Board Policy #
Title
Established
Effective Date
Supersedes Dates
HIPAA
Assuring Privacy of Individual Protected Health Information,
General Policy
4/14/03
4/14/03
Safeguards for Protection if IIHI and PHI
4/14/03
4/14/03
Minimum Necessary Use and Disclosure of Protected Health
Information
4/14/03
4/14/03
Mitigating the Effects of Unauthorized Use/Disclosure of
Protected Health Information
4/14/03
4/14/03
Sanctions for Breach of Privacy and Security of PHI
4/14/03
4/14/03
Use
and Disclosure of PHI for Fundraising and Marketing
4/14/03
4/14/03
Complaint
4/14/03
4/14/03
Member’s/Clients Rights: Inspect & Copy, Amend, Accounting
of Disclosures, and Confidential Communication
4/14/03
4/14/03
Disclosure of Client PHI to Business Associates
4/14/03
4/14/03
Development and distribution of Notice of Privacy Practices
4/14/03
4/14/03
Implementing/Updating Policies to Ensure Compliance
4/14/03
4/14/03
Workforce Training for HIPAA Privacy Compliance
4/14/03
4/14/03
Use
of Client PHI for Treatment Payment and Operations
4/14/03
4/14/03
Uses
and Disclosures of PHI for Other than Treatment, Payment and
Operations
4/14/03
4/14/03
Member’s/Client’s Right to Request Restrictions on
Use/Disclosure of Protected Health Information
4/14/03
4/14/03
Client’s Personal Representative
4/14/03
4/14/03
Access Controls
4/27/05
8/2/2006
4/27/06
Data
Back-Up Plan
4/27/05
Device and Media Controls
4/27/05
E-Mail
4/27/05
Evaluation Policies and Procedures
4/27/05
Facility Access Controls
4/27/05
Guarding Against, Detecting and Reporting Malicious Software
4/27/05
Information System Activity Review
4/27/05
Password Management
4/27/05
Person-Entity Authentication
4/27/05
Risk
Analysis and Risk Management
4/27/05
Security Incident, Response and Reporting
4/27/05
8/2/2006
4/27/05
Workforce Authorization, Supervision and Clearance
4/27/05
Workstation Use & Security
4/27/05
Disaster Recovery Plan and Emergency Model Operation
4/27/05
insert snippet content here