Skip to content
Meeting space in a modern professional office

Documentation

HIPAA policy and procedure manual.

A customisable manual written in plain English, with the patient-facing forms and notices your front desk uses every day already drafted and ready to adopt.

Why plain English

A policy nobody reads protects nobody.

Manuals written in statutory language get filed and forgotten. The medical assistant deciding whether to leave a voicemail, or the receptionist facing a records request, needs an answer they can find and understand in under a minute.

Ours is organised by situation rather than by regulation, cross-referenced to the rule behind each answer, so it works both as a day-to-day reference and as the documentation an investigator expects to see.

Contents

Policies and forms included.

  • Notice of privacy practices, ready to post and distribute
  • Acknowledgement of receipt form
  • Authorisation for use and disclosure of PHI
  • Revocation of authorisation form
  • Request for access to records, with fee and timeline guidance
  • Request for amendment and the response and denial procedure
  • Request for accounting of disclosures with the tracking log
  • Request for restriction and confidential communications
  • Minimum necessary policy with role-based access matrix
  • Verification of identity procedure for callers and requesters
  • Workforce confidentiality agreement
  • Sanction policy for privacy and security violations
  • Security incident and breach response procedure with notification templates
  • Business associate agreement template and vendor register
  • Device, media and disposal policy including departing employee checklist
  • Contingency and data backup plan with restoration testing log
  • Annual review log with signature blocks

Policies must be retained for six years from creation or from the date last in effect, whichever is later. Our review log makes that history provable.

Adopt a manual your staff will actually use.

We customise it to your practice, walk your team through it, and keep it current as your systems change.