FirstHR

HIPAA Policies and Procedures: A Small Practice Guide

Which HIPAA policies and procedures you need, how a policy differs from a procedure, the six-year retention rule, and how to run them at a small practice.

Nick Anisimov

Nick Anisimov

FirstHR Founder

General
21 min

HIPAA Policies and Procedures

What the rules actually require, the minimum working set for a practice with no compliance department, what addressable really means, the retention rule that changes how you version documents, and where the proposed Security Rule update stands

Most guides on this topic are written by companies that sell you the documents at the end. That is not a criticism, it is just worth knowing while you read, because it shapes the answer. The message tends to be that you need 45 or 65 or 69 policies and that assembling them is a project.

The number is not the point. What an investigation asks is whether every applicable requirement is addressed in writing somewhere, whether the writing describes what you actually do, and whether you have records showing it happened. A practice with twenty well-organized policies that are true passes that test. A practice with sixty-nine purchased documents describing a workflow nobody follows fails it, and fails it worse than having nothing, because a policy you did not follow is evidence you knew the requirement.

This guide is written for the person who ended up owning compliance at a small practice without asking to: the office manager, the practice manager, the owner. It covers what the rules require, the difference between a policy and a procedure with concrete pairs, a working minimum set, what addressable really means, the retention rule that changes how you version documents, and where the proposed Security Rule update actually stands. I build the training records, document controls, and offboarding workflows this depends on at FirstHR. This is general information rather than legal advice, and HIPAA rules are under active revision, so verify current requirements before you act.

TL;DR
HIPAA policies and procedures are the written rules that implement the Privacy, Security, and Breach Notification Rules, plus the step-by-step instructions that carry them out. A policy is the what and why; a procedure is the who, how, and when. They must be kept in written form, which may be electronic, and retained for six years from creation or from the date the document last was in effect, whichever is later. Requirements do not scale down for small practices. And addressable does not mean optional: it means implement it, implement an alternative, or document why neither applies.

What Are HIPAA Policies and Procedures?

HIPAA policies and procedures are the written rules a covered entity or business associate adopts to comply with the Privacy, Security, and Breach Notification Rules, together with the operational steps that put those rules into daily practice. They are not optional documentation. They are themselves a requirement.

Definition
HIPAA policies and procedures
The documented internal rules governing how an organization protects the confidentiality, integrity, and availability of protected health information, and the specific steps by which those rules are carried out. Per 45 CFR 164.316, a covered entity or business associate must implement reasonable and appropriate policies and procedures to comply with the Security Rule standards, maintain them in written form which may be electronic, and keep a record of any action, activity, or assessment the rule requires to be documented. The Privacy Rule imposes a parallel obligation for its own standards.

Two features of that definition drive everything else on this page.

The first is that the documentation obligation is separate from the substantive one. Doing the right thing is not enough; you have to be able to show the written rule that says you do it and the record showing that you did. An investigation is a documentary exercise, and a practice that behaves well without paperwork is in roughly the same position as one that behaves badly.

The second is that policies must be reasonable and appropriate for your organization. The Security Rule is deliberately flexible about how you meet its standards, taking your size, complexity, and resources into account. That flexibility is real and it is also frequently overread, which is the subject of the addressable section below.

Policy vs Procedure: The Distinction That Matters

A policy is a statement of what your organization does and why. A procedure is the instruction for how it gets done and by whom. Most small practices write two policies, call one of them a procedure, and end up with documents that describe intentions rather than operations.

PolicyProcedure
AnswersWhat and whyHow, who, and when
AudienceEveryone, plus investigators and auditorsThe person performing the task
ChangesRarely, when intent or law changesOften, when systems, vendors, or staff change
LengthA paragraph or twoAs long as the steps need
Names peopleBy role, if at allYes, by role and ideally by position title
ProducesA standard to be measured againstRecords that prove the standard was met

The paired examples below show the same four topics written both ways. Read the right column and notice how little of it survives without a named owner and a timeframe.

