Operations · Policies & Procedures
A policy set is not a document you write once. It is one you keep.
Starters pinned to the provisions they answer, separate fields for what you do and how you do it, and a set that tells you when it has drifted out of date.
HIPAA mapping
Where this fits in the HIPAA rules.
4 provisions this capability contributes to, each with the specific Policies & Procedures behavior behind it. The obligation stays with your practice — the mapping shows which part of the work the platform carries.
§164.316(a)Policies and procedures
Requires reasonable and appropriate policies and procedures for the Security Rule's standards, taking your size, complexity and capabilities into account. Reasonable and appropriate for a four-person practice is not what it is for a hospital, which is exactly why a starter has to be edited before it means anything.
§164.316(b)(1)Documentation
Requires those policies and procedures to be maintained in writing. Written and retrievable are different states, and the second is the one that matters when someone asks to see them.
§164.316(b)(2)(iii)Updates
Requires periodic review and updating in response to environmental or operational changes affecting ePHI security. A policy set is a living document by regulation, not by best practice — this is the provision people are surprised by.
§164.530(i)Privacy Rule policies and procedures
The Privacy Rule's parallel obligation, covering uses and disclosures of PHI. The two rules ask for different policy sets, and a practice that has addressed only the Security Rule has done half.
What it does
Everyone has policies. Almost nobody has current ones.
The usual shape of this is a binder or a folder, assembled during a compliance push two or three years ago, mostly downloaded, lightly edited, and never opened since. It satisfies the version of the question a practice asks itself — do we have policies — while failing the version an investigator asks, which is whether they describe what the practice actually does and when they were last reviewed.
Policies & Procedures starts you from 48 starters, each pinned to the provision it answers, so the set has coverage before you have written a word. What it then does is the part that matters: it treats the set as something with a state. Policies you have adopted, policies you have not, policies overdue for review, policies nobody on the workforce has acknowledged.
The boundary is worth putting up front rather than in a footnote. Starter text is a starting point. It describes a generic practice, and yours is not generic — your systems, your staffing, your specialty and your physical space all belong in it. Adopting a starter unedited produces a policy that is written down and untrue, which in an investigation is a worse position than having none, because you have documented a control you do not operate.
How it works
7 mechanisms keep Policies & Procedures working.
48 starters, each pinned to a citation.
Every starter names the provision it exists to answer, which turns the set from a pile of documents into a map. When you are looking at a gap you can see which provision is uncovered rather than guessing whether the thing you are missing is a policy you have never heard of.
Policy and procedure are separate fields.
A policy states what your practice does and why. A procedure states how, and who. Most templates blur them into one document, which is how you end up with a policy nobody can follow and a procedure that nobody can trace to a rule. Keeping them apart forces the second question — you have said workstations are locked when unattended, now say by whom, using what, and what happens when they are not.
Adopted against a recommended set.
The Scoreboard shows adoption as a fraction — adopted over the number recommended for your practice type — rather than as a percentage of a fixed library. Most practices will never reach the denominator, and should not: a dental office has no business adopting laboratory policies. The fraction is there to show movement, not to be finished.
Editing is the workflow, not the exception.
The starter opens as editable content, because the product's position is that an unedited policy is not a policy. Revising a policy produces a version rather than replacing the previous one, which is what makes §164.316(b)(2)'s clock — six years from creation or last effective date — a question you can answer.
Lock, and every change after it is a versioned edit.
An adopted policy can be locked. After that the document is not simply editable — subsequent changes are tracked as versioned edits with an audit trail behind them, so the set has a governed state rather than being a folder anyone can quietly rewrite. This is the difference between having policies and being able to say what your policy was on a particular date, which is the only version of the question that has ever mattered in an investigation.
Drift arrives as work.
Policies not yet adopted, policies overdue for review, and policies lacking workforce acknowledgment are picked up in the nightly Compliance Advice pass and surface as items coded PO-, alongside everything else you owe. This is the mechanism that separates a living policy set from a binder: the binder never tells you it has gone stale.
Acknowledgment is a workforce fact, not a signature page.
The set connects to your roster, so an adopted policy has a list of who has acknowledged it and who has not — and the gap becomes its own advice item. §164.530(b) asks you to train workforce members on your policies; a policy the workforce has never read is a training failure and a policy failure at the same time.
Who this is for
Built for the practices that need it most.
Practices that downloaded a template pack and stopped.
This is the most common position and it is not a failure of effort. A template pack solves the acquisition problem and leaves the entire maintenance problem untouched, which is the half that gets practices into trouble.
Practices whose policies describe a different office.
Staff changed, a system was replaced, the practice moved or added a location. The policy set describes the practice as it was, and nobody has read it since. §164.316(b)(2)(iii) is specifically about this, and it is the provision most practices do not know exists.
Practices being asked for them right now.
A vendor's security review, a payer, an acquiring group, or OCR. The ask is always for the current set with dates on it, and the scramble that follows is the reason to have a system rather than a folder.
What you get
6 outcomes you'll feel in week one.
Coverage from day one.
48 starters, each naming its provision.
What and how, kept apart.
Separate policy and procedure fields force the second question.
Adoption you can see.
Adopted against what is recommended for your practice type.
Lock after adoption.
Later changes become versioned edits with an audit trail.
Versions, not overwrites.
Which makes the six-year clock a date you can produce.
Staleness becomes work.
Overdue reviews and missing acknowledgments arrive in the queue.
Can I adopt the starters as they are?
How is this different from a HIPAA policy template pack?
Why does my adopted count not reach the total?
How often do policies need reviewing?
Do we need Privacy Rule policies as well as Security Rule ones?
Does having these policies make us compliant?
What it does not do.
- Starter content is a starting point, not a compliance guarantee — the practice adopts and maintains its own policies
Continue exploring
Related features in the platform.
System
Autonomous Compliance Engine
Your practice state produces the next thing worth doing — from the assessment, but also from a lapsing BAA, a policy change, a new workforce member. Work closes when its conditions are met, and closing it changes the state.
Learn moreOperations
Workforce & Access Governance
A workforce record carries the roles a person holds, whether they may reach ePHI, and the specific systems they can touch. One place, one answer, dated.
Learn moreOperations
Compliance Evidence & Records
The question is almost never whether the practice did the work. It is whether the practice can produce what the work generated — and do it this week rather than after a month of archaeology.
Learn moreStarters that name their provision, and a set that tells you when it has drifted.
Most practices adopt their first policies in the opening week. The part that pays off is the review that lands eleven months later without anyone remembering to schedule it.
