Free HIPAA policy template · v1.0 · Applies to covered entities & business associates · Companion: Procedures →
Adopting this document means committing to these HIPAA controls, the 45 CFR §164 requirements it helps satisfy, by area:
Common threats (NIST SP 800-30 classes) that the controls behind this document defend against:
Exploits: No or weak MFA; reused passwords · 164.312(d) Authentication; 164.308(a)(5) Training
Template. Replace every
[bracketed]item with your organization's specifics. A name in[Title Case]is your organization, a role, or a person; a phrase in[lower case]is a category of tool. Substitute the actual product you use (e.g.,[learning management system]→ your chosen tool). Have this reviewed by counsel or your compliance advisor before adoption.
This Policy establishes how [Organization] manages the people dimension of protecting electronic protected health information (ePHI) and protected health information (PHI): screening workforce members before they are granted access, training them on their security and privacy obligations, reinforcing that training over time, applying consistent sanctions when they violate policy, and guaranteeing that no one is intimidated or retaliated against for exercising their rights or raising a concern. It satisfies the workforce-clearance, training, security-reminder, and sanction requirements of the HIPAA Security Rule at 45 CFR § 164.308(a)(3)(ii)(B), § 164.308(a)(5)(i)–(ii)(A), and § 164.308(a)(1)(ii)(C), and the training, sanction, and anti-retaliation requirements of the Privacy Rule at § 164.530(b), (e), and (g).
See where your organization stands on the controls this template cites.
Join UsAccount provisioning, modification, and revocation are governed by the Access Control Policy; this Policy covers the HR/people controls that surround them.
This Policy applies to all workforce members (employees, contractors, interns, and volunteers) and, where noted, to candidates for employment and to third parties who are exposed to [Organization] PHI. It covers pre-hire screening, onboarding and ongoing training, periodic security awareness reminders, the unified sanction process for security and privacy violations, and [Organization]'s anti-retaliation guarantee. Workforce members must acknowledge this Policy in writing during onboarding and at least annually thereafter.
[Organization] screens individuals before authorizing access to systems or PHI, to a degree appropriate to the role. Each position is assigned a risk designation reflecting its access to critical systems, confidential data, or the ability to influence business and patient relationships; the designation sets the level of screening required, and designations are reviewed at least annually. For roles with access to ePHI/PHI or other sensitive functions, screening includes a background check performed through an approved provider and verification of role-appropriate criteria (education, certifications/licensure, and relevant work history). Background checks must be completed and accepted before the start date; if a check is not complete, the start date is delayed. More stringent criteria may apply to leadership, privileged, or other high-risk positions, and individuals may be re-screened on role change. Candidates are informed in the job posting that a check is required, provide written consent before it is run, and convictions (not arrests) are evaluated case-by-case against job-relevant criteria without unlawful discrimination. Before access is granted, the workforce member also signs the required confidentiality/NDA and acceptable-use agreements (see Access Control Policy). The screening procedure is detailed in the companion Workforce Security Procedures.
[Organization] provides a combined security and privacy training program to all workforce members regardless of role, including managers, executives, and contractors. Training is completed during onboarding before access to ePHI/PHI is granted (and in all cases no later than [30 days] after start), again when a material change to a role, system, regulation, or policy warrants it, and at least annually thereafter. At minimum, training covers: [Organization]'s security and privacy policies and procedures; how to recognize, guard against, and report malicious software and social-engineering/phishing attempts; safe handling of PHI/PII (minimum necessary, appropriate use and disclosure, clear-desk/clear-screen, secure transmission and disposal); password and authenticator hygiene; each member's role in incident reporting and in the No intimidation or retaliation guarantee (§ 5); and the consequences of non-compliance, including sanctions (§ 4). Role- specific modules are provided where warranted (e.g., privileged users, engineers, managers). Content is reviewed and updated at least annually and after incidents, audits, or regulatory change. Workforce members must complete training before access and re-attest on the schedule above; completion is a condition of continued access.
Between formal training cycles, [Organization] issues periodic security and privacy reminders to keep awareness current. Reminders may include security newsletters or email advisories, login-screen or banner messages, posted notices, simulated-phishing exercises with follow-up coaching, and short briefings on recent threats or policy changes. Reminders are distributed on a recurring cadence (at least [quarterly]) and ad hoc when a new or significant threat emerges. The [Security Official] owns the reminder program and the [Privacy Officer] contributes privacy-specific content.
[Organization] applies one consistent sanction process to workforce members who fail to comply with its security or privacy policies and procedures, including the HIPAA Security and Privacy Rules. Sanctions are applied fairly and proportionately to the nature and severity of the violation, whether it was intentional or negligent, whether it is a first or repeat occurrence, and the actual or potential harm to patients, the organization, or others. The range of sanctions includes (escalating) retraining, a documented warning, heightened monitoring, suspension of access or duties, and termination of employment or contract; serious violations may also carry civil or criminal referral. Every sanction decision is documented and the record is retained for six years. Sanctions are not applied to a workforce member for: filing or cooperating in a complaint, investigation, or proceeding; reporting a suspected violation in good faith through the No intimidation or retaliation guarantee (§ 5); or exercising any right under the HIPAA Rules. The decision guide and documentation steps are in the companion Workforce Security Procedures. Termination mechanics (access revocation, asset return) are governed by the Access Control Policy.
[Organization] will not intimidate, threaten, coerce, discriminate against, or take any retaliatory action against any individual for: exercising a right under the HIPAA Privacy or Security Rules; filing a complaint with [Organization] or the U.S. Department of Health and Human Services; testifying, assisting, or participating in an investigation, compliance review, proceeding, or hearing; or opposing, in good faith and by lawful means, an act or practice the individual reasonably believes to be unlawful or in violation of these Rules. This protection extends to workforce members, patients, and other individuals. As a condition of providing treatment, payment, enrollment, or eligibility, [Organization] will not require individuals to waive their right to file a complaint with HHS. Workforce members are encouraged to raise concerns to their manager, the [Security Official], or the [Privacy Officer] (anonymously where supported), and anyone who is told to "keep quiet" about a suspected violation must report that fact as well. Retaliation against a person who raises a concern is itself a sanctionable violation under § 4.
[Security Official]: owns this Policy; defines role risk designations; owns the training and security-reminder program for security topics; participates in sanction decisions for security violations.[Privacy Officer]: owns privacy training content; is the point of contact for privacy complaints and the anti-retaliation guarantee; participates in sanction decisions for privacy violations.Workforce Security Procedures · Access Control Policy (provisioning, termination, asset return) · Security Incident Response Policy · Breach Notification Policy · Confidentiality / Nondisclosure Agreement · Acceptable Use Policy.
| Citation | Requirement | Addressed in |
|---|---|---|
| 164.308(a)(3)(ii)(B) | Workforce Clearance Procedure | §1 |
| 164.308(a)(5)(i) | Security Awareness and Training | §2, §3 |
| 164.308(a)(5)(ii)(A) | Security Reminders | §3 |
| 164.308(a)(1)(ii)(C) | Sanction Policy | §4 |
| 164.530(b) | Training (Privacy) | §2 |
| 164.530(e) | Sanctions (Privacy) | §4 |
| 164.530(g) | Refraining from Intimidating or Retaliatory Acts | §4, §5 |
Reviewed at least annually by the [Security Official] and [Privacy Officer], and after any significant change to the workforce, the regulatory landscape, or the ePHI environment. v1.0.