Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

Operations · Policies & Procedures

A policy set is not a document you write once. It is one you keep.

Starters pinned to the provisions they answer, separate fields for what you do and how you do it, and a set that tells you when it has drifted out of date.

Included in Basic·

HIPAA mapping

Where this fits in the HIPAA rules.

4 provisions this capability contributes to, each with the specific Policies & Procedures behavior behind it. The obligation stays with your practice — the mapping shows which part of the work the platform carries.

§164.316(a)

Policies and procedures

Requires reasonable and appropriate policies and procedures for the Security Rule's standards, taking your size, complexity and capabilities into account. Reasonable and appropriate for a four-person practice is not what it is for a hospital, which is exactly why a starter has to be edited before it means anything.

§164.316(b)(1)

Documentation

Requires those policies and procedures to be maintained in writing. Written and retrievable are different states, and the second is the one that matters when someone asks to see them.

§164.316(b)(2)(iii)

Updates

Requires periodic review and updating in response to environmental or operational changes affecting ePHI security. A policy set is a living document by regulation, not by best practice — this is the provision people are surprised by.

§164.530(i)

Privacy Rule policies and procedures

The Privacy Rule's parallel obligation, covering uses and disclosures of PHI. The two rules ask for different policy sets, and a practice that has addressed only the Security Rule has done half.

What it does

Everyone has policies. Almost nobody has current ones.

The usual shape of this is a binder or a folder, assembled during a compliance push two or three years ago, mostly downloaded, lightly edited, and never opened since. It satisfies the version of the question a practice asks itself — do we have policies — while failing the version an investigator asks, which is whether they describe what the practice actually does and when they were last reviewed.

Policies & Procedures starts you from 48 starters, each pinned to the provision it answers, so the set has coverage before you have written a word. What it then does is the part that matters: it treats the set as something with a state. Policies you have adopted, policies you have not, policies overdue for review, policies nobody on the workforce has acknowledged.

The boundary is worth putting up front rather than in a footnote. Starter text is a starting point. It describes a generic practice, and yours is not generic — your systems, your staffing, your specialty and your physical space all belong in it. Adopting a starter unedited produces a policy that is written down and untrue, which in an investigation is a worse position than having none, because you have documented a control you do not operate.

How it works

7 mechanisms keep Policies & Procedures working.

01

48 starters, each pinned to a citation.

Every starter names the provision it exists to answer, which turns the set from a pile of documents into a map. When you are looking at a gap you can see which provision is uncovered rather than guessing whether the thing you are missing is a policy you have never heard of.

02

Policy and procedure are separate fields.

A policy states what your practice does and why. A procedure states how, and who. Most templates blur them into one document, which is how you end up with a policy nobody can follow and a procedure that nobody can trace to a rule. Keeping them apart forces the second question — you have said workstations are locked when unattended, now say by whom, using what, and what happens when they are not.

03

Adopted against a recommended set.

The Scoreboard shows adoption as a fraction — adopted over the number recommended for your practice type — rather than as a percentage of a fixed library. Most practices will never reach the denominator, and should not: a dental office has no business adopting laboratory policies. The fraction is there to show movement, not to be finished.

04

Editing is the workflow, not the exception.

The starter opens as editable content, because the product's position is that an unedited policy is not a policy. Revising a policy produces a version rather than replacing the previous one, which is what makes §164.316(b)(2)'s clock — six years from creation or last effective date — a question you can answer.

05

Lock, and every change after it is a versioned edit.

An adopted policy can be locked. After that the document is not simply editable — subsequent changes are tracked as versioned edits with an audit trail behind them, so the set has a governed state rather than being a folder anyone can quietly rewrite. This is the difference between having policies and being able to say what your policy was on a particular date, which is the only version of the question that has ever mattered in an investigation.

06

Drift arrives as work.

Policies not yet adopted, policies overdue for review, and policies lacking workforce acknowledgment are picked up in the nightly Compliance Advice pass and surface as items coded PO-, alongside everything else you owe. This is the mechanism that separates a living policy set from a binder: the binder never tells you it has gone stale.

07

Acknowledgment is a workforce fact, not a signature page.

The set connects to your roster, so an adopted policy has a list of who has acknowledged it and who has not — and the gap becomes its own advice item. §164.530(b) asks you to train workforce members on your policies; a policy the workforce has never read is a training failure and a policy failure at the same time.

Who this is for

Built for the practices that need it most.

Practices that downloaded a template pack and stopped.

This is the most common position and it is not a failure of effort. A template pack solves the acquisition problem and leaves the entire maintenance problem untouched, which is the half that gets practices into trouble.

Practices whose policies describe a different office.

Staff changed, a system was replaced, the practice moved or added a location. The policy set describes the practice as it was, and nobody has read it since. §164.316(b)(2)(iii) is specifically about this, and it is the provision most practices do not know exists.

Practices being asked for them right now.

A vendor's security review, a payer, an acquiring group, or OCR. The ask is always for the current set with dates on it, and the scramble that follows is the reason to have a system rather than a folder.

What you get

6 outcomes you'll feel in week one.

Coverage from day one.

48 starters, each naming its provision.

What and how, kept apart.

Separate policy and procedure fields force the second question.

Adoption you can see.

Adopted against what is recommended for your practice type.

Lock after adoption.

Later changes become versioned edits with an audit trail.

Versions, not overwrites.

Which makes the six-year clock a date you can produce.

Staleness becomes work.

Overdue reviews and missing acknowledgments arrive in the queue.

FAQ

What people ask first.

6 questions cover most first-time evaluations. See all FAQs →

Can I adopt the starters as they are?
You can, and you should not. A starter describes a generic practice; the provision asks for policies that are reasonable and appropriate for yours, taking your size, complexity and capabilities into account. An unedited policy that describes controls you do not operate is worse than a missing one, because in an investigation you have documented the gap yourself.
How is this different from a HIPAA policy template pack?
A template pack is a one-time acquisition. This is the maintenance: which policies you have adopted, when each was last reviewed, which versions preceded the current one, and who on the workforce has acknowledged them. If you only need the documents, our policy templates guide covers that ground and asks nothing of you.
Why does my adopted count not reach the total?
Because it is not meant to. The denominator is the set recommended for your practice type, and some of it will not apply to you — laboratory policies in a dental office, for instance. The number is there to show direction. A practice that adopted everything on the list to make the fraction look complete would have made its policy set less accurate, not more.
How often do policies need reviewing?
The Security Rule does not name an interval. §164.316(b)(2)(iii) requires periodic review and updating in response to environmental or operational changes affecting the security of ePHI, which means the trigger is change rather than the calendar — a new system, a new location, a departure, an incident. Many practices settle on an annual cadence as a floor and review out of band when something moves.
Do we need Privacy Rule policies as well as Security Rule ones?
Yes, and this is a common gap. §164.316 is the Security Rule's policy standard; §164.530(i) is the Privacy Rule's, covering uses and disclosures of PHI. They are separate obligations covering separate ground, and a practice that has addressed only the technical safeguards has done part of the job.
Does having these policies make us compliant?
No. Written policies are one of the things the rules require, and they are evidence of intent rather than evidence of practice. What makes a policy set worth anything is that it describes what the office really does, that the workforce knows it, and that it changes when the office does. The product can hold and track it; operating it is the practice's work.

What it does not do.

  • Starter content is a starting point, not a compliance guarantee — the practice adopts and maintains its own policies

Starters that name their provision, and a set that tells you when it has drifted.

Most practices adopt their first policies in the opening week. The part that pays off is the review that lands eleven months later without anyone remembering to schedule it.