Policy Reference

HIPAA Written Policies Every Practice Needs

HIPAA requires covered entities and business associates to maintain written policies and procedures. This page lists every policy category the regulation calls for, organized by regulatory category, with the CFR sections behind each one.

Why Written Policies Are Required

Two parts of HIPAA say your policies have to be in writing. The first is the Security Rule. Under 45 CFR 164.316(a), a covered entity or business associate must put in place policies and procedures that are reasonable, and that meet the standards and implementation specifications in Subpart C. The second is the Privacy Rule. Under 45 CFR 164.530(i), a covered entity must write privacy policies and procedures that line up with what that rule asks for.

Both parts also say how long you have to keep them. Under 45 CFR 164.530(j), a covered entity must hold on to every policy and procedure for six years. The clock starts the day you wrote it, or the last day it was in force, whichever comes later. The Security Rule sets the same six-year mark under 45 CFR 164.316(b)(2)(i).

No written policies is the second most common gap OCR cites when it takes action. Only a missing Security Risk Assessment shows up more often. If OCR looks into your practice, your written policies are one of the first things they ask to see.

How Many Policies Does Your Practice Need?

Most small practices need 20 to 35 written policies. They span the three safeguard groups, plus the Privacy Rule and breach notification. Your own count turns on how you work. What systems do you use? How many sites do you run? Do you hold specialty records? Which of your vendors touch PHI?

HIPAA does not name a number. It asks you to put every standard and implementation specification that applies to you in writing. Some practices roll a few of them into one document. Others keep a separate policy for each safeguard. Both ways work, as long as you leave nothing out.

Not sure which policies apply to you? A HIPAA gap analysis shows you what you are missing. If you know what you need and want documents you can edit, see our HIPAA policy templates and documentation services.

Administrative Safeguard Policies

Administrative safeguards are the steps you take to run the program: who does what, and how. They make up the largest group of policies you have to write.

Security Management Process

45 CFR 164.308(a)(1)

Says how you spot risk, put safeguards in place, and run the program day to day. It holds your risk analysis method and the way you track fixes.

Security Rule implementation guide
Workforce Security

45 CFR 164.308(a)(3)

Says how you clear and watch over workforce members who can reach ePHI. It covers what a new hire gets, what shifts when a role changes, and how you close access out.

Workforce termination procedures
Information Access Management

45 CFR 164.308(a)(4)

Sets out how you grant access to ePHI. Who signs off on a request? What level do they get? Where do you write it down?

ePHI access control best practices
Security Awareness and Training

45 CFR 164.308(a)(5)

Calls for training for all workforce members before they touch PHI, and again on a set cycle. It has to cover security reminders, guarding against bad software, watching log-ins, and how you handle passwords.

Essential HIPAA training topics · Training modules & completion documentation
Security Incident Procedures

45 CFR 164.308(a)(6)

Says how you spot a security incident, what you do about it, how you hold down the harm, and where you write it down. It also says what counts as one, and who tells whom.

Incident management guide
Contingency Plan

45 CFR 164.308(a)(7)

Covers backups, getting back up after a disaster, and how you run in an emergency. It says how you keep working, and keep ePHI safe, when systems go down.

Ransomware protection for healthcare
Business Associate Contracts

45 CFR 164.308(b)

Calls for a signed deal with every vendor or subcontractor that creates, receives, maintains, or transmits PHI for you. Cloud tools like Google Workspace count. It says what goes in a BAA, and how you keep track of them.

What is a Business Associate Agreement?
Sanctions Policy

45 CFR 164.308(a)(1)(ii)(C)

Says what happens to workforce members who break your security policies. It has to set a range of sanctions that fits how serious the act was.

Physical Safeguard Policies

Physical safeguards protect the things you can touch: your building, your gear, and your media, wherever ePHI is held or reached.

Facility Access Controls

45 CFR 164.310(a)

Says how you limit who can walk into a space that holds ePHI. It covers backup plans, your facility security plan, how you check people at the door, and the records you keep on repairs.

