus-final-rule-before-sept-23.html\" rel=\"nofollow noopener\" target=\"_blank\">Becker's Hospital Review<\/a><\/p>\n<p>The changes that need to be made to NPPs can be summarized as:<\/p>\n<ul>\n<li>The Omnibus Rule requires that the health plan NPP state that use and disclosure of PHI for marketing and use and disclosure that constitute a sale of PHI require authorization.<\/li>\n<li>The NPP must include a statement that other uses and disclosures not described in the NPP will be made only with authorization.<\/li>\n<li>The NPP must state that an individual has a right to or will receive notifications of breaches of unsecured PHI.<\/li>\n<li>The NPP must state that genetic information cannot be used or disclosed for underwriting purposes.<\/li>\n<\/ul>\n<p>You can <strong>attach and\/or link to your updated NPP<\/strong> below.<\/p>\n<\/p><\/div>\n<div class=\"file-field-content form-field-content\">\n<div class=\"form-group\"> <label> Updated NPP (file) <\/label> <\/p>\n<div class=\"file-container\"> <button type=\"button\" disabled class=\"btn btn-default\"> <i class=\"fa fa-upload btn-icon\"><\/i> File will be uploaded here <\/button>\n   <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"update-breach-notification-compliance-plan\">\n<h2>Update breach notification compliance plan<\/h2>\n<div class=\"text-content\">\n<p class=\"style-blockquote\"><em>The Omnibus Rule amends the definition of breach to clarify that the impermissible acquisition, access, use, or disclosure of PHI is presumed to be a breach and breach notification is necessary unless a covered entity or business associate can demonstrate, through a documented risk assessment, that there is a low probability that the PHI has been compromised.<\/em><\/p>\n<p>The Omnibus Rule identifies<strong> four factors that must be considered<\/strong> in a risk assessment:<\/p>\n<ul>\n<li>The nature and extent of the PHI involved;<\/li>\n<li>The unauthorized person who used the PHI or to whom the disclosure was made;<\/li>\n<li>Whether the PHI actually was acquired or viewed; and<\/li>\n<li>The extent to which the risk to the PHI has been mitigated.<\/li>\n<\/ul>\n<p><strong>Update your breach notification compliance plan<\/strong> to reflect the new changes.&nbsp;<\/p>\n<p>You can <strong>attach and\/or link to<\/strong> your updated plan below.<\/p>\n<hr>\n<p class=\"style-success\">Process Street has built a HIPAA Security Breach Reporting Checklist that you can run immediately if you are facing a breach.&nbsp;<\/p>\n<p class=\"style-info\"><a href=\"https:\/\/www.dwt.com\/insights\/2013\/01\/new-omnibus-rule-released-hipaa-puts-on-more-weigh#:~:text=The%20Omnibus%20Rule%20amends%20the,that%20there%20is%20a%20low\" rel=\"nofollow noopener\" target=\"_blank\">Click here<\/a> to learn more about the changes made to the breach notification rule<\/p>\n<\/p><\/div>\n<div class=\"file-field-content form-field-content\">\n<div class=\"form-group\"> <label> Updated breach notification compliance plan (file) <\/label> <\/p>\n<div class=\"file-container\"> <button type=\"button\" disabled class=\"btn btn-default\"> <i class=\"fa fa-upload btn-icon\"><\/i> File will be uploaded here <\/button>\n   <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"update-patient-medical-record-request-form\">\n<h2>Update patient medical record request form<\/h2>\n<div class=\"text-content\">\n<p>In order to comply with the HIPAA Omnibus Rule, you must update the patient medical record request form to<strong> include the option of providing an electronic copy to the patient.<\/strong><\/p>\n<p>You can <strong>attach and\/or link to <\/strong>the updated patient medical record request form below.<\/p>\n<\/p><\/div>\n<div class=\"file-field-content form-field-content\">\n<div class=\"form-group\"> <label> Updated patient medical record request form (file) <\/label> <\/p>\n<div class=\"file-container\"> <button type=\"button\" disabled class=\"btn btn-default\"> <i class=\"fa fa-upload btn-icon\"><\/i> File will be uploaded here <\/button>\n   <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"redraft-hipaa-policies-and-procedures\">\n<h2>Redraft HIPAA policies and procedures<\/h2>\n<div class=\"text-content\">\n<p>Redraft <strong>HIPAA policies and procedures<\/strong> to address the changes in the the following documents:<\/p>\n<\/p><\/div>\n<div class=\"multi-select-content form-field-content\">\n<ul class=\"items\">\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       1\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Notice of Privacy Practice\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       2\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Business Associate Agreements\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       3\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Security risk assessment\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       4\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Patient medical record request form\n    <\/div>\n<\/li>\n<\/ul><\/div>\n<div class=\"text-content\">\n<p>You can <strong>attach and\/or link to<\/strong> the updated HIPAA policies and procedures document below.