HIPAA Controls - Tips and Tricks
A list of all updates that will need to be made to the control library for HIPAA controls
Written By Micah
When using Strike Graph to manage your controls and adding on the HIPAA framework, we recommend making a few updates to the control language to cover additional regulations. You can use the guidance below to make these changes to the controls within your Control Library and to activate additional controls that may be relevant to your organization.
Remember, you can and should edit the control descriptions to ensure that they accurately describe your processes.
Data Breach Policy
If relevant to your business model, add the following sentence to the existing control description: The breach procedures include specific steps that need to be taken by Business Associates when notifying covered entities.
Data Retention/ Deletion
Add the following sentence to the control description: All HIPAA-related documentation is retained for a minimum period of six (6) years from the date of its creation or modification, or the date when it was last in effect.
Disciplinary Process
Replace the existing control description with the following: A Sanctions Policy is in place for the appropriate, fair, and consistent sanctions for workforce members who fail to follow established policies and procedures or commit various offenses.
Group Health Plan
This is a suggested control for Covered Entities and Group Health Plans. If it is not relevant to your business, you can ignore this control.
HHS Notification
This is a suggested control for Covered Entities. If it is not relevant to your business, you can ignore this control.
Logical Access - Clearinghouse
This is a suggested control for Covered Entities and Clearinghouses. If it is not relevant to your business, you can ignore this control.
Maintenance Record
Add the following sentence to the end of the existing control description: A HIPAA Maintenance Records Policy is in place.