Physical safeguards requirements
Workstation Use and Security

45 CFR 164.310(b) & (c)

Says what a workstation that reaches ePHI may be used for, and how you guard it. That takes in screen locks, where the screen faces, and a clean desk rule.

Device and Media Controls

45 CFR 164.310(d)

Covers what you do when hardware or media that holds ePHI comes in, moves, leaves, or gets thrown out. It says how you wipe data, how you reuse media, and how you track each device.

Mobile device security in healthcare

Technical Safeguard Policies

Technical safeguards are the tech itself, plus the rules around it, that keep ePHI safe and control who can reach it.

Access Control

45 CFR 164.312(a)

Says what you use to limit who can reach ePHI: a unique user ID for each person, a way in during an emergency, auto log-off, and encryption for data at rest.

ePHI access control best practices
Audit Controls

45 CFR 164.312(b)

Says how you record and review what happens in systems that hold or reach ePHI. What goes in the log? How long do you keep it? Who reads it?

Integrity Controls

45 CFR 164.312(c)

Sets out how you keep ePHI from being changed or wiped when it should not be. It includes the way you prove a record is still what it was.

Person or Entity Authentication

45 CFR 164.312(d)

Says how you check that a person or entity asking to reach ePHI really is who they say. It covers what a password must look like, multi-factor sign-in, and how you prove who someone is.

MFA requirements in plain English
Transmission Security

45 CFR 164.312(e)

Says how you guard ePHI while it is on the move. It covers which encryption you use, safe email, when a VPN is needed, and how you know data was not changed on the way.

Encryption requirements for 2026

Privacy Rule Policies

Privacy Rule policies cover how you use and disclose PHI in every form, on paper and out loud, not just on a screen. A covered entity has to have them under 45 CFR 164.530(i).

Notice of Privacy Practices

45 CFR 164.520

The NPP is a document and a process at once. It lays out how you use and disclose PHI, spells out what rights a patient has, and has to be handed over the first time you treat someone. It also has to hang in your office and sit on your website.

Notice of Privacy Practices guide
Minimum Necessary Standard

45 CFR 164.502(b)

Says how you hold PHI use, disclosure, and requests to the minimum necessary for the job at hand. It applies to most uses. Treatment, payment with a patient authorization, and disclosures the law demands sit outside it.

Minimum necessary rule explained
Patient Rights Procedures

45 CFR 164.524–164.528

Covers a patient's right to see their records, ask for a change, get an accounting of disclosures, ask you to hold back, and ask you to reach them a certain way. Each one needs a written process.

Patient rights provider guide
Authorization Policy

45 CFR 164.508

Says when you need a written authorization before you use or disclose PHI, what has to be in that form, and what you do when a patient takes it back.

Authorization form requirements
De-Identification Procedures

45 CFR 164.514

Says how you strip out the details that point to a person before you use health data for research or other work. It covers both routes: Safe Harbor and Expert Determination.

De-identification requirements

Breach Notification Policies

These policies say how you spot, look into, and report a breach of unsecured PHI. The Breach Notification Rule calls for them.

Breach Identification and Risk Assessment

45 CFR 164.402

Says what counts as a breach, how staff spot one and pass it up the line, and how you run the four-factor risk assessment that tells you whether you have to notify.

Breach notification rule compliance
Individual Notification Procedures

45 CFR 164.404

Says how you tell the people affected, within 60 days of the day you find out. It covers what the notice says, how you send it, what to do when you lack good contact details, and the media notice you owe when a breach hits 500 or more people.

Data breach response plan
HHS and Media Notification

45 CFR 164.406 & 164.408

Says how you notify the Secretary of HHS and, when the rule calls for it, the press. A breach that hits 500 or more people goes to HHS and the media within 60 days. You log the smaller ones and report them once a year.

Specialty-Specific Policy Considerations

Some practices need more than the standard set. If yours is one of them, plan for the extra policies below.