Minimum necessary access
Policy: the what and whyWorkforce members access only the protected health information required to perform their job. Access is granted by role and reviewed when a role changes.
Procedure: the how and whoThe practice manager maintains a table of job roles and the systems and record types each role may access. On any role change, the manager updates the table, adjusts system permissions within one business day, and records the date and who made the change.
Workforce termination
Policy: the what and whyAll access to systems containing protected health information is removed when a workforce member leaves or is reassigned.
Procedure: the how and whoOn the final day, the practice manager works through the offboarding checklist: disable the network account, remove access to the record system and email, collect keys and badge, retrieve any device, and log the completion date. The checklist is filed with the personnel record.
Sanctions
Policy: the what and whyWorkforce members who violate privacy and security policies are subject to disciplinary action proportionate to the nature and severity of the violation.
Procedure: the how and whoThe privacy official documents the incident, interviews those involved, determines the sanction tier from the published schedule, delivers it in writing, and retains the record. Repeat violations escalate one tier.
Breach assessment
Policy: the what and whyEvery impermissible use or disclosure of unsecured protected health information is presumed to be a breach unless a documented risk assessment shows a low probability of compromise.
Procedure: the how and whoWithin one business day of discovery, the privacy official completes the four-factor risk assessment form, records the conclusion and the reasoning, and if notification is required, starts the notification timeline from the date of discovery.
The test for whether you have written a procedure rather than a second policy: it names a person, an action, and a timeframe. If it does not, it is still a policy.
The Records Column Is the Point
Every procedure in that set produces a record: an updated access table, a completed offboarding checklist, a written sanction, a four-factor assessment form. Those records are what you hand over when someone asks whether the policy operated. A procedure that produces no artifact cannot be evidenced, which is why the policy template further down this page includes a records produced section as a required field rather than an afterthought.

What the Rules Actually Require

Three rules generate the obligations, and each one requires written policies of its own.

The Privacy Rule governs how protected health information may be used and disclosed and what rights individuals have over it. It requires a designated privacy official, workforce training, a complaint process, sanctions, and written policies and procedures covering its standards.

The Security Rule governs electronic protected health information specifically, through administrative, physical, and technical safeguards. Per HHS, a major goal of the rule is to protect ePHI while allowing regulated entities to adopt new technologies, which is why its requirements are written as standards with flexibility in how you meet them.

The Breach Notification Rule governs what happens after something goes wrong. Per HHS, individual notifications must be provided without unreasonable delay and no later than 60 days following discovery of a breach, and an impermissible use or disclosure of unsecured protected health information is presumed to be a breach unless you can demonstrate a low probability of compromise through a documented risk assessment.

The Presumption Runs Against You
This is the structural feature that catches practices with no written breach procedure. An impermissible disclosure is presumed to be a breach. The way out is a documented four-factor risk assessment showing a low probability that the information was compromised. If you have no procedure for producing that assessment, you have no way to rebut the presumption, and a misdirected fax becomes a notifiable breach by default rather than by analysis.

Required vs Addressable: The Most Misread Word in HIPAA

Security Rule implementation specifications are labeled either required or addressable. Required means you implement it. Addressable means something considerably more demanding than the word suggests, and reading it as optional is one of the more expensive mistakes available in this area.

Addressable means you must assess whether the specification is reasonable and appropriate for your environment, and then take one of exactly three paths.

Implement it as writtenYou assess the specification, decide it is reasonable and appropriate for your practice, and put it in place. Document the assessment, not just the outcome. This is the path most small practices should take most of the time, because the alternatives require more writing, not less.
Implement an equivalent alternativeYou determine the specification is not reasonable and appropriate as written, document why, and implement an alternative measure that achieves the same purpose. Both halves have to be written down. An alternative with no documented reasoning behind it looks identical to a gap.
Do neither, and document whyPermitted only where the specification is not reasonable and appropriate and no equivalent alternative is, and where the standard can still be met. This is the narrowest path and the one auditors scrutinize hardest. If you take it, the written analysis is the entire defense.
Every one of the three paths ends in a written record. There is no version of addressable where the correct action is to do nothing and write nothing.

Notice what all three have in common. Each produces a written analysis. There is no fourth path where you decide the specification does not apply to a practice your size and move on without recording anything, which is nonetheless what happens in most small practices that have never had this explained to them.

