Policy Reference

HIPAA Written Policies Every Practice Needs

HIPAA requires covered entities and business associates to maintain written policies and procedures. This page lists every policy category the regulation calls for, organized by regulatory category, with the CFR sections behind each one.

Why Written Policies Are Required

Two separate HIPAA provisions create the written policy requirement. Under the Security Rule, 45 CFR 164.316(a) requires covered entities and business associates to implement reasonable and appropriate policies and procedures to comply with the standards and implementation specifications of Subpart C. Under the Privacy Rule, 45 CFR 164.530(i) requires covered entities to develop and implement written privacy policies and procedures consistent with the Privacy Rule's requirements.

Both provisions also require a retention period. Under 45 CFR 164.530(j), covered entities must retain all policies and procedures for six years from the date of creation or the date when the policy was last in effect, whichever is later. The Security Rule carries the same six-year retention requirement under 45 CFR 164.316(b)(2)(i).

Having no written policies is the second most commonly cited deficiency in OCR enforcement actions, behind only the absence of a Security Risk Assessment. If OCR investigates your practice, your written policies are among the first documents they request.

How Many Policies Does Your Practice Need?

Most small practices need 20 to 35 written policies across administrative, physical, and technical safeguards plus Privacy Rule and breach notification requirements. The exact number depends on how your practice operates: what systems you use, how many locations you have, whether you handle specialty records, and which vendor relationships involve PHI.

HIPAA does not prescribe an exact number of policies. What it requires is that every applicable standard and implementation specification be addressed in writing. Some organizations consolidate related requirements into fewer documents. Others maintain separate policies for each safeguard. Either approach can satisfy the regulation as long as every requirement is covered.

If you need help determining which policies apply to your practice, a HIPAA gap analysis identifies exactly where your documentation falls short. If you already know what you need and want ready-to-customize documents, see our HIPAA policy templates and documentation services.

Administrative Safeguard Policies

Administrative safeguards are the management actions, policies, and procedures that form the backbone of your compliance program. These typically represent the largest group of required written policies.

Security Management Process

45 CFR 164.308(a)(1)

Documents how your organization identifies risks, implements safeguards, and manages the overall security program. Includes your risk analysis methodology and remediation tracking procedures.

Security Rule implementation guide
Workforce Security

45 CFR 164.308(a)(3)

Defines authorization and supervision procedures for workforce members who access ePHI. Covers onboarding access provisioning, role changes, and clearance procedures.

Workforce termination procedures
Information Access Management

45 CFR 164.308(a)(4)

Establishes how your practice authorizes access to ePHI. Defines who approves access requests, how access levels are determined, and how access is documented.

ePHI access control best practices
Security Awareness and Training

45 CFR 164.308(a)(5)

Requires training for all workforce members before they access PHI, with periodic refreshers. Must cover security reminders, malicious software protection, login monitoring, and password management.

Essential HIPAA training topics · Training modules & completion documentation
Security Incident Procedures

45 CFR 164.308(a)(6)

Documents how your practice identifies, responds to, mitigates, and documents security incidents. Defines what constitutes a security incident and establishes reporting chains.

Incident management guide
Contingency Plan

45 CFR 164.308(a)(7)

Covers data backup, disaster recovery, and emergency mode operations. Documents how your practice continues to operate and protect ePHI during emergencies or system failures.

Ransomware protection for healthcare
Business Associate Contracts

45 CFR 164.308(b)

Requires written agreements with every vendor or subcontractor that creates, receives, maintains, or transmits PHI on your behalf. Defines the content and management of BAAs.

What is a Business Associate Agreement?
Sanctions Policy

45 CFR 164.308(a)(1)(ii)(C)

Documents the consequences for workforce members who violate your security policies. Must define a range of sanctions proportionate to the severity of the violation.

Physical Safeguard Policies

Physical safeguards protect the physical infrastructure — buildings, equipment, and media — that stores or accesses ePHI.

