1. Establish and communicate privacy policies and procedures.
Organizations should establish privacy policies and procedures and communicate them to employees. Employees should be trained on how to protect patient privacy.
2. Implement safeguards to protect electronic health information.
Organizations should implement safeguards to protect electronic health information, such as firewalls, passwords, and encryption.
3. Implement safeguards to protect paper health information.
Organizations should also implement safeguards to protect paper health information, such as locked filing cabinets and shredding documents when they are no longer needed.
4. Conduct risk assessments.
Organizations should conduct risk assessments to identify and mitigate risks to patient privacy.
5. Identify and respond to threats and vulnerabilities.
Organizations should identify and respond to threats and vulnerabilities in order to protect patient data.
6. Report breaches of protected health information.
Organizations should report any breaches of protected health information so that they can be addressed quickly.
7. Maintain documentation of HIPAA compliance activities.
Organizations should maintain documentation of their HIPAA compliance activities so that they can show that they are meeting HIPAA requirements.