Two more things worth knowing. Encryption of electronic protected health information at rest is currently an addressable specification, which is why so many practices have never encrypted a laptop and have no written analysis explaining that choice. And the proposed Security Rule update would remove the required and addressable distinction entirely, making all specifications required, which is covered further down.

Still Using Spreadsheets for Onboarding?
Automate documents, training assignments, task management, and track onboarding progress in real time.
See How It Works

The Minimum Policy Set for a Small Practice

Below is a working set grouped by the rule that drives it. It is not the shortest possible list and it is not a 69-document suite. It is the coverage a practice actually needs, organized so you can see the shape of it.

Privacy Rule
Designation of a privacy official and a contact for complaints
Notice of privacy practices and how it is provided and acknowledged
Uses and disclosures of protected health information, including what requires authorization
Minimum necessary standard applied by role
Individual rights: access, amendment, accounting of disclosures, restriction requests, confidential communications
Workforce training on privacy policies and procedures
Complaint process for patients
Sanctions for workforce members who violate policies
Mitigation of known harmful effects of an improper disclosure
Prohibition on retaliation and on requiring a waiver of rights
Business associate agreements and vendor management
Security Rule
Security risk analysis and risk management
Assigned security responsibility naming a security official
Workforce security: authorization, clearance, and termination procedures
Information access management by role
Security awareness and training, including malware, login monitoring, and passwords
Security incident response and reporting
Contingency planning: data backup, disaster recovery, emergency mode operation
Periodic technical and non-technical evaluation
Facility access controls and workstation use and security
Device and media controls, including disposal and reuse
Access control, audit controls, integrity, authentication, and transmission security
Breach Notification Rule
Breach risk assessment using the four-factor test
Individual notification, without unreasonable delay and no later than 60 days from discovery
Notification to the Secretary, immediately for larger breaches and annually for smaller ones
Media notification where a breach affects more than 500 residents of a state or jurisdiction
Breach log maintenance and burden-of-proof documentation
A working set for a small practice, grouped by the rule that drives it. Vendors sell suites of 45 to 69 documents, which is the same substance sliced more finely. Consolidating related topics into one policy is fine as long as every requirement is addressed somewhere and you can find it.

Two notes on using that list. First, consolidation is fine. Several of those bullets can live in one document if the document addresses each of them clearly. What you cannot do is drop a topic because it feels large for your size.

Second, the flexibility the Security Rule allows applies to how you meet a standard, not to whether the standard applies. A three-person dental office needs a contingency plan. It does not need the contingency plan a hospital needs. The document might be a page describing where backups live, how often they run, who verifies them, and what the office does if the record system is unavailable for a day. That page satisfies the standard. The absence of the page does not.

What worked for me
The version of this I have seen work at small scale is not a binder, it is a folder with a numbered file per policy and one spreadsheet listing every file with its owner, version, and review date. The spreadsheet is the actual compliance artifact, because it is the only thing that answers the question an investigator opens with: what policies do you have, and when did you last look at them. Building it took an afternoon. Keeping it took about twenty minutes a quarter. The practices that struggle are not the ones with weak policies, they are the ones with no index and no idea which version is current.

The Half of HIPAA That Is Actually an HR Job

A surprising share of what the Security and Privacy Rules require is not technical at all. It is workforce administration, and in a small practice that means it belongs to whoever handles hiring, onboarding, and departures rather than to whoever handles the computers.

RequirementWhat it actually isWhere it lives day to day
Workforce authorization and clearanceDeciding and recording who may access what, by roleHiring and role changes
Termination proceduresRemoving all access when someone leaves or moves rolesOffboarding
Security awareness and trainingDelivering training and keeping dated records of who completed itOnboarding and annual training
Sanctions policyA published, applied disciplinary schedule for policy violationsEmployee relations
Privacy trainingTraining on privacy policies as necessary and appropriate for each roleOnboarding
Documentation of all of the aboveRetaining every record for six yearsPersonnel and compliance files

The termination row is where small practices are most exposed and it is the least technical item on the list. Access that outlives employment is a finding waiting to happen, and it is discovered constantly, because nobody owns the last step. Fold it into a written IT offboarding checklist that is completed and filed rather than performed from memory, and treat the completed checklist as the compliance record it is. The same logic applies to the rest of offboarding.