<\/p>\n<\/p><\/div>\n<div class=\"file-field-content form-field-content\">\n<div class=\"form-group\"> <label> Updated HIPAA policies and procedures (file) <\/label> <\/p>\n<div class=\"file-container\"> <button type=\"button\" disabled class=\"btn btn-default\"> <i class=\"fa fa-upload btn-icon\"><\/i> File will be uploaded here <\/button>\n   <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"approval-all-documents-updated\">\n<h2>Approval: All documents updated<\/h2>\n<div class=\"approval-content\">\n<div class=\"header\">\n<div class=\"list-title\">\n    Will be submitted for approval:\n   <\/div>\n<\/p><\/div>\n<div class=\"approval-rule-subject-tasks-list\">\n<ul class=\"list\">\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Update Business Associate Agreements (BAAs)<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Update Notice of Privacy Practices (NPPs)<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Update breach notification compliance plan<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Update patient medical record request form<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Redraft HIPAA policies and procedures<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"phi-security\">\n<h2>PHI security:<\/h2>\n<\/section>\n<section id=\"encrypt-phi-to-federal-standards\">\n<h2>Encrypt PHI to federal standards<\/h2>\n<div class=\"text-content\">\n<p>PHI must be <strong>encrypted to federal standards<\/strong>, though what this means exactly remains intentionally ambiguous.&nbsp;<\/p>\n<p>This is in large part due to the <strong>technical safeguards<\/strong> relating to the encryption of PHI are defined as <strong>\u201caddressable\u201d<\/strong> requirements.<\/p>\n<p>Ultimately, it comes down to the findings gathered from<strong> conducting a risk analysis of PHI security.&nbsp;<\/strong><\/p>\n<p class=\"style-blockquote\"><em>The HIPAA Security Rule allows covered entities to transmit ePHI via email over an electronic open network, provided the information is adequately protected. HIPAA-covered entities must decide whether or not to use encryption for email. That decision must be based on the results of a risk analysis. The risk analysis will identify the risks to the confidentiality, integrity, and availability of ePHI, and a risk management plan must then be developed to reduce those risks to an appropriate level. <\/em>- <a href=\"https:\/\/www.hipaajournal.com\/\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Journal<\/a>, <a href=\"https:\/\/www.hipaajournal.com\/hipaa-encryption-requirements\/\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Encryption Requirements<\/a><\/p>\n<p class=\"style-warning\">Once a communication containing PHI goes <strong>beyond a covered entity's firewall<\/strong>, encryption becomes an addressable safeguard that <strong>must be dealt with<\/strong>. This applies to <strong>any form electronic communication<\/strong> \u2013 email, SMS, instant message, etc.<\/p>\n<p>In the form field below, provide a <strong>summary of the measures your organization has taken<\/strong> to encrypt PHI to federal standards.<\/p>\n<p>You can also <strong>attach and\/or link to<\/strong> relevant documentation.<\/p>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\"> <label> Summary of measures taken to encrypt PHI <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<div class=\"file-field-content form-field-content\">\n<div class=\"form-group\"> <label> PHI encryption (file) <\/label> <\/p>\n<div class=\"file-container\"> <button type=\"button\" disabled class=\"btn btn-default\"> <i class=\"fa fa-upload btn-icon\"><\/i> File will be uploaded here <\/button>\n   <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"ensure-your-electronic-health-record-ehr-is-certified\">\n<h2>Ensure your Electronic Health Record (EHR) is certified<\/h2>\n<div class=\"text-content\">\n<p>In addition to encrypting PHI, you need to ensure that your <strong>Electronic Health Record (EHR) is certified.&nbsp;<\/strong><\/p>\n<p>The Center for Medicare and Medicaid Services (CMS) and the Office of the National Coordinator for Health IT (ONC) have placed standards that will certify your EHR if you have acquired have the necessary technical capabilities and security safeguards.<\/p>\n<p class=\"style-danger\">EHR systems <strong>must include access controls<\/strong> such as passwords which help limit the access to patients\u2019 confidential information.