Free HIPAA policy template · v1.0 · Applies to covered entities & business associates · Companion: Procedures →
Adopting this document means committing to these HIPAA controls, the 45 CFR §164 requirements it helps satisfy, by area:
Common threats (NIST SP 800-30 classes) that the controls behind this document defend against:
Exploits: No access controls on shares · 164.312(a) Access Control; 164.514(d)
Template. Replace every
[bracketed]item with your organization's specifics. A name in[Title Case]is your organization, a role, or a person; a phrase in[lower case]is a category of tool. Substitute the actual product you use. This Policy is for a Business Associate (a vendor that handles PHI on behalf of a covered entity). Have it reviewed by counsel before adoption.
This Policy establishes the obligations [Organization] accepts as a Business Associate (BA) when it creates, receives, maintains, or transmits protected health information (PHI) on behalf of a covered entity or another business associate. It ensures PHI is used and disclosed only as permitted, limited to the minimum necessary, never sold, made available to HHS on request, and handled so the covered entity can meet its own HIPAA obligations. It satisfies 45 CFR §§ 164.502(a)(3), 164.502(a)(4), 164.502(a)(5)(ii), 164.502(b), 164.514(d), and 164.504(e).
This Policy applies to all workforce members, systems, and subcontractors of [Organization] that create, receive, maintain, or transmit PHI under any Business Associate Agreement (BAA). Where a BAA imposes a stricter or more specific term, the BAA controls.
See where your organization stands on the controls this template cites.
Join Us[Organization] uses and discloses PHI only as expressly permitted by the applicable BAA, or as required by law. PHI is used or disclosed for [Organization]'s own management, administration, and legal responsibilities only where the BAA permits it and, for disclosures, only with reasonable assurances of continued protection from the recipient. Any use or disclosure not permitted by the BAA or the Privacy Rule is prohibited and is treated as a potential incident under the Security Incident Response Policy.
Requests for, uses of, and disclosures of PHI are limited to the minimum necessary to accomplish the intended purpose. [Organization] maintains role-based access so each workforce member and system reaches only the PHI needed for its function (see the Access Control Policy).
[Organization] does not sell PHI and does not receive direct or indirect remuneration in exchange for PHI except as narrowly permitted by law and expressly authorized in the BAA. Marketing and fundraising uses of PHI are made only where the covered entity has obtained any authorization the Privacy Rule requires.
[Organization] makes its internal practices, books, and records relating to the use and disclosure of PHI available to the U.S. Department of Health and Human Services (HHS) on request for a compliance determination, and discloses PHI where required by law, routing such requests through the [Privacy Official].
When an individual exercises a HIPAA right that touches PHI [Organization] holds, [Organization] assists the covered entity within the timeframe the BAA specifies: providing access to PHI in a designated record set, incorporating amendments the covered entity directs, and supplying the information needed for an accounting of disclosures. Requests received directly from an individual are promptly relayed to the covered entity rather than actioned unilaterally.
[Organization] applies the administrative, physical, and technical safeguards of the HIPAA Security Rule to ePHI (see the organization's security policies), binds every subcontractor that handles PHI to terms at least as protective through a written agreement (see the Subcontractor Management Policy), and reports security incidents and breaches to the covered entity as required (see the Breach Reporting to Covered Entity Procedure).
On termination of a BAA, [Organization] returns or securely destroys all PHI it holds where feasible, retaining none; where return or destruction is infeasible, it extends the BAA's protections to the retained PHI and limits further use to the purposes that make return or destruction infeasible.
| Citation | Requirement | Addressed in |
|---|---|---|
| 164.502(a)(3) | Impermissible uses/disclosures prohibited | §1 |
| 164.504(e) | Business associate contract terms | §1, §5, §6, §7 |
| 164.502(b) | Minimum necessary | §2 |
| 164.514(d) | Minimum necessary standard | §2 |
| 164.502(a)(5)(ii) | Sale of PHI prohibition | §3 |
| 164.502(a)(4) | Disclosures required by law / to HHS | §4 |
Reviewed at least annually by the [Privacy Official] and after any change to [Organization]'s BAAs or the PHI it handles. v1.0.