Training is the second exposure and it fails in a specific way: the training happens and the record does not. Delivering compliance training without a dated log of who completed what leaves you in the position of having complied and being unable to show it. A simple training matrix with names, dates, and topics closes that gap for almost no effort.

The sanctions policy is third and it is the one people avoid writing because it feels punitive. It is required, and a published schedule applied consistently is considerably fairer than case-by-case improvisation. Align it with your existing approach to disciplinary action rather than running a parallel system.

The Documentation Standard

The Security Rule sets out three obligations about the documents themselves, separate from anything they say. All three are easy to satisfy and commonly missed.

1
Keep policies in written form, which may be electronic
A shared folder of documents is fine. What is not fine is a set of practices that live in someone head and have never been written down, however consistently they are followed.
2
Record the actions the rules require to be documented
Where a standard says something must be documented, the record is part of compliance. Risk analyses, training completions, sanctions applied, access reviews, breach assessments. The policy says what you do; the record proves you did it.
3
Make documentation available to the people who implement it
The rule requires documentation to be available to those responsible for implementing the procedures. A policy set only the manager can open does not meet this. Neither does a binder in a locked office nobody has been shown.
4
Review periodically and update as needed
The rule expects periodic review and updating in response to environmental or operational changes affecting the security of protected health information. New system, new vendor, new location, incident, staff change: all triggers.

Step three is the one that surprises people. Documentation that exists but is not reachable by the person expected to follow it fails the standard on its own terms. This is an argument for keeping the policy set wherever your team already goes for HR documents rather than in a separate compliance silo that only one person opens.

The Six-Year Retention Rule and What It Implies

Retain documentation for six years from the date of its creation or the date when it last was in effect, whichever is later. That phrasing carries a consequence most practices have not worked through.

A Retired Policy Is Not a Deleted Policy
When you replace a policy, the old version does not become disposable. Its six-year clock starts on the day it stopped being in effect. A policy written in 2020 and superseded in 2026 has to be retained until 2032, and if the version that replaced it is itself replaced next year, the older document outlives the newer one in your files. The practical implication is that you cannot overwrite a policy document. Every revision creates a new version, and the previous one is archived with the dates it governed.

That single rule dictates a document-control approach: version numbers, effective-from and last-in-effect dates on every document, and an archive rather than an edit history buried inside a word processor. It also means the retention question for a policy is answered per version, not per policy, which is why the register template below tracks superseded versions on their own rows.

Note that this obligation is about the compliance documentation, not about medical records themselves. Medical record retention is set by state law and varies considerably, and it is a separate schedule to maintain alongside your ordinary employee record retention rules.

HIPAA Policy Register and Review Schedule
ABCDEFGHIJ
1Policy numberPolicy titleRuleCitationOwnerVersionApprovedEffective fromLast in effectRetain until
2P-01Designation of Privacy and Security OfficialsPrivacy and Security164.530(a)Practice manager2.02026-01-122026-02-01CurrentOpen
3P-02Minimum Necessary Access by RolePrivacy164.502(b)Practice manager1.32026-01-122026-02-01CurrentOpen
4S-04Workforce Termination ProceduresSecurity164.308(a)(3)Practice manager1.12025-11-032025-12-01CurrentOpen
5S-04Workforce Termination ProceduresSecurity164.308(a)(3)Practice manager1.02024-06-102024-07-012025-11-302031-11-30
6
7

Three sheets because three separate questions get asked. The register answers what policies exist, who owns them, which version is current, and when each retired version can finally be destroyed. The review schedule answers when everything is next due and where the evidence sits. The training log answers the question that comes up in almost every investigation and that almost nobody can answer from memory.

How to Write a Policy Somebody Will Follow

The failure mode in policy writing is restating the regulation. A document that paraphrases the CFR back at your front desk staff is compliant in form and useless in operation, and uselessness in operation is what an investigation eventually surfaces.

