Free HIPAA policy template · v1.0 · Applies to covered entities · Companion: Procedures →
Adopting this document means committing to these HIPAA controls, the 45 CFR §164 requirements it helps satisfy, by area:
Common threats (NIST SP 800-30 classes) that the controls behind this document defend against:
Exploits: No access controls on shares · 164.312(a) Access Control; 164.514(d)
Template. Replace every
[bracketed]item with your organization's specifics. A name in[Title Case]is your organization, a role, or a person; a phrase in[lower case]is a category of tool. Substitute the actual product you use (e.g.,[knowledge base]→ your chosen tool). Have this reviewed by counsel or your compliance advisor before adoption.
This Policy establishes how [Organization] uses and discloses protected health information (PHI), and how it honors the privacy rights of the individuals whose information it holds, so that PHI is used and shared only as the law permits and individuals can exercise control over their own information. It satisfies the requirements of the HIPAA Privacy Rule at 45 CFR Part 164, Subpart E (§§ 164.500–164.534), including the general rules on uses and disclosures, the minimum-necessary standard, de-identification, the Notice of Privacy Practices, and the rights of access, amendment, accounting, restriction, and confidential communication.
This Policy applies to all PHI that [Organization] creates, receives, maintains, or transmits in any form or medium (electronic, paper, or oral) and to all workforce members (employees, contractors, interns, and volunteers) and business associates who handle that PHI. Workforce members must acknowledge this Policy in writing before being given access to PHI and at least annually thereafter. Where a state privacy law is more protective of the individual than this Policy, the more protective requirement governs.
See where your organization stands on the controls this template cites.
Join Us[Organization] may not use or disclose PHI except as this Policy permits or requires, or as authorized in writing by the individual. PHI may be used or disclosed without authorization only for the purposes identified below (treatment, payment, and health-care operations; situations where the individual is given an opportunity to agree or object; and the public-interest categories that the Rule permits). [Organization] must disclose PHI in two situations: (a) to the individual (or their personal representative) when they request access or an accounting, and (b) to the Secretary of HHS when required for a compliance investigation or enforcement action. Every other use or disclosure that is not permitted by this Policy requires a valid authorization. An impermissible use or disclosure is presumed to be a breach and is handled under the Breach Notification Policy.
When using, disclosing, or requesting PHI, [Organization] limits the information to the minimum necessary to accomplish the intended purpose. Minimum necessary does not apply to: disclosures to or requests by a health-care provider for treatment; disclosures to the individual; uses or disclosures made under a valid authorization; disclosures to HHS for compliance; uses or disclosures required by law; and uses or disclosures required for compliance with the Rule. [Organization] implements minimum necessary through role-based access. Each role is granted access only to the categories of PHI it needs to do its job (the role map lives in the companion Privacy Procedures). For routine, recurring disclosures and requests, [Organization] relies on standard protocols that limit PHI to what is reasonably necessary; non-routine disclosures are reviewed individually against documented criteria.
[Organization] may use and disclose PHI, without authorization, for its own treatment, payment, and health-care operations, and for certain TPO activities of another covered entity as the Rule allows (for example, disclosing to another provider for that provider's treatment of the individual, or to another covered entity for certain payment or quality-related operations where both have a relationship with the individual). Consent for TPO is not required by HIPAA; where [Organization] chooses to obtain consent, doing so does not waive any other requirement of this Policy.
Any use or disclosure not otherwise permitted by this Policy requires a valid written authorization signed by the individual. Authorizations are always required for: most uses and disclosures of psychotherapy notes; uses and disclosures for marketing (other than the narrow permitted exceptions); and any sale of PHI. A valid authorization must be in plain language and contain: a specific description of the information; who may disclose and who may receive it; the purpose; an expiration date or event; the individual's signature and date; a statement of the right to revoke and how to do so; a statement that information disclosed may be re-disclosed and lose protection; and a statement about conditioning. [Organization] will not condition treatment, payment, enrollment, or eligibility on obtaining an authorization, except in the limited cases the Rule allows. An individual may revoke an authorization in writing at any time, except to the extent [Organization] has already acted in reliance on it.
