2.6 The Privacy Policy Set: Operational Procedures, Retention Schedules and Industry-Participant Agreements
Key Takeaways
- 45 CFR 164.530(i) requires covered entities to implement written privacy policies and procedures and to change them promptly when law or practice changes; 164.530(j) requires six-year retention of every superseded version.
- The six-year HIPAA retention clock runs from creation or from the date the document was last in effect, whichever is later — it is not a six-year medical record retention rule.
- Federal law sets no national medical record retention period; state statutes, Medicare Conditions of Participation, and payer contracts set the operative floor and are frequently longer than six years.
- Relationships with payors, referral partners, physician practices, and IT providers each require a specific instrument — BAA, data use agreement, OHCA participation document, or a plain confidentiality clause — and choosing the wrong one is itself a policy failure.
- A defensible policy set is inventoried, owner-assigned, version-controlled, and on a scheduled review cycle rather than rewritten reactively after each incident.
The Privacy Policy Set: Operational Procedures, Retention Schedules and Industry-Participant Agreements
Two outline tasks meet in this section. Task 1.A requires the privacy officer to develop, review, or update operational policies and procedures, naming HIPAA Privacy and Security, FERPA, GINA, non-retaliation, record retention, and disciplinary policies. Task 1.E requires the same for policies on relationships with other industry participants — hospitals, physicians, payors, IT providers, and vendors.
Both are maintenance tasks, and maintenance is where programs quietly fail. A policy binder assembled in 2013 and never re-opened is not evidence of compliance; under § 164.530(i)(2)(i) it is evidence of a violation, because the rule requires the entity to change its policies as necessary and appropriate to comply with changes in law.
1. The Mandatory Written Policy Set
Section 164.530(i)(1) is short and absolute: a covered entity must implement policies and procedures with respect to PHI that are designed to comply with the Privacy Rule, reasonably designed for the size and type of activities the entity undertakes. In practice, an OCR data request will name most of the following.
| Policy Domain | What the Policy Must Actually Decide | Governing Cite |
|---|---|---|
| Uses and disclosures | TPO boundaries, minimum necessary determinations by role, public-interest disclosure approvals | § 164.502, § 164.506, § 164.512 |
| Authorizations | Who validates elements, how revocations are processed, where signed forms live | § 164.508 |
| Individual rights | Access, amendment, accounting, restrictions, confidential communications — with named owners and clocks | §§ 164.524–164.528 |
| Notice of Privacy Practices | Content, distribution, acknowledgment, website posting, material-change republication | § 164.520 |
| Workforce training | Timing triggers, role-based curricula, documentation | § 164.530(b) |
| Sanctions | Tiered discipline, consistency review, documentation | § 164.530(e) |
| Non-retaliation and non-waiver | Protection for complainants and witnesses; no conditioning treatment on waiver | § 164.530(g), (h) |
| Mitigation | Duty to mitigate known harmful effects of an impermissible use or disclosure | § 164.530(f) |
| Safeguards | Administrative, technical, and physical safeguards for PHI in every medium | § 164.530(c) |
| Complaints | Internal complaint process and the contact person or office | § 164.530(d) |
| Breach response | Discovery, four-factor assessment, notification, documentation | Subpart D |
| Documentation and retention | Six-year retention of policies, notices, designations, and required records | § 164.530(j) |
Adjacent statutes the outline names explicitly, each of which needs at least a policy paragraph:
- FERPA — treatment records of eligible students at a school that provides health services are generally FERPA education records, not PHI. The policy must tell staff which record system governs at the student health center.
- GINA — genetic information is health information under HIPAA, and Title I bars group health plans from using it for underwriting. A health system that also sponsors its own employee health plan touches both roles.
- Non-retaliation — required by § 164.530(g), and the operational hinge on which the internal reporting program in Chapter 7 depends.
2. Retention: Two Clocks That Are Constantly Confused
This is one of the highest-yield distinctions in the entire outline, and candidates get it wrong routinely.