Facility Access Controls

45 CFR 164.310(a)

Defines how physical access to facilities containing ePHI is limited and controlled. Covers contingency operations, facility security plans, access control and validation, and maintenance records.

Physical safeguards requirements
Workstation Use and Security

45 CFR 164.310(b) & (c)

Documents the acceptable uses of workstations that access ePHI and the physical safeguards applied to those workstations. Includes screen lock requirements, positioning rules, and clean desk policies.

Device and Media Controls

45 CFR 164.310(d)

Governs the receipt, removal, movement, and disposal of hardware and electronic media containing ePHI. Covers data disposal methods, media reuse procedures, and device accountability tracking.

Mobile device security in healthcare

Technical Safeguard Policies

Technical safeguards are the technology and related policies that protect ePHI and control access to it.

Access Control

45 CFR 164.312(a)

Defines the technical measures used to restrict access to ePHI: unique user identification, emergency access procedures, automatic logoff, and encryption of data at rest.

ePHI access control best practices
Audit Controls

45 CFR 164.312(b)

Documents the mechanisms for recording and examining activity in information systems that contain or access ePHI. Defines what is logged, how long logs are retained, and who reviews them.

Integrity Controls

45 CFR 164.312(c)

Establishes how your practice protects ePHI from improper alteration or destruction. Includes mechanisms to authenticate that ePHI has not been altered or destroyed in an unauthorized manner.

Person or Entity Authentication

45 CFR 164.312(d)

Documents the procedures used to verify that a person or entity seeking access to ePHI is who they claim to be. Covers password requirements, multi-factor authentication, and identity verification.

MFA requirements in plain English
Transmission Security

45 CFR 164.312(e)

Defines the measures used to guard against unauthorized access to ePHI during electronic transmission. Covers encryption standards, secure email, VPN requirements, and integrity controls for data in transit.

Encryption requirements for 2026

Privacy Rule Policies

Privacy Rule policies govern how your practice uses and discloses PHI in all forms — not just electronic. These are required of covered entities under 45 CFR 164.530(i).

Notice of Privacy Practices

45 CFR 164.520

The NPP is both a document and a process. It describes how your practice uses and discloses PHI, explains patient rights, and must be provided at first service delivery. It must be posted in your facility and on your website.

Notice of Privacy Practices guide
Minimum Necessary Standard

45 CFR 164.502(b)

Documents your procedures for limiting PHI use, disclosure, and requests to the minimum amount necessary to accomplish the intended purpose. Applies to most uses except treatment, payment with patient authorization, and disclosures required by law.

Minimum necessary rule explained
Patient Rights Procedures

45 CFR 164.524–164.528

Covers the right to access records, request amendments, receive an accounting of disclosures, request restrictions, and request confidential communications. Each right requires a documented process.

Patient rights provider guide
Authorization Policy

45 CFR 164.508

Defines when your practice requires a written authorization before using or disclosing PHI, what elements the authorization must contain, and how revocations are handled.

Authorization form requirements
De-Identification Procedures

45 CFR 164.514

Documents how your practice removes identifying information from health data when using PHI for research, analytics, or other secondary purposes. Covers both the Safe Harbor and Expert Determination methods.

De-identification requirements

Breach Notification Policies

Breach notification policies document your procedures for identifying, investigating, and reporting breaches of unsecured PHI. These are required by the Breach Notification Rule.

Breach Identification and Risk Assessment

45 CFR 164.402

Defines what constitutes a breach, how potential breaches are identified and reported internally, and how the four-factor risk assessment is performed to determine whether notification is required.

Breach notification rule compliance
Individual Notification Procedures

45 CFR 164.404

Documents the process for notifying affected individuals within 60 days of discovery. Covers notification content, delivery methods, substitute notice procedures for insufficient contact information, and media notice for breaches affecting 500+ individuals.

