Six years. That is how long you must retain every version of every written policy, every risk analysis, every sanction record, and every signed acknowledgment your practice produces under HIPAA. Not six years from when you wrote it — six years from the date of creation or the date it was last in effect, whichever is later. Most practices discover this the week a records request arrives. This article walks through the HIPAA policies and procedures a covered entity must actually hold in writing, who inside the practice owns each one, and what the documented evidence looks like when someone outside your office asks to see it.

What HIPAA Policies and Procedures Must Cover

HIPAA does not publish a checklist of policy titles. It publishes obligations, and each obligation implies a written policy plus a procedure describing how your workforce carries it out. At minimum, a covered entity must maintain written policies and procedures addressing:

  • Privacy Rule obligations — uses and disclosures, minimum necessary, patient rights (access, amendment, accounting of disclosures, restrictions, confidential communications), notice of privacy practices, authorizations, personal representatives, complaints, sanctions, and mitigation.
  • Security Rule safeguards — risk analysis and risk management, workforce security and sanctions, information system activity review, security incident response, contingency planning, device and media controls, facility access, access control, audit controls, integrity, authentication, and transmission security.
  • Breach notification — discovery, risk assessment, individual and HHS notification, media notification, and business associate reporting duties.
  • Business associate management — vendor identification, contracting, and monitoring.
  • Documentation practices — how policies are approved, distributed, reviewed, updated, and retained for six years.

Every one of those must exist in writing, be available to the workforce members expected to follow it, and be reviewed as your environment changes.

The Documentation Rule Nobody Reads: 45 CFR 164.316

The Security Rule's documentation standard is short and it is the provision that turns a folder of PDFs into either evidence or a liability. It requires three things: keep policies and procedures in written (which may be electronic) form; retain that documentation for six years from creation or last effective date; make it available to the people responsible for implementing it; and review it periodically, updating in response to environmental or operational changes.

Read the last clause again. "Environmental or operational changes" means the new patient portal you turned on in March, the two front-desk hires in June, the imaging vendor you swapped in September, and the move to a second suite. Each of those is a trigger. A policy set with a 2019 approval date and no change log since then documents that you stopped paying attention.

The Privacy Rule carries a parallel requirement at 45 CFR 164.530, which also obligates you to designate a privacy official, train the workforce, apply sanctions, and mitigate known harmful effects of improper disclosures. HHS keeps the current regulation text and guidance collected on its HIPAA Security Rule page and its Privacy Rule page.

Your Privacy Rule Policy Set

The documents most practices already have

Notice of privacy practices. A patient access procedure. An authorization form. A complaint form. Most offices can produce these within an hour. Note that the notice of privacy practices changes tied to alignment with 42 CFR Part 2 substance use disorder records carry a February 16, 2026 compliance date — if your practice handles Part 2 records or receives them, your NPP revision belongs on the calendar now, not in February.

The documents most practices are missing

These are the ones that produce findings:

  • Designated record set definition. A written list of which systems and files make up the record set you must produce on a patient access request. Without it, your 30-day access response is improvised.
  • Minimum necessary by role. A table mapping job titles to the PHI each may access. "Everyone sees everything" is a finding, not a configuration.
  • Verification of identity and authority. How the front desk confirms a caller is the patient, and how you evaluate a personal representative claim.
  • Sanctions policy with a graduated schedule. Written consequences, plus records showing you applied them at least once when something happened.
  • Restriction on disclosure to a health plan when the patient pays out of pocket in full — a mandatory right under 164.522, and one your billing workflow has to be able to honor.
  • Accounting of disclosures procedure and the log that supports it.

Your Security Rule Policy Set

Administrative safeguards

The anchor is the risk analysis. Everything else in your security policy set should trace back to a documented risk finding and a documented decision. You need written procedures for security management, assigned security responsibility, workforce clearance and termination, access authorization and modification, security awareness training, log review, incident response and reporting, contingency planning with data backup and disaster recovery, and periodic evaluation.

The distinction between required and addressable implementation specifications trips people up. Addressable does not mean optional. It means you either implement it, implement an equivalent alternative, or document why it is not reasonable and appropriate in your environment. That third path is a written analysis, not a shrug. NIST's SP 800-66 Revision 2 maps each Security Rule specification to concrete practices and is the most useful free reference for building this section. Note also that HHS proposed significant Security Rule amendments in January 2025 that would tighten many of these specifications; that rulemaking was still pending as of this writing, so build your policies against the current rule while tracking the proposal.

Physical safeguards

Facility access controls, workstation use and security, and device and media controls — including the sanitization and disposal procedure for the laptop your departing biller hands back. Write down who wipes it, with what method, and where the certificate of destruction goes.

Technical safeguards

Unique user IDs, emergency access, automatic logoff, encryption and decryption, audit controls, integrity controls, person or entity authentication, and transmission security. For a small practice these policies mostly describe how you configure your EHR and email — which means they must match reality. A policy stating 15-minute automatic logoff while every workstation is set to four hours is worse than no policy at all.