1
Write the policy statement in your own words, in present tense
State what this practice does. Avoid will, should, and may, which turn a rule into an aspiration. If the sentence describes an intention rather than a current fact, either change the sentence or change the practice.
2
Put the citation in the header, not the body
You need the regulatory reference for traceability. Your staff do not need it in the middle of a paragraph. Header field, one line, done.
3
Name a person for every procedural step
By position rather than by individual, so the document survives turnover. A step with no owner is a step that does not happen, and it is visible as such to anyone reading the policy against the records.
4
Add a timeframe to every step
Within one business day. Before the final shift ends. Quarterly. Vague timing is the most common reason a documented procedure produces no evidence that it ran.
5
List the records the procedure produces
Name each artifact, where it is stored, and how long it is kept. This is the section that converts a policy into something you can evidence, and it is missing from most template sets.
6
Keep it as short as it can be and still be complete
Length is not thoroughness. A two-page policy that people read beats a nine-page policy that people scroll past, and both satisfy the same standard.
HIPAA Policy and Procedure Template
HIPAA POLICY AND PROCEDURE

Policy title:
Policy number: Version:
Applies to:
Regulatory citation:
Owner: Approved by:
Effective date: Last reviewed: Next review due:
Retain until: (six years from the date this version last was in effect)
PURPOSE

State in one or two sentences why this policy exists and what it protects. Name the requirement it implements.
SCOPE

Identify who this applies to. Include employees, contractors, temporary staff, students, and volunteers where relevant. Note any location or system limits.
DEFINITIONS

Define only the terms a reader could reasonably misread. Do not restate the regulation.
Term: Meaning:
Term: Meaning:
POLICY STATEMENT

Write the rule itself as a plain statement of what this practice does and does not do. Present tense. No conditional language. This is the what and the why, not the how.
PROCEDURE

Number the steps. Each step names who does it, what they do, and when. If a step does not have an owner, it will not happen.
Step 1. Who: Does: When:
Step 2. Who: Does: When:
Step 3. Who: Does: When:
Step 4. Who: Does: When:
RECORDS PRODUCED

List every record this procedure creates, where it is stored, and who can reach it. This is the evidence that the policy operated, and it is what an investigation asks for.
Record: Stored at: Retained until:
Record: Stored at: Retained until:
EXCEPTIONS

State who may approve an exception and how it is recorded. If there are none, write "No exceptions" rather than leaving the section blank.
RELATED POLICIES

REVISION HISTORY

Version: Date: Changed by: Summary of change:
Version: Date: Changed by: Summary of change:
APPROVAL

Name: Title: Signature: Date:

The header block on that template is doing more work than it looks. Version, effective date, last reviewed, next review due, and retain-until are what make the six-year rule administrable. Fill them in when you create the document and the retention question answers itself later.

Using Templates Without Creating a Liability

Templates are fine. Buying a policy suite is fine. What is not fine, and what quietly creates exposure, is adopting documents that describe a practice you do not run.

The reason is straightforward. Policies are read against evidence. If your policy says access reviews happen quarterly and there are no access review records, the policy has not helped you, it has established the standard you failed to meet and demonstrated that you were aware of the requirement. That is a materially worse position than having addressed the topic more modestly and actually done it.

The Three-Pass Method for a Purchased Template
First pass: delete everything describing systems, roles, or activities that do not exist at your practice. Second pass: rewrite every procedure so it names your real positions, your real systems, and a real timeframe. Third pass: run it once and see whether it produces the records it claims to. Anything that survives all three is yours. Anything that does not was never going to help you.

The same discipline applies to any data protection policy or handbook language you adopt from a template. It is the reason a shorter employee handbook that matches reality outperforms a comprehensive one that does not, and it applies with more force here because the audience includes a federal regulator.

Keeping Policies Current

The Security Rule expects periodic review and updating in response to environmental or operational changes. It does not prescribe an interval, which in practice means annually plus event-driven, and the event-driven half is the one that catches people.