<\/p>\n<\/p><\/div>\n<div class=\"file-field-content form-field-content\">\n<div class=\"form-group\"> <label> EHR certification (file) <\/label> <\/p>\n<div class=\"file-container\"> <button type=\"button\" disabled class=\"btn btn-default\"> <i class=\"fa fa-upload btn-icon\"><\/i> File will be uploaded here <\/button>\n   <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"comply-with-marketing-restrictions\">\n<h2>Comply with marketing restrictions<\/h2>\n<div class=\"text-content\">\n<p>The introduction of the Omnibus Rule brought in <strong>new, stricter restrictions when it comes to marketing PHI.&nbsp;<\/strong><\/p>\n<p class=\"style-info\">To learn more about the marketing restrictions that have been put in place, <a href=\"https:\/\/www.hipaajournal.com\/hipaa-omnibus-rule-places-restrictions-marketing\/#:~:text=The%20Privacy%20Rule%20severely%20restricted,first%20provided%20by%20the%20patient.\" rel=\"nofollow noopener\" target=\"_blank\">read this article by the HIPAA Journal<\/a>.&nbsp;<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"approval-phi-security\">\n<h2>Approval: PHI security<\/h2>\n<div class=\"approval-content\">\n<div class=\"header\">\n<div class=\"list-title\">\n    Will be submitted for approval:\n   <\/div>\n<\/p><\/div>\n<div class=\"approval-rule-subject-tasks-list\">\n<ul class=\"list\">\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Encrypt PHI to federal standards<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Ensure your Electronic Health Record (EHR) is certified<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Comply with marketing restrictions<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"employee-training\">\n<h2>Employee training:<\/h2>\n<\/section>\n<section id=\"implement-a-privacy-and-security-awareness-training-program\">\n<h2>Implement a privacy and security awareness training program<\/h2>\n<div class=\"text-content\">\n<p>It is essential that you perform <strong>ongoing employee training<\/strong> to make sure <strong>all staff members are aware of the rules and regulations<\/strong> laid out by the Omnibus Rule, and are performing their duties accordingly.&nbsp;<\/p>\n<p>Enter the<strong> date of the most recent training session<\/strong> below for record-keeping purposes<\/p>\n<\/p><\/div>\n<div class=\"date-field-content form-field-content\">\n<div class=\"form-group\"> <label> Date of most recent omnibus rule training <\/label> <\/p>\n<div class=\"date-container\"> <button type=\"button\" disabled class=\"btn btn-default\"> <i class=\"fa fa-calendar btn-icon\"><\/i> Date will be set here <\/button>\n   <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"ensure-all-training-is-being-documented\">\n<h2>Ensure all training is being documented<\/h2>\n<div class=\"text-content\">\n<p>All training must be documented. This is incredibly important in the event of an<strong>&nbsp;external audit or investigation.<\/strong><\/p>\n<p class=\"style-blockquote\"><em>HIPAA requires that training be documented.&nbsp; It doesn\u2019t say much else on how training must be documented.&nbsp; In the event of an OCR investigation or audit, it is best to be able to produce the content of the training as well as when it was administered, to whom, and how frequently.&nbsp; You should also keep track of who completed it successfully and what successful completion entailed. -&nbsp;<\/em><a href=\"https:\/\/teachprivacy.com\/hipaa-training-requirements\/#:~:text=HIPAA%20requires%20that%20training%20be,to%20whom%2C%20and%20how%20frequently.\" rel=\"nofollow noopener\" target=\"_blank\">TeachPrivacy<\/a><\/p>\n<p>&nbsp;You can <strong>attach and\/or link to training documentation<\/strong> below.&nbsp;<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"approval-employee-training\">\n<h2>Approval: Employee training<\/h2>\n<div class=\"approval-content\">\n<div class=\"header\">\n<div class=\"list-title\">\n    Will be submitted for approval:\n   <\/div>\n<\/p><\/div>\n<div class=\"approval-rule-subject-tasks-list\">\n<ul class=\"list\">\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Ensure all training is being documented<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Implement a privacy and security awareness training program<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"sources\">\n<h2>Sources:<\/h2>\n<div class=\"text-content\">\n<ul>\n<li><a href=\"https:\/\/healthitsecurity.com\/\" rel=\"nofollow noopener\" target=\"_blank\">HealthITSecurity<\/a> - <a href=\"https:\/\/healthitsecurity.com\/news\/hipaa-omnibus-rule-compliance-checklist\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Omnibus Rule compliance checklist for CEs, BAs<\/a><\/li>\n<li><a href=\"https:\/\/www.capphysicians.