Breach Notification: The Policy That Gets Tested Under Pressure

Your breach procedure has to work on the worst day of the year, executed by whoever is on site. Build it around the clocks:

  • Discovery — the clock starts on the first day the incident is known, or would have been known with reasonable diligence, by anyone in the workforce other than the person who caused it.
  • Four-factor risk assessment — nature and extent of PHI, who received it, whether it was actually acquired or viewed, and the extent to which risk was mitigated. Document all four in writing, even when you conclude notification is required.
  • Individual notice — without unreasonable delay and no later than 60 calendar days from discovery.
  • 500 or more residents of a state or jurisdiction — HHS notice and media notice within the same 60 days.
  • Fewer than 500 — log the incident and report to HHS within 60 days after the end of the calendar year. For incidents discovered during 2025, that submission window closes March 1, 2026.
  • Business associate discovery — your BAA should require notice to you fast enough that you can still meet your own 60-day deadline. Sixty days from the BA to you leaves you zero.

Reading a few dozen entries on the OCR breach portal is a fast education in which failure modes are common in practices your size. Most are not exotic attacks. They are unencrypted devices, misdirected mailings, and vendors nobody had a signed agreement with.

Who Signs, Who Owns, Who Trains

A policy with no named owner does not get maintained. Assign every document to a person by title:

  • Privacy Officer — NPP, patient rights procedures, authorizations, complaint intake, accounting of disclosures, minimum necessary role table.
  • Security Officer — risk analysis, risk management plan, all technical and physical safeguard procedures, log review, incident response.
  • Practice Administrator / Owner — final approval and signature on the policy set, sanctions decisions, budget for remediation.
  • HR or office manager — onboarding and termination checklists, training completion tracking, confidentiality agreements.
  • Billing lead — cash-pay restriction handling, clearinghouse and RCM vendor agreements.

In a five-person clinic one human may hold three of these roles. That is fine. Write down which hat applies to which decision so coverage is documented when that person is on vacation.

What the Evidence Actually Looks Like

When OCR sends a data request, or a hospital's third-party risk team sends a questionnaire, they are not asking whether you believe you are compliant. They are asking for artifacts. Have these ready:

  1. Signed approval page on each policy — version number, effective date, approver name and title.
  2. Change log showing what was revised, when, and why (the trigger event).
  3. Distribution and attestation records — dated acknowledgments from each workforce member, including new hires within their first weeks.
  4. Training records — who, what curriculum, what date, how long, and evidence of any role-specific modules.
  5. Risk analysis report with scope, asset inventory, threat and vulnerability findings, and likelihood/impact ratings — plus a risk management plan with owners and target dates showing what you did about the findings.
  6. Business associate inventory with signed agreements, execution dates, and services described.
  7. Incident log including incidents you determined were not breaches, with the four-factor analysis attached.
  8. Sanction records and termination checklists showing access was revoked on the separation date.

Assembling that set from scratch is where most practices stall, because the risk analysis has to exist before the policies can honestly reference it. If you are starting from an empty folder or a decade-old binder, generating a scoped risk analysis and a matching policy set is exactly the work that HIPAA compliance documentation software is built to compress — it produces the risk analysis report, the policy library, and the supporting document set as one internally consistent package rather than a pile of unrelated templates. If your immediate gap is the vendor paperwork, you can also produce a signature-ready business associate agreement and get it out to the vendor this week.

The Annual Review Calendar That Keeps This Alive

Pick fixed months and put them on the practice calendar with a named owner:

  • January — review and re-approve the full policy set; increment version numbers even when text is unchanged, and record the review date.
  • February — submit the prior year's small-breach log to HHS by March 1.
  • April — refresh the business associate inventory; confirm every vendor touching PHI has a current signed agreement.
  • July — annual workforce training plus attestation collection.
  • October — risk analysis update, contingency plan test, and one tabletop walkthrough of the breach procedure.
  • Any time — new system, new location, new vendor, or a security incident triggers an off-cycle review of the affected policies within 30 days.

HHS has published summaries of what its audit program examined and where entities fell short; the HIPAA Audit Program page is worth reading before you assume your documentation would hold up.

Four Ways Template Policies Fail

They name a role you do not have. A policy referencing your "Information Security Committee" in a four-provider practice signals the document was never customized.

They contradict your configuration. Auditors compare the written control to the system setting. Mismatches are findings.

They reference a risk analysis that does not exist. This is the single most common gap and the one most frequently cited in enforcement. A policy set without a supporting risk analysis is a stack of assertions.

Nobody signed them. No approval date, no version, no distribution record. There is no way to prove the policy was in effect on the day the incident happened.

A 90-Day Path If You Are Behind

Days 1–30: Inventory what exists. List every system holding PHI and every vendor with access. Name your Privacy Officer and Security Officer in writing. Complete or refresh the risk analysis — everything downstream depends on it.

Days 31–60: Draft or revise the policy set against your actual environment. Build the risk management plan with owners and dates. Close BAA gaps. Fix the three highest-risk technical findings, whatever they are.

Days 61–90: Owner signs and dates the policy set. Distribute and collect attestations. Run training. Walk the breach procedure as a tabletop and revise what did not work. File everything in one location with a retention date six years out.

Your HIPAA policies and procedures are the record of decisions you made about protecting patient information — and the only thing that speaks for your practice when an incident is already underway. If yours are missing, stale, or borrowed from a template that names roles you do not have, generate a current risk analysis and matching policy set and get the owner's signature on it before January closes.