TriggerWhat to revisitTypical window
Scheduled annual reviewThe full policy set against actual practiceSame month each year
New system or vendor with access to PHIAccess management, business associate agreement, risk analysisBefore go-live
Security incident or breachIncident response, the specific control that failed, trainingWithin the response
New workforce member or departureAccess provisioning or removal, training recordAt hire and final day
Change of privacy or security officialThe designation policy itself, and every policy naming that roleImmediately
New location or a moveFacility access controls, workstation security, device controlsBefore occupancy
Change in federal or state lawWhatever the change touchesBefore the effective date

Put the annual review on a fixed date and attach it to your existing compliance calendar rather than treating it as a standalone project. The review itself is not long once the register exists: you are checking whether each policy still describes what you do, not rewriting from scratch.

Annual HIPAA Policy Review Record
ANNUAL HIPAA POLICY REVIEW RECORD

Practice:
Review period: to
Reviewer: Title:
Date completed:
WHAT TRIGGERED THIS REVIEW

Scheduled annual review
New or changed system, vendor, or location
Security incident or breach
Change in the workforce or in who holds the privacy or security official role
Change in federal or state law
Finding from an audit, assessment, or complaint
Notes:
POLICIES REVIEWED

For each policy, record whether it still matches what the practice actually does.
Policy: Still accurate: Change needed: New version issued:
Policy: Still accurate: Change needed: New version issued:
Policy: Still accurate: Change needed: New version issued:
Policy: Still accurate: Change needed: New version issued:
SUPPORTING ITEMS CHECKED

Security risk analysis completed or updated within the period. Date: _______
Workforce training delivered and recorded for every member. Date range: _______
Business associate agreements current for every vendor with access to protected health information. Gaps: _______
Access reviewed against current roles; departures fully offboarded. Exceptions: _______
Incident and breach log reviewed and complete. Entries this period: _______
Superseded policy versions retained rather than overwritten. Confirmed: _______
GAPS IDENTIFIED

Gap: Owner: Target date:
Gap: Owner: Target date:
STATEMENT

I reviewed the policies listed above against current practice on the date shown. Changes made in response are recorded in each policy revision history.
Signature: Date:
All three HIPAA documents
Policy and procedure template, annual review record, and the policy register with review schedule and training log.

The review record matters for a reason that is easy to miss: it is the artifact proving the review happened. Reviewing your policies and leaving no trace of it puts you in the same evidentiary position as never having reviewed them, which is the recurring theme of this entire topic.

Companies Using FirstHR Onboard 3x Faster
Join hundreds of small businesses who transformed their new hire experience.
See It in Action

The Proposed Security Rule Update

There is a substantial proposed overhaul of the Security Rule in circulation, and a great deal of published content describes it with more certainty than the facts support. Here is the accurate position.

The Office for Civil Rights published a Notice of Proposed Rulemaking in the Federal Register in January 2025. It would, among other things, remove the distinction between required and addressable implementation specifications and make all of them required, mandate written documentation of all Security Rule policies, procedures, plans, and analyses, and add a standard requiring a documented compliance audit at least once every twelve months.

It Is Still Proposed, and the Target Date Has Moved
The comment period closed in March 2025 and drew close to 5,000 comments, with more than 100 hospital systems and provider associations formally asking for the proposal to be withdrawn. The regulatory agenda originally targeted a final rule in spring 2026. That target has since moved: the federal unified agenda now shows final action projected for 2027, and agency timelines of this kind are not legally binding and have moved before. The existing Security Rule remains in force in the meantime. Treat any page describing these as current requirements with suspicion.

What should a small practice do about a rule that may or may not arrive, in a form that may or may not resemble the proposal? Not restructure around it. But two of the proposed changes are worth acting on regardless, because they are already good practice and already show up in enforcement.

The first is documenting your addressable decisions. If the distinction is eventually removed, you will have to implement those specifications anyway. If it is not, you still owe the written analysis today. Either way the work is not wasted.

The second is the annual documented review. It is not currently a named standard in that form, but periodic review and updating already is, and a dated review record is the cheapest evidence available. A practice already doing this absorbs a large share of the proposed documentation burden without a project.

What Enforcement Actually Looks Like

Enforcement of the existing rules is active, and the pattern in recent settlements is consistent enough to plan around: cases are opened by a breach report or a complaint, and the finding that recurs is a missing or inadequate security risk analysis.

