The purpose of this policy is to establish documentation requirements for data security policies and procedures in accord with standards, implementation specifications, or other requirements of the Health Insurance Portability and Accountability Act (HIPAA) Security Rule. (45 CFR § 164.316) Contracted agencies shall develop an internal policy and associated procedures that are consistent with their organizational practices and meet the requirements set forth in this policy. |