HIPAA Final Rules Checklist
 
Use this checklist to ensure that your agency is in full compliance with the HIPAA mega rule. This tool was developed by Frank Ruelas, compliance officer for Gila River Health Care in, Sacaton, Ariz. (See related article)
 
Item #
Description
Responsible Party
Status
1
Revise Notice of Privacy Practices to include material changes.
 
 
2
Inventory electronic PHI locations and develop process to capture and provide copies upon request.
 
 
3
Develop process and forms for use in transmitting PHI to third parties (to include by email).
 
 
4
Review process to restrict disclosure of information to a health plan.
 
 
5
Develop “low probability of compromise” four-factor analysis model for breach assessments.
 
 
6
Conduct training on impermissible use and disclosure
 
 
7
Update business associate contracts
 
 
8
Confirm that electronic PHI on office machines is included in risk assessments.
 
 
9
Revise marketing policy to indicate that patient authorizations are required.
 
 
10
Develop or review process on permitted disclosures on decedents
 
 
11
Develop or review process to disclose immunization related information to schools.
 
 
12
Identify notification of opt-out process for fundraising communications and non-burdensome process for opt out.