That matters for a small practice because the risk analysis is a required implementation specification, it is the foundation the rest of the Security Rule sits on, and it is the single most commonly absent document. HHS and the national health IT office jointly publish a Security Risk Assessment Tool built specifically to help small and medium-sized practices perform one, available from the HHS Security Rule page. It is free, and it produces exactly the artifact that is missing in most enforcement actions.

What Penalties Look Like on Paper
Civil money penalties are set in four tiers by culpability and adjusted annually for inflation. Following the adjustment published in the Federal Register effective January 28, 2026, they run from $145 per violation at the lowest tier to $2,190,294 at the willful-neglect-uncorrected tier (Federal Register). In practice most matters resolve through settlement with a corrective action plan and a period of monitoring rather than at those figures, and the tier structure means the gap between a documented good-faith gap and an uncorrected known one is roughly four orders of magnitude.

The tier structure is the part worth internalizing. Culpability drives the number, and culpability is assessed from documents. A practice that identified a risk, wrote down its reasoning, and had not finished remediating sits in a different tier than one that never looked. The Enforcement Rule also lets the agency weigh the nature and extent of the violation, the number of individuals affected, and prior compliance history, all of which are evidenced from your own records.

Worth adding that penalties are rarely the largest cost. Notification expense, the operational disruption of a corrective action plan under monitoring, state attorney general action, and the reputational effect on a local practice generally outweigh the assessment itself.

Where Small Practices Get Caught

The failure patterns repeat with unusual consistency in this area.

No risk analysis is first, and it is the finding behind most enforcement. It is a required specification, it is the basis for every other security decision, and a free federal tool exists to produce it.

Purchased policies that describe a practice you do not run is second. The documents establish the standard and the absence of records demonstrates the gap. Templates are a starting point, not a deliverable.

Treating addressable as optional is third. Three paths, all of them ending in a written analysis, and none of them being silence.

Access that outlives employment is fourth, and it is a workforce administration failure rather than a technical one. A completed offboarding checklist filed with the personnel record prevents it.

Training with no record is fifth. The training happened, the log does not exist, and the position is identical to not having trained.

Overwriting policy documents is sixth. The six-year clock runs from the date a version last was in effect, so a retired policy has to be archived rather than replaced in place.

Then the quieter ones. No named privacy or security official, or a designation that everyone knows and nobody wrote down. Business associate agreements that were signed once and never revisited as vendors changed. A policy set stored somewhere only the manager can reach, which fails the availability requirement on its own. And no index, so nobody can say which version of which policy is currently in effect, which is the question that opens every conversation with an investigator.

None of this requires a compliance department. It requires a named owner, a register, a review date, and the discipline to write down what you actually do rather than what a template says you should. That is the same infrastructure that makes the rest of HR at a small business function without a specialist, and it holds together or falls apart as one piece along with the rest of your workplace policies.

Key Takeaways
HIPAA policies and procedures are themselves a requirement, not just supporting paperwork. The Security Rule requires them in written form, which may be electronic, along with records of the actions the rules require to be documented.
A policy states what you do and why. A procedure names a person, an action, and a timeframe, and produces a record. If your procedure does not name someone, it is still a policy.
There is no required number of policies. Vendor suites range from 45 to 69 documents; what matters is that every applicable standard is addressed somewhere in writing and that you can find it.
Requirements do not scale down for small practices. The Security Rule gives flexibility in how you meet a standard, based on your size and resources, not in whether the standard applies.
Addressable does not mean optional. It means implement it, implement a documented equivalent, or document why neither is reasonable and appropriate. All three paths end in writing.
Documentation must be retained six years from creation or from the date it last was in effect, whichever is later, so retired versions are archived rather than overwritten.
Documentation must be available to the people responsible for carrying out the procedures, which a locked binder or a single-user folder does not satisfy.
A large share of the requirements are workforce administration rather than IT: access by role, termination procedures, training records, and a sanctions policy.
Templates are a starting point. A policy describing a workflow you do not run establishes a standard you failed to meet and shows you knew the requirement.
The proposed Security Rule overhaul, which would make all specifications required and add an annual documented audit, remains proposed. The target for final action has moved to 2027 and the existing rule stays in force.