For certain uses and disclosures, [Organization] must give the individual the opportunity to agree or object (orally is acceptable). These include: maintaining a facility directory; disclosing to family members, relatives, or others involved in the individual's care or payment for care; and notification for disaster-relief purposes. Where the individual is present and has capacity, [Organization] obtains agreement or provides the opportunity to object; where the individual is not present or is incapacitated, [Organization] may use professional judgment to determine whether the disclosure is in the individual's best interest and disclose only the PHI directly relevant.
[Organization] may use or disclose PHI without authorization and without the opportunity to agree or object for the specific public-interest purposes the Rule permits, each subject to its own conditions: when required by law; for public health activities; about victims of abuse, neglect, or domestic violence; for health-oversight activities; for judicial and administrative proceedings (e.g., a court order, or a subpoena with satisfactory assurances); for law-enforcement purposes; to coroners, medical examiners, and funeral directors; for cadaveric organ, eye, or tissue donation; for research (with IRB/Privacy-Board approval or other permitted basis); to avert a serious threat to health or safety; for specialized government functions (e.g., military, national security); and for workers' compensation. Each such disclosure is limited to the minimum necessary (except where minimum necessary does not apply) and is recorded for accounting where the Rule requires it.
Health information that has been de-identified in accordance with the Rule is not PHI and may be used and disclosed freely. [Organization] de-identifies information only by one of the two permitted methods: (a) Expert Determination: a qualified statistical/scientific expert determines and documents that the risk of re-identification is very small; or (b) Safe Harbor: removal of all 18 specified identifiers of the individual and of relatives, employers, and household members, with no actual knowledge that the remaining information could identify the individual. [Organization] may assign a re-identification code to de-identified data, provided the code is not derived from PHI and the mechanism is not disclosed; the code and method are controlled and used only by [Organization].
Where a fully de-identified set is not workable, [Organization] may use or disclose a limited data set (PHI stripped of the direct identifiers the Rule specifies) for research, public health, or health-care operations, but only under a signed data use agreement that restricts the recipient's use and re-disclosure and prohibits re-identification or contact of individuals.
If [Organization] conducts fundraising, it may use only the limited categories of PHI the Rule permits (e.g., demographic information, dates of service, treating department, outcome) and every fundraising communication must include a clear, easy way to opt out of future fundraising; an individual's opt-out is honored and is treated as a revocation of authorization to use their PHI for fundraising. If [Organization] is a health plan, it must not use or disclose genetic information for underwriting purposes. PHI is not used or disclosed for marketing or sold without a valid authorization (see §4).
[Organization] maintains and distributes a Notice of Privacy Practices written in plain language that describes: how [Organization] may use and disclose PHI; the individual's rights (access, amendment, accounting, restriction, confidential communication, paper copy, and complaint); the duties of [Organization] to protect PHI and abide by the Notice; how to file a complaint; and the contact information for the [Privacy Officer]. The Notice includes an effective date and the required statements (e.g., that certain uses (psychotherapy notes, marketing, sale) require authorization, and that the individual may opt out of fundraising). [Organization] provides the Notice no later than the date of first service delivery, makes a good-faith effort to obtain written acknowledgement of receipt, posts the Notice prominently (including on any website), makes it available on request, and re-distributes it when materially revised. Documentation of the Notice and acknowledgements is retained.
Individuals have the right to inspect and obtain a copy of PHI about them in a designated record set, for as long as [Organization] maintains it. [Organization] acts on an access request within 30 days (with one 30-day extension on written notice explaining the delay), provides the copy in the form and format requested if readily producible (including a readily producible electronic copy of ePHI, and transmission to a third party the individual designates in a signed, clear request), and charges only a reasonable, cost-based fee. Access may be denied only on the limited grounds the Rule specifies; where a denial is reviewable, the individual is told of their right to have it reviewed by a licensed health-care professional who did not participate in the original decision.
Individuals may request restrictions on uses and disclosures of their PHI for treatment, payment, or operations, and on disclosures to persons involved in their care. [Organization] is generally not required to agree, except it must agree to restrict disclosure to a health plan for payment or operations when the individual has paid in full out of pocket for the item or service and the disclosure is not otherwise required by law. Agreed restrictions are documented and honored (except in an emergency). Individuals also have the right to request and receive confidential communications by alternative means or at alternative locations (e.g., a specific phone number or mailing address); [Organization] accommodates reasonable requests and does not require an explanation.