  • Dental practices — how long you keep digital images, who can get into a shared operatory, and rules for x-ray gear that moves from room to room or site to site.
  • Behavioral health providers — psychotherapy notes get extra shielding under 45 CFR 164.508(a)(2). Records of substance abuse treatment may also fall under 42 CFR Part 2, which calls for its own consent and disclosure policies.
  • Business associates — need their own set of Security Rule policies. Leaning on the covered entity's will not do. They also need a way to handle BAAs with their subcontractors.
  • Pharmacies — more policies for handling controlled substance records, moving a prescription from one place to another, and checking a script that came in by phone or online.

What Makes a Policy Actually Compliant?

A policy on paper is not enough. OCR has cited practices whose policies did not match how they really worked. Under 45 CFR 164.316(b)(2)(i), a policy has to fit the size of your practice, how complex it is, and what it can do. A policy that holds up has all of this:

  • A specific CFR citation — points to the rule in the CFR that it answers.
  • A named responsible party — the one person who owns it and makes it stick.
  • Defined scope — which workforce members, systems, or sites it covers.
  • Procedures that match actual workflows — not stock template text, but the steps your staff really take.
  • A review date and version history — proof you look at it on a cycle, as 45 CFR 164.316(b)(2)(iii) asks.
  • Staff acknowledgment records — proof each workforce member got it and read it.

This is also where our platform earns its keep. Policies are generated and tailored to your practice automatically, using what the system already learned about your organization from your Security Risk Assessment. Staff attestation of understanding is tracked per workforce member, so acknowledgment records exist before anyone asks for them. Jargon, be gone.

Starting from scratch? Begin with the HIPAA starting point guide to see the order things go in. If you want policies written for your practice, our policy template and documentation services come with setup help and a way to track staff sign-off. Our free HIPAA starter checklist shows what's required and in what order.

Frequently Asked Questions

HIPAA requires written policies and procedures under the Security Rule (45 CFR 164.316(a)) and Privacy Rule (45 CFR 164.530(i)). These span administrative safeguards (security management, workforce training, access authorization, incident response, contingency planning), physical safeguards (facility access, workstation use, device controls), technical safeguards (access control, audit controls, transmission security), Privacy Rule requirements (Notice of Privacy Practices, minimum necessary, patient rights, authorization), and breach notification procedures. Most small practices need 20 to 35 written policies across these categories.

A typical small practice with 1 to 25 staff members usually needs 20 to 35 written policies. The exact number depends on how your practice operates, what systems you use, and whether you handle specialized records such as substance abuse treatment or psychotherapy notes. Some businesses consolidate related requirements into fewer documents while others maintain separate policies for each safeguard.

Templates can provide a starting structure, but 45 CFR 164.316(b)(2)(i) requires policies to be tailored to the size, complexity, and capabilities of your business. A generic template that does not reflect your actual workflows, systems, and workforce roles does not satisfy this requirement. OCR has cited businesses for having policies that existed on paper but did not match how the practice actually operated.

Under 45 CFR 164.530(j), covered entities must retain all policies for six years from the date of creation or the date when the policy was last in effect, whichever is later. The Security Rule has the same six-year retention requirement under 45 CFR 164.316(b)(2)(i). This means you must keep superseded versions, not just the current ones.

Under 45 CFR 164.316(b)(2)(iii), policies must be updated periodically in response to environmental or operational changes that affect the security of ePHI. Most compliance programs review all policies at least annually. Also update policies when you add new systems, change vendors, experience a security incident, modify workflows, or undergo significant staffing changes. Organizations should consult legal counsel for guidance specific to their situation.

Learn More About HIPAA Policies and Compliance

Not Sure Which Policies Your Practice Is Missing?

A 30-minute call with a Certified HIPAA Professional can pin down what you are missing and map the fastest way to close it.

Book Your Free 30 Minute HIPAA Compliance Review