Frequently Asked Questions

What are HIPAA policies and procedures?

HIPAA policies and procedures are the written rules a covered entity or business associate puts in place to comply with the Privacy, Security, and Breach Notification Rules, together with the step-by-step instructions that carry those rules out day to day. A policy states what the organization does and why. A procedure states who does it, how, and when. The Security Rule requires that these be maintained in written form, which may be electronic, and that a record be kept of any action or assessment the rules require to be documented.

What is the difference between a HIPAA policy and a procedure?

A policy is a statement of intent, the what and the why. A procedure is the operational detail, the how and the who. A policy might state that workforce access to protected health information is limited to what each role requires. The matching procedure names the person who maintains the role-to-access table, states that permissions are adjusted within one business day of a role change, and says where the record of that change is kept. A useful test: if the text does not name a person, an action, and a timeframe, it is still a policy rather than a procedure.

How many HIPAA policies and procedures are required?

There is no fixed number in the regulation. Commercial template suites range from roughly 45 to 69 documents, and typical practice sets run 20 to 40, but that variation reflects how finely the same substance is sliced rather than a difference in obligation. What matters is coverage: every standard and implementation specification that applies to your organization has to be addressed somewhere in writing, and you have to be able to find it. A practice that consolidates related topics into 20 well-organized policies is in the same position as one with 60, provided nothing is missing.

Do small practices need the same HIPAA policies as large organizations?

Yes. The requirements do not scale down with headcount. A solo practitioner and a hospital system are subject to the same standards, and both must have written policies and procedures addressing them. What the Security Rule does allow is flexibility in how you meet those standards, taking into account your size, complexity, technical infrastructure, and the cost of the measures. That flexibility changes the depth and cost of your controls. It does not remove any topic from the list or excuse the absence of a written policy.

How long must HIPAA policies and procedures be retained?

Six years from the date of creation or the date when the document last was in effect, whichever is later. The second half is the part people miss. When you replace a policy, the retired version does not become disposable. Its clock starts on the day it stopped being in effect and runs six years from there, which means a superseded policy can outlive its replacement in your files. The practical implication is that you cannot simply overwrite a policy document. You issue a new version and keep the old one with the dates it governed.

Can I use a HIPAA policy template?

Yes, and templates are a sensible starting point, but only if you tailor them to what your organization actually does and then operate them. A template that describes procedures you do not follow is worse than no template at all, because it establishes that you knew the requirement and documents a gap between your stated process and your real one. Investigators read policies against evidence of what happened. Take a template, delete what does not apply, rewrite the procedures to name your real people and systems, and keep records showing the procedures ran.

Who is responsible for HIPAA policies and procedures?

The organization must designate a privacy official responsible for developing and implementing its privacy policies and procedures, and must identify a security official responsible for the Security Rule policies and procedures. In a small practice this is very often the same person, typically the practice manager or the owner, and that is permitted. What is not permitted is leaving the role unassigned or implied. The designation should be written down with a name and a date, because it is one of the first things an investigation asks for.

What does addressable mean in the HIPAA Security Rule?

Addressable does not mean optional. It means you must assess whether the implementation specification is reasonable and appropriate for your environment, and then take one of three documented paths: implement it as written, implement an equivalent alternative measure and document why, or do neither where neither is reasonable and appropriate and document that analysis. Every path ends in a written record. Treating an addressable specification as something you can skip silently is one of the more common and more expensive misreadings of the rule.

Are the new HIPAA Security Rule requirements in effect?

No. The Office for Civil Rights published a Notice of Proposed Rulemaking in the Federal Register in January 2025 that would make all implementation specifications required, mandate written documentation of all Security Rule policies and procedures, and add an annual compliance audit. The comment period closed in March 2025 and drew nearly 5,000 comments, with more than 100 hospital and provider organizations asking for the proposal to be withdrawn. It remains proposed. The federal regulatory agenda has moved the target for final action to 2027, and those dates are not binding. The existing Security Rule remains in force throughout.

Ready to transform your onboarding?

7-day free trial No credit card required
Start Your Free Trial