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Cooperative of American Physicians<\/a> - <a href=\"https:\/\/www.capphysicians.com\/articles\/hipaa-omnibus-rule-checklist\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Omnibus Rule Checklist<\/a><\/li>\n<li><a href=\"http:\/\/www.hipaasurvivalguide.com\/\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Survival Guide<\/a> - <a href=\"http:\/\/www.hipaasurvivalguide.com\/hipaa-omnibus-rule.php\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Omnibus Rule<\/a><\/li>\n<li><a href=\"https:\/\/dentalenhancements.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Dental Enhancements Inc.<\/a> - <a href=\"https:\/\/dentalenhancements.com\/wp-content\/uploads\/2016\/11\/HIPAA-OMNIBUS-RULE-QUICK-CHECKLIST-of-REQUIREMENTS-2016.pdf\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Omnibus Rule Checklist of Requirements<\/a><\/li>\n<li><a href=\"https:\/\/www.hhhealthlawblog.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Holland &amp; Hart<\/a> - <a href=\"https:\/\/www.hhhealthlawblog.com\/2013\/03\/hipaa-omnibus-rule-checklist-for-compliance.html\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Omnibus Rule: Checklist for Compliance<\/a><\/li>\n<li><a href=\"http:\/\/www.bricker.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Bricker &amp; Eckler<\/a> - <a href=\"http:\/\/www.bricker.com\/documents\/publications\/Business%20Associates%20and%20Business%20Associate%20Agreements.pdf\" rel=\"nofollow noopener\" target=\"_blank\">Analysis of Final HIPAA Omnibus Rule: Business Associates and Business Associate<\/a><\/li>\n<li><a href=\"https:\/\/cynergistek.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Cynergistek<\/a> - <a href=\"https:\/\/cynergistek.com\/blog\/are-your-business-associate-agreements-compliance-with-the-omnibus-rule\/#:~:text=On%20September%2023rd%2C%20all%20business,for%20Civil%20Rights%20(OCR).&amp;text=Compliance%20dates%20for%20key%20changes%20to%20HIPAA%20Rules%20are%20here\" rel=\"nofollow noopener\" target=\"_blank\">Are Your Business Associate Agreements Compliant With The Omnibus Rule?<\/a><\/li>\n<\/ul><\/div>\n<\/section>\n<section id=\"related-checklists\">\n<h2>Related checklists:<\/h2>\n<div class=\"text-content\">\n<ul>\n<li><a href=\"https:\/\/www.process.st\/templates\/hipaa-compliance-checklist-for-hr\/\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Compliance Checklist for HR<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/hipaa-compliance-checklist-for-hr\/\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Privacy Risk Assessment Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/hipaa-compliance-checklist-for-hr\/\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Security Breach Reporting Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/hipaa-business-associate-agreement-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Business Associate Agreement Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/hipaa-data-backup-plan-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Data Backup Plan Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/hipaa-compliance-checklist-for-hr\/\" rel=\"nofollow noopener\" target=\"_blank\">Patient Intake Checklist for a Medical Clinic<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/hipaa-compliance-checklist-for-hr\/\" rel=\"nofollow noopener\" target=\"_blank\">Patient Intake Checklist for a Dental Clinic<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/hipaa-compliance-checklist-for-hr\/\" rel=\"nofollow noopener\" target=\"_blank\">Patient Satisfaction Survey Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/hospital-housekeeping-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">Hospital Housekeeping Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/terminal-room-cleaning-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">Terminal Room Cleaning Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/hospital-safety-inspection-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">Hospital Safety Inspection Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/general-infection-control-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">General Infection Control Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/patient-satisfaction-survey-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">Patient Satisfaction Survey Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/home-visit-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">Home Visit Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/mental-health-risk-assessment-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">Mental Health Risk Assessment Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/who-surgical-safety-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">WHO