Skip to Content

HIPAA Privacy - Documentation 164.530(j)

Overview:
§164.530(j)(1)
Standard: Documentation.
A covered entity must: (i) Maintain the policies and procedures provided for in paragraph (i) of this section in written or electronic form; (ii) If a communication is required by this subpart to be in writing, maintain such writing, or an electronic copy, as documentation; and (iii) If an action, activity, or designation is required by this subpart to be documented, maintain a written or electronic record of such action, activity, or designation. (iv) Maintain documentation sufficient to meet its burden of proof under § 164.414(b).
(2) Implementation specification: Retention period. A covered entity must retain the documentation required by paragraph (j)(1) of this section for six years from the date of its creation or the date when it last was in effect, whichever is later.


Action Items:
1) Does the entity maintain all required policies and procedures, written communication, and documentation in written or electronic form? Are such documentations retained for the required time period?


Related Documents:
1) Policies and procedures, written communication, and documentation in written or electronic form


Additional Guidance:
A covered entity must maintain, until six years after the later of the date of their creation or last effective date, its privacy policies and procedures, its privacy practices notices, disposition of complaints, and other actions, activities, and designations that the Privacy Rule requires to be documented.