All Courses HIPAA HIPAA for Leaders Training Policies, Procedures and the Book of Evidence

Policies, Procedures and the Book of Evidence

Video 19 of 26
2 min 18 sec
English
English

In healthcare compliance, maintaining thorough policies and procedures is essential for safeguarding protected health information (PHI) and electronic protected health information (ePHI). Every practice and business associate must develop, implement, and maintain a unique set of compliance documents commonly referred to as the "Book of Evidence." This lesson covers the core requirements for building your Book of Evidence, proper storage practices, and critical record retention timelines mandated by HIPAA and federal regulations.

Key Components of the Book of Evidence

Your Book of Evidence acts as the foundation of your practice's HIPAA compliance program. To meet regulatory requirements, your documentation must specifically cover the following areas:

  • Responsibilities of Covered Entities and Business Associates: Defining roles, duties, and operational expectations for managing health data.
  • Use and Disclosure of PHI: Establishing strict rules for when and how patient information may be accessed, shared, or transferred.
  • Patients' Individual Rights: Outlining protocol to honor patient access requests, amendment rights, and privacy notifications.
  • Breach Notification Protocols: Detailing immediate procedures and reporting steps to follow in the event of a PHI breach.

Pro Tip: Avoid Generic Templates: A common misconception is that the Book of Evidence is a one-size-fits-all document. You are required to customize every policy and procedure to reflect your unique business operations. Generic templates downloaded from the internet do not satisfy regulatory standards.

Storage, Accessibility, and Record Retention

Your Book of Evidence must reflect the most recent changes in healthcare law and be readily available to demonstrate compliance during an audit by the Office for Civil Rights (OCR).

To ensure disaster recovery and business continuity, maintain printed physical copies on-site as well as digital copies stored at an off-site or cloud-based location. Furthermore, organization compliance records must be retained according to applicable statutory timelines:

  • HIPAA Standard (6 Years): Keep all required documentation, policy changes, and historical records for 6 years from the date of creation or the date last in effect, whichever is later.
  • Medicare Sponsors (10 Years): Medicare Advantage and Part D sponsors, along with their associated entities, must retain compliance records for at least 10 years.
  • False Claims Act Considerations (10 Years): Because liability under the False Claims Act can reach back up to 10 years, retaining documentation for 10 years is widely considered a best practice.

Compliance Warning

Always adhere to the longest applicable record retention period for your organization. Retaining records for insufficient lengths of time can result in substantial regulatory penalties during an OCR audit or investigation.

Interactive Knowledge Check

Knowledge Check: According to HIPAA regulations, what is the minimum required retention period for compliance documentation such as policies and procedures?

A) 3 years from the date of creation

B) 5 years from the date last in effect

C) 6 years from creation or when last in effect, whichever is later

D) 10 years for all healthcare entities without exception

Reveal Correct Answer

Correct Answer: C) 6 years from creation or when last in effect, whichever is later

Explanation: Standard HIPAA regulations require organizations to retain policies, procedures, and required records for 6 years from creation or the date last active. However, entities associated with Medicare Advantage or those addressing False Claims Act risks may need to extend retention to 10 years.