HIPAA Security Rule

Author:  Karla Davis
                    Goodwill Industries Director of Finance & IT
                    Ntech Steering Committee Member

The HIPAA Security Rule is effective April 21, 2005.  Small health plans have until April 21, 2006 to become compliant.  Here are two templates that you can use in this effort.

The Excel worksheet provides a very brief summary of the Standard and a notation of whether the Standard is Required (R) or Addressable (A).  Remember that Addressable Standards are not Optional Standards.  The Standard must still be considered, and that consideration documented, explaining why the Standard is not applicable at the current time either because it simply doesn't apply to the work the agency carries out or because there is a circumstance at the agency that meets the Standard in another way. 

Use the worksheet to assign tasks and due dates for documentation related to the Standards.

Click here for the Excel file

The Word document is a password protected form.  You can use it as is by typing in your own agency name in the heading each time.  If you are familiar with forms, you may use the password (hipaa) to open the form and enter your own agency name in the heading, replacing the text field.  You must remember to protect the form again for the other fields to work properly. 

Using a form such as this will enable different people to work on different Standards but still have a final document that looks the same.

Click here for Word Form

The Regs were published in the Federal Register on Feb. 20, 2003.

Click here for a .pdf of the Regs