+---------------------------------------------------------------------------------------------------+
| TWO RETENTION CLOCKS, TWO DIFFERENT SUBJECTS |
| |
| CLOCK 1: HIPAA DOCUMENTATION RETENTION (45 CFR 164.530(j)) |
| • Subject: PROGRAM DOCUMENTS - policies, procedures, notices, authorizations kept as required, |
| hybrid/ACE designations, complaint records, sanction records, training logs, breach risk |
| assessments, accounting logs. |
| • Period: SIX YEARS from the date created OR the date it was LAST IN EFFECT, whichever is later. |
| • Consequence: a policy in force 2014-2024 must be retained until 2030, not 2020. |
| |
| CLOCK 2: MEDICAL RECORD RETENTION |
| • Subject: THE CLINICAL RECORD ITSELF. |
| • Period: HIPAA SETS NONE. Governed by state law, Medicare Conditions of Participation, |
| professional licensure rules, payer contracts, and statutes of limitation - commonly 7 to 10 |
| years for adults and until majority plus several years for minors. |
| • Consequence: "HIPAA says seven years" is a false statement. HIPAA says nothing. |
+---------------------------------------------------------------------------------------------------+
A defensible retention schedule therefore has three columns for every record class: the HIPAA documentation requirement, the longest applicable state or payer requirement, and the operational disposition rule that adopts whichever is longer. Add a fourth column for legal hold, which suspends destruction entirely once litigation or a regulatory investigation is reasonably anticipated. The most damaging retention failure in practice is not keeping too little — it is destroying records on schedule after a preservation duty attached.
3. Policies Governing Relationships With Other Industry Participants
Task 1.E is really a question of instrument selection. The privacy officer's job is to look at a proposed relationship and name the correct legal vehicle before the data moves.
| Counterparty and Purpose | Correct Instrument | Why Not the Others |
|---|---|---|
| Billing company, transcription vendor, cloud EHR host, coding auditor | Business associate agreement (§ 164.504(e)) | They create, receive, maintain, or transmit PHI on your behalf |
| Independent medical staff, joint credentialing and quality with the hospital | OHCA participation documentation | Neither party acts on the other's behalf; a BAA misdescribes the relationship |
| Affiliate under common ownership | ACE designation | PHI moves as internal use; a BAA between them is unnecessary |
| Researcher receiving a limited data set | Data use agreement (§ 164.514(e)) | An LDS is not de-identified; a DUA, not a BAA, is the required instrument |
| Health plan requesting records for payment or its own operations | No agreement needed — § 164.506 permits the disclosure | A payor receiving PHI for its own payment purposes is not your business associate |
| Health plan performing a function for you (for example, a plan-run care management program using your data) | BAA | Now it is acting on your behalf |
| Referring physician practice sending or receiving PHI for treatment | No agreement needed — treatment disclosure under § 164.506 | Provider-to-provider treatment exchange never requires a BAA |
| IT provider with only incidental or transient access, e.g. an ISP | Conduit — no BAA | Persistent storage defeats the conduit exception |
[!CAUTION] The Reflexive BAA. Contracting teams under time pressure default to "send them a BAA" for every counterparty. Executing a BAA with a payor that is receiving PHI for its own payment purposes, or with a referring practice, does not merely waste effort — it misstates the parties' obligations, creates contractual duties that do not track the regulation, and can imply agency where none exists. Task 1.E rewards knowing which instrument is correct, not which is most cautious.
What Each Relationship Policy Should Fix
- Trigger — the event that requires privacy review (new vendor, new data feed, new affiliation, new interface).
- Owner — who performs the instrument-selection analysis and signs off before data moves.
- Minimum data set — the narrowest PHI that satisfies the purpose, documented at approval.
- Term and termination — return or destruction of PHI, and continued confidentiality after termination.
- Audit and reporting — the counterparty's obligation to report incidents and to permit review.
4. Keeping the Set Alive
A policy set is a managed inventory, not a binder. The minimum operating discipline:
- Inventory every privacy policy with an ID, an accountable owner, an effective date, and a next-review date.
- Review cycle of no more than two years for every policy, with immediate off-cycle review triggered by a rule change, an enforcement action against a peer, a recurring incident type, or a new service line.
- Version control that preserves every superseded version with its effective and end dates — the § 164.530(j) obligation is impossible to satisfy if the content management system overwrites in place.
- Change log capturing what changed, why, who approved it, and the date the workforce was notified.
- Traceability from each policy back to the regulatory citation or risk-assessment finding that requires it, so that reviewers can prove the set is complete rather than merely long.
A hospital's privacy policy on authorizations was in effect from March 2016 until it was replaced in March 2026. Under 45 CFR 164.530(j), until when must the superseded version be retained?
A hospital contracts with a commercial health plan. Under the contract, the plan receives claims and clinical documentation so it can adjudicate payment for its members. The contracting department asks the privacy officer whether a business associate agreement is required. What is the correct answer?
A health system's counsel asks how long HIPAA requires medical records to be retained. What is the accurate response?