Free HIPAA procedures template · v1.0 · Applies to covered entities & business associates · Companion: Policy →
Adopting this document means committing to these HIPAA controls, the 45 CFR §164 requirements it helps satisfy, by area:
Common threats (NIST SP 800-30 classes) that the controls behind this document defend against:
Exploits: No access controls on shares · 164.312(a) Access Control; 164.514(d)
Template. These procedures operationalize the Business Associate HIPAA Obligations Policy. Replace
[bracketed]items with your specifics and adjust steps to match your tools and team size.
Repeatable, auditable steps for a Business Associate to keep PHI use and disclosure within its BAAs, enforce minimum necessary, respond to HHS and individual-rights requests, and handle PHI correctly at the end of a relationship. This implements the Business Associate HIPAA Obligations Policy.
[BAA tracker]: counterparty, effective date, the PHI categories received, the permitted uses/disclosures, and the return-or-destruction terms.[quarterly]; flag any BAA nearing renewal or any use not traceable to a BAA.See where your organization stands on the controls this template cites.
Join Us[Privacy Official] before proceeding.[Privacy Official] immediately. Do not respond directly.[Privacy Official] validates the request, notifies the affected covered entity where the BAA requires, assembles the responsive records, and logs the disclosure.[Organization] directly to access, amend, or get an accounting of their PHI, log it and forward it to the covered entity within [2 business days]. Do not action it unilaterally.