Surgical Safety Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/hipaa-compliance-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Compliance Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-isolation-area-management\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Isolation Area Management<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-disinfection-procedures-for-covid-19-isolation-ward-area\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Disinfection Procedures for COVID-19 Isolation Ward Area<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-lung-transplantation-pre-transplantation-assessment\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Lung Transplantation Pre-Transplantation Assessment<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-nursing-care-during-treatment-alss\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Nursing Care During Treatment (ALSS)<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-protocol-for-donning-and-removing-ppe\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Protocol for Donning and Removing PPE<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-staff-management-workflow-and-health\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Staff Management (Workflow and Health)<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-daily-management-and-monitoring-of-ecmo-audit\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Daily Management and Monitoring of ECMO Audit<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-digital-support-for-epidemic-prevention-and-control\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Digital Support for Epidemic Prevention and Control<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-discharge-standards-and-follow-up-plan-for-covid-19-patients\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Discharge Standards and Follow-up Plan for COVID-19 Patients<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-disinfection-of-covid-19-related-reusable-medical-devices\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Disinfection of COVID-19 Related Reusable Medical Devices<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-disinfection-procedures-for-infectious-fabrics-of-suspected-or-confirmed-patients\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Disinfection Procedures for Infectious Fabrics of Suspected or Confirmed Patients<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-disposal-procedures-for-covid-19-related-medical-waste\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Disposal Procedures for COVID-19 Related Medical Waste<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-disposal-procedures-for-spills-of-covid-19-patient-blood-fluids\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Disposal Procedures for Spills of COVID-19 Patient Blood\/Fluids<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-procedures-for-handling-bodies-of-deceased-suspected-or-confirmed-patients\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Procedures for Handling Bodies of Deceased Suspected or Confirmed Patients<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-procedures-for-taking-remedial-actions-against-occupational-exposure-to-covid-19\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Procedures for Taking Remedial Actions against Occupational Exposure to COVID-19<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-surgical-operations-for-suspected-or-confirmed-patients\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Surgical Operations for Suspected or Confirmed Patients<\/a><\/li>\n<\/ul><\/div>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>Introduction: The Omnibus Rule was introduced in 2013 as a way to amend the HIPAA privacy and security rules requirements, including changes to the obligations of business associates regarding the management of PHI. The rule merges the following four separate rule makings: Amendments to HIPAA Privacy and Security rules requirements HIPAA and HIPAA HITECH under [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":24513,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"ep_exclude_from_search":false,"cover_icon_emoji":"","cover_icon_url":"","tasks_count":"22","template_description":"Run this checklist periodically to evaluate compliance with the HIPAA Omnibus Rule","template_id":"lV5SbCpErOw1lX_BkGlNzw","task_0":"Introduction:","task_slug_0":"introduction","task_1":"Enter basic details","task_slug_1":"enter-basic-details","task_2":"Team management:","task_slug_2":"team-management","task_3":"Designate a privacy and security official","task_slug_3":"designate-a-privacy-and-security-official","task_4":"Amending documentation:","task_slug_4":"amending-documentation","task_5":"Update