Data breach response plan
HHS and Media Notification

45 CFR 164.406 & 164.408

Documents the procedures for notifying the Secretary of HHS and prominent media outlets when required. Breaches affecting 500+ individuals require notification to HHS and media within 60 days. Smaller breaches are logged and reported annually.

Specialty-Specific Policy Considerations

Some practice types require additional policies beyond the standard set. If your organization falls into one of these categories, your policy library should account for these specialty requirements.

  • Dental practices — digital imaging retention, shared operatory access controls, and policies for portable x-ray equipment that moves between operatories or locations.
  • Behavioral health providers — psychotherapy notes receive heightened protection under 45 CFR 164.508(a)(2). Substance abuse treatment records may also fall under 42 CFR Part 2, requiring additional consent and disclosure policies.
  • Business associates — must maintain their own independent set of Security Rule policies, not just rely on the covered entity's policies. Also need subcontractor BAA management procedures.
  • Pharmacies — additional policies for controlled substance record handling, prescription transfer procedures, and telephonic/electronic prescription verification.

What Makes a Policy Actually Compliant?

Having a policy on paper is not enough. OCR has cited organizations for maintaining policies that did not reflect actual operations. Under 45 CFR 164.316(b)(2)(i), policies must be tailored to the size, complexity, and capabilities of the organization. A compliant policy includes:

  • A specific CFR citation — identifies which regulatory requirement the policy addresses.
  • A named responsible party — the person accountable for implementation and enforcement.
  • Defined scope — which workforce members, systems, or locations the policy covers.
  • Procedures that match actual workflows — not generic template language, but steps your staff actually follow.
  • A review date and version history — demonstrating periodic review as required by 45 CFR 164.316(b)(2)(iii).
  • Staff acknowledgment records — evidence that workforce members received and understood the policy.

If you are starting from scratch, begin with the HIPAA starting point guide to understand the sequence. If you need customized policies written for your practice, our policy template and documentation services include implementation guidance and staff acknowledgment tracking.

Frequently Asked Questions

HIPAA requires written policies and procedures under the Security Rule (45 CFR 164.316(a)) and Privacy Rule (45 CFR 164.530(i)). These span administrative safeguards (security management, workforce training, access authorization, incident response, contingency planning), physical safeguards (facility access, workstation use, device controls), technical safeguards (access control, audit controls, transmission security), Privacy Rule requirements (Notice of Privacy Practices, minimum necessary, patient rights, authorization), and breach notification procedures. Most small practices need 20 to 35 written policies across these categories.

A typical small practice with 1 to 25 staff members generally needs 20 to 35 written policies. The exact number depends on how your practice operates, what systems you use, and whether you handle specialized records such as substance abuse treatment or psychotherapy notes. Some organizations consolidate related requirements into fewer documents while others maintain separate policies for each safeguard.

Templates can provide a starting structure, but 45 CFR 164.316(b)(2)(i) requires policies to be tailored to the size, complexity, and capabilities of your organization. A generic template that does not reflect your actual workflows, systems, and workforce roles does not satisfy this requirement. OCR has cited organizations for having policies that existed on paper but did not match how the practice actually operated.

Under 45 CFR 164.530(j), covered entities must retain all policies for six years from the date of creation or the date when the policy was last in effect, whichever is later. The Security Rule has the same six-year retention requirement under 45 CFR 164.316(b)(2)(i). This means you must keep superseded versions, not just the current ones.

Under 45 CFR 164.316(b)(2)(iii), policies must be updated periodically in response to environmental or operational changes that affect the security of ePHI. Most compliance programs review all policies at least annually. Also update policies when you add new systems, change vendors, experience a security incident, modify workflows, or undergo significant staffing changes. Organizations should consult legal counsel for guidance specific to their situation.

Learn More About HIPAA Policies and Compliance

Not Sure Which Policies Your Practice Is Missing?

A 30-minute call with a Certified HIPAA Professional can identify your documentation gaps and outline the fastest path to close them.

Book Your Free HIPAA Compliance Review