10 Red Flags for HIPAA Policy Compliance
by Kelly McLendon
Kelly McLendon, our Managing Director and Chief Privacy Officer, wrote an article for the May issue of the Journal of AHIMA based on his extensive knowledge and experience offering privacy and security policy and form templates.
Here are his 10 Red Flags to watch for:
- Policies and procedures are not searchable
- Policies and procedures are not well formatted or indexed
- Unclear and non-standardized formatting of policy document sections
- Policy and procedure documents too long and complex
- Approval processes are inefficient
- Tracking of who was trained on which policies and procedures is never or infrequently performed
- Policy manuals for privacy and security are printed out and have dust on them
- Going it alone
- Policies are outdated
- Policies lack security risk analysis or privacy compliance assessments
Kelly suggests you review your HIPAA and related privacy and security polices, procedures and forms on a regular basis and to keep records of version changes. It is important to be able to show OCR you have an active program to keep them up-to-date.