Business Associate Agreements (BAAs)","task_slug_5":"update-business-associate-agreements-baas","task_6":"Update Notice of Privacy Practices (NPPs)","task_slug_6":"update-notice-of-privacy-practices-npps","task_7":"Update breach notification compliance plan","task_slug_7":"update-breach-notification-compliance-plan","task_8":"Update patient medical record request form","task_slug_8":"update-patient-medical-record-request-form","task_9":"Redraft HIPAA policies and procedures","task_slug_9":"redraft-hipaa-policies-and-procedures","task_10":"Approval: All documents updated","task_slug_10":"approval-all-documents-updated","task_11":"PHI security:","task_slug_11":"phi-security","task_12":"Encrypt PHI to federal standards","task_slug_12":"encrypt-phi-to-federal-standards","task_13":"Ensure your Electronic Health Record (EHR) is certified","task_slug_13":"ensure-your-electronic-health-record-ehr-is-certified","task_14":"Comply with marketing restrictions","task_slug_14":"comply-with-marketing-restrictions","task_15":"Approval:  PHI security","task_slug_15":"approval-phi-security","task_16":"Employee training:","task_slug_16":"employee-training","task_17":"Implement a privacy and security awareness training program","task_slug_17":"implement-a-privacy-and-security-awareness-training-program","task_18":"Ensure all training is being documented","task_slug_18":"ensure-all-training-is-being-documented","task_19":"Approval: Employee training","task_slug_19":"approval-employee-training","task_20":"Sources:","task_slug_20":"sources","task_21":"Related checklists:","task_slug_21":"related-checklists","task_22":"","task_slug_22":"","task_23":"","task_slug_23":"","task_24":"","task_slug_24":"","task_25":"","task_slug_25":"","task_26":"","task_slug_26":"","task_27":"","task_slug_27":"","task_28":"","task_slug_28":"","task_29":"","task_slug_29":"","task_30":"","task_slug_30":"","task_31":"","task_slug_31":"","task_32":"","task_slug_32":"","task_33":"","task_slug_33":"","task_34":"","task_slug_34":"","task_35":"","task_slug_35":"","task_36":"","task_slug_36":"","task_37":"","task_slug_37":"","task_38":"","task_slug_38":"","task_39":"","task_slug_39":"","task_40":"","task_slug_40":"","task_41":"","task_slug_41":"","task_42":"","task_slug_42":"","task_43":"","task_slug_43":"","task_44":"","task_slug_44":"","task_45":"","task_slug_45":"","task_46":"","task_slug_46":"","task_47":"","task_slug_47":"","task_48":"","task_slug_48":"","task_49":"","task_slug_49":"","task_50":"","task_slug_50":"","task_51":"","task_slug_51":"","task_52":"","task_slug_52":"","task_53":"","task_slug_53":"","task_54":"","task_slug_54":"","task_55":"","task_slug_55":"","task_56":"","task_slug_56":"","task_57":"","task_slug_57":"","task_58":"","task_slug_58":"","task_59":"","task_slug_59":"","task_60":"","task_slug_60":"","task_61":"","task_slug_61":"","task_62":"","task_slug_62":"","task_63":"","task_slug_63":"","task_64":"","task_slug_64":"","task_65":"","task_slug_65":"","task_66":"","task_slug_66":"","task_67":"","task_slug_67":"","task_68":"","task_slug_68":"","task_69":"","task_slug_69":"","task_70":"","task_slug_70":"","task_71":"","task_slug_71":"","task_72":"","task_slug_72":"","task_73":"","task_slug_73":"","task_74":"","task_slug_74":"","task_75":"","task_slug_75":"","task_76":"","task_slug_76":"","task_77":"","task_slug_77":"","task_78":"","task_slug_78":"","task_79":"","task_slug_79":"","task_80":"","task_slug_80":"","task_81":"","task_slug_81":"","task_82":"","task_slug_82":"","task_83":"","task_slug_83":"","task_84":"","task_slug_84":"","task_85":"","task_slug_85":"","task_86":"","task_slug_86":"","task_87":"","task_slug_87":"","task_88":"","task_slug_88":"","task_89":"","task_slug_89":"","task_90":"","task_slug_90":"","task_91":"","task_slug_91":"","task_92":"","task_slug_92":"","task_93":"","task_slug_93":"","task_94":"","task_slug_94":"","task_95":"","task_slug_95":"","task_96":"","task_slug_96":"","task_97":"","task_slug_97":"","task_98":"","task_slug_98":"","task_99":"","task_slug_99":"","footnotes":""},"categories":[29,7],"tags":[],"class_list":["post-24512","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-healthcare","category-miscellaneous"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts\/24512","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/comments?post=24512"}],"version-history":[{"count":0,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts\/24512\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/media\/24513"}],"wp:attachment":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/media?parent=24512"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/categories?post=24512"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/tags?post=24512"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}