Individuals have the right to request amendment of PHI in a designated record set. [Organization] acts on the request within 60 days (with one 30-day extension on written notice). If the amendment is accepted, [Organization] makes the change, flags the record, and informs persons the individual identifies and persons known to have the erroneous PHI. [Organization] may deny a request on the limited grounds the Rule allows (e.g., the record was not created by [Organization], is not part of the designated record set, is accurate and complete, or would not be available for access); a denial is in writing, in plain language, and informs the individual of their right to submit a statement of disagreement, which is then included with future disclosures of the disputed PHI.
Individuals have the right to receive an accounting of disclosures of their PHI made by [Organization] and its business associates in the six years prior to the request. The accounting excludes the disclosures the Rule exempts (e.g., for treatment, payment, and operations; to the individual; pursuant to an authorization; for a facility directory or to persons involved in care; and certain others). For each accountable disclosure [Organization] records the date, the recipient, a description of the PHI, and the purpose. [Organization] provides the accounting within 60 days (with one 30-day extension), and the first accounting in any 12-month period is free.
[Organization] treats a personal representative (a person with authority under applicable law to act on the individual's behalf (e.g., a parent for a minor, a guardian, or a holder of a health-care power of attorney), or an executor/administrator for a deceased individual) as the individual for purposes of this Policy, with respect to PHI relevant to that authority. [Organization] may decline to treat a person as a personal representative if it reasonably believes the individual has been or may be subjected to abuse or neglect by that person, or that doing so would endanger the individual. Special rules for minors are applied consistently with state law.
[Organization] does not require individuals to waive their rights under the Privacy Rule (including the right to file a complaint with HHS) as a condition of treatment, payment, enrollment, or eligibility for benefits.
Individuals may file a complaint about [Organization]'s privacy practices or its compliance with this Policy, and may also complain to the HHS Office for Civil Rights. The [Privacy Officer] receives, logs, and investigates complaints; documents their disposition; and ensures no retaliation is taken against any individual for filing a complaint, cooperating in an investigation, or exercising a privacy right. The complaint process is described in the Privacy Procedures and summarized in the NPP.
[Privacy Officer]: owns this Policy; maintains the Notice of Privacy Practices; oversees the minimum-necessary role map, authorizations, and de-identification; processes individual-rights requests; and receives and resolves complaints.[Security Official]: safeguards ePHI that this Policy governs (administrative, physical, and technical controls) under the security policies.[Privacy Officer], and report suspected impermissible uses or disclosures.[Organization]'s accounting and individual-rights obligations.Privacy Procedures · Security & Privacy Program Policy · Breach Notification Policy · Access Control Policy · Workforce Security, Training & Sanctions Policy · Vendor Management Policy (business associate agreements).
| Citation | Requirement | Addressed in |
|---|---|---|
| 164.502(a) | Uses and Disclosures: General Rules | §1 |
| 164.502(b) | Minimum Necessary | §2 |
| 164.514(d) | Minimum Necessary: Implementation | §2 |
| 164.506 | Uses/Disclosures for Treatment, Payment & Operations | §3 |
| 164.508 | Authorizations | §4, §9 |
| 164.510 | Uses/Disclosures Requiring Opportunity to Agree or Object | §5 |
| 164.512 | Uses/Disclosures Not Requiring Authorization | §6 |
| 164.514(a) | De-identification: Standard | §7 |
| 164.514(b) | De-identification: Implementation (Expert / Safe Harbor) | §7 |
| 164.514(c) | Re-identification Code | §7 |
| 164.514(f) | Fundraising | §9 |
| 164.514(g) | Underwriting (genetic information) | §9 |
| 164.520 | Notice of Privacy Practices | §10 |
| 164.524 | Right of Access | §11 |
| 164.522 | Restrictions & Confidential Communications | §12 |
| 164.526 | Right to Amend | §13 |
| 164.528 | Accounting of Disclosures | §14 |
| 164.502(g) | Personal Representatives | §15 |
| 164.530(h) | No Waiver of Rights | §16 |
| 164.530(d) | Complaints | §17 |
Reviewed at least annually by the [Privacy Officer] and after any change in law or in [Organization]'s use or disclosure of PHI. v1.0.