Get certified in HIPAA for Leaders for just $49.95.
To view this video please enable JavaScript, and consider upgrading to a web browser that supports HTML5 video
So now let’s dive into policies, procedures, and the Book of Evidence. Your practice and business are required to have policies and procedures on handling PHI and ePHI. We call this your Book of Evidence. These policies must be customized and unique to your practice or business and not a template that has been downloaded from the internet. It must be relevant to your exact business. The Book of Evidence includes: responsibilities of covered entities and business associates, the use and disclosure of PHI, your patients' individual rights, and how to handle a breach of PHI. Your Book of Evidence must reflect the dates of the last changes to the law. You must have and provide evidence of all policies and procedures to the Office of Civil Rights when asked. The Book of Evidence must be present in the office of the practice or business and is recommended to be stored online or a local network for disaster recovery and business continuity purposes. A common misconception is that the Book of Evidence is a one-size-fits-all book. You are required, and it is a best practice, to customize the policies and procedures to fit your unique business. When creating your Book of Evidence, we recommend you have printed material on-site and a copy at an off-site or cloud-based location. Lastly, let's discuss how long you need to keep the records in the Book of Evidence. HIPAA requires you to keep and maintain all required documentation, including your policies, procedures, changes, and required records, for 6 years from the date it was created or the date it was last in effect, whichever is later. However, some organizations must keep them longer. Medicare Advantage and Part D sponsors, and the entities that work under them, must retain records for 10 years. And because False Claims Act liability can reach back as far as 10 years, many organizations keep their compliance records for 10 years as a best practice. Always follow the longest retention period that applies to your organization.
In healthcare compliance, maintaining thorough policies and procedures is essential for safeguarding protected health information (PHI) and electronic protected health information (ePHI). Every practice and business associate must develop, implement, and maintain a unique set of compliance documents commonly referred to as the "Book of Evidence." This lesson covers the core requirements for building your Book of Evidence, proper storage practices, and critical record retention timelines mandated by HIPAA and federal regulations.
Your Book of Evidence acts as the foundation of your practice's HIPAA compliance program. To meet regulatory requirements, your documentation must specifically cover the following areas:
Pro Tip: Avoid Generic Templates: A common misconception is that the Book of Evidence is a one-size-fits-all document. You are required to customize every policy and procedure to reflect your unique business operations. Generic templates downloaded from the internet do not satisfy regulatory standards.
Your Book of Evidence must reflect the most recent changes in healthcare law and be readily available to demonstrate compliance during an audit by the Office for Civil Rights (OCR).
To ensure disaster recovery and business continuity, maintain printed physical copies on-site as well as digital copies stored at an off-site or cloud-based location. Furthermore, organization compliance records must be retained according to applicable statutory timelines:
Always adhere to the longest applicable record retention period for your organization. Retaining records for insufficient lengths of time can result in substantial regulatory penalties during an OCR audit or investigation.
Knowledge Check: According to HIPAA regulations, what is the minimum required retention period for compliance documentation such as policies and procedures?
A) 3 years from the date of creation
B) 5 years from the date last in effect
C) 6 years from creation or when last in effect, whichever is later
D) 10 years for all healthcare entities without exception
Correct Answer: C) 6 years from creation or when last in effect, whichever is later
Explanation: Standard HIPAA regulations require organizations to retain policies, procedures, and required records for 6 years from creation or the date last active. However, entities associated with Medicare Advantage or those addressing False Claims Act risks may need to extend retention to 10 years.