Start Free Assessment

HIPAA Policy Review Schedule: Annual Update Checklist

HIPAA requires covered entities to maintain comprehensive written policies and procedures that address privacy and security requirements.

This guide provides a complete schedule for reviewing and updating your HIPAA policies annually. Learn which policies to review, what triggers additional reviews, how to document changes, and how to communicate updates to your organization and patients.

HIPAA Policy Requirements Overview

HIPAA requires organizations to develop, implement, and maintain comprehensive written privacy and security policies and procedures. These policies must be:

  • Documented in writing and maintained for at least 6 years
  • Reviewed and updated as needed when the environment or operations change (45 CFR 164.316(b)(2)(iii)); reviewing at least annually is a common best practice
  • Based on current HIPAA regulations and organizational practices
  • Made available to all workforce members
  • Communicated to patients as required by the Privacy Rule

Note: Updated policies should reflect current organizational practices. If your policies don't match your actual operations, you're creating audit risk.

Core HIPAA Policies Required

1. Privacy Policy

Describes how your organization uses and protects PHI. Required by HIPAA Privacy Rule.

  • Notice of Privacy Practices
  • Uses and disclosures of PHI
  • Patient rights (access, amendment, restrictions)
  • Authorization procedures

2. Security Policy

Addresses protection of ePHI through administrative, physical, and technical safeguards.

  • Access controls and authentication
  • Encryption standards
  • Audit logging and monitoring
  • System security requirements

3. Breach Notification Policy

Procedures for identifying, investigating, and notifying of security breaches.

  • Breach definition and assessment
  • Investigation procedures
  • Notification timelines
  • Documentation requirements

4. Acceptable Use Policy

Defines appropriate and inappropriate use of IT resources and PHI access.

  • System use authorization
  • Prohibited activities
  • Consequences for violations
  • Monitoring and enforcement

5. Access Control Policy

Describes authorization, authentication, and access management procedures.

  • User provisioning/deprovisioning
  • Role-based access control
  • Least privilege principle
  • Regular access reviews

6. Password Policy

Requirements for password complexity, creation, and management.

  • Password complexity requirements
  • Change frequency
  • Reuse restrictions
  • Storage and protection

7. Incident Response Plan

Procedures for identifying, responding to, and documenting security incidents.

  • Incident definition
  • Detection and reporting procedures
  • Investigation and containment
  • Recovery and remediation

8. Business Associate Policy

Requirements for managing vendors and third parties with PHI access.

  • Business Associate Agreement requirements
  • Vendor assessment procedures
  • Ongoing monitoring
  • Remediation procedures

9. Audit Logging Policy

Standards for system audit logs, monitoring, and retention.

  • What must be logged
  • Log retention period
  • Review frequency
  • Anomaly detection

Annual Policy Review Schedule

Q1
Jan-Mar

Planning & Schedule Development

At the beginning of the year, schedule policy reviews for all required policies. Assign ownership for each policy review to specific individuals or departments.

Q2
Apr-Jun

Privacy & Breach Notification Policy Review

Review privacy policy and Notice of Privacy Practices. Verify breach notification procedures are current. Check if any regulatory changes require updates.

Q3
Jul-Sep

Security & Technical Policies Review

Review security policy, access control policy, password policy, and audit logging requirements. Update based on new systems, technology changes, or identified gaps.

Q4
Oct-Dec

Incident Response & Business Associate Reviews

Review incident response procedures and business associate management policies. Compile all updates, obtain approval, and prepare for implementation in the new year.

Policy Review Checklist

Standard Policy Review Items

Last Review Date: When was this policy last reviewed and updated?
Regulatory Changes: Have there been any HIPAA regulatory changes affecting this policy?
System Changes: Have new systems, technologies, or applications been implemented requiring policy updates?
Incident Response: Have any security incidents or breaches occurred since last review requiring changes?
Audit Findings: Have any audit findings or gaps identified since last review?
Practice Changes: Have organizational practices changed requiring policy updates?
Accuracy: Does the policy accurately reflect current operations and procedures?
Completeness: Are all HIPAA-required elements covered in the policy?
Training Updates: If policy changed significantly, was training conducted?
Documentation: Is the review documented with date, reviewer name, and any changes made?
Approval: Has the updated policy been approved by appropriate leadership?
Distribution: Have updated policies been distributed to all affected workforce members?

Triggers for Additional Policy Reviews

Review Policies When:

Security Incident or Breach Occurs

After any breach or security incident, review policies to determine if the incident could have been prevented with stronger policies or procedures.

New Systems or Technology Implemented

When implementing new IT systems, applications, or cloud services, update security and access control policies to address new systems.

Regulatory Changes

When HIPAA regulations are updated or new guidance issued by OCR, review and update affected policies immediately.

Failed Audit Findings

When compliance audits identify gaps or violations, update policies to close identified gaps.

Organizational Restructuring

When departments are reorganized, staff roles change, or major operational changes occur, update relevant policies.

New Locations or Services

When expanding to new locations or adding new healthcare services, review policies for applicability and necessary updates.

Mergers or Acquisitions

When merging with other organizations, standardize policies across the combined entity.

Workforce Feedback

When staff members report that policies don't align with actual practices, investigate and update policies.

Documentation & Patient Communication

Documenting Policy Changes

For each policy review and update, maintain documentation including:

  • Date of review
  • Who conducted the review
  • What changes were made and why
  • Who approved the changes
  • Date changes became effective
  • How changes were communicated to staff

Communicating Changes to Patients

If you make material changes to your privacy practices:

  • Less Restrictive Changes: Can be included in the next Notice of Privacy Practices provided to patients
  • More Restrictive Changes: Must notify affected individuals at least 30 days before implementation
  • Notification Method: Through mail, email, or on-site notification depending on your organization
  • All Changes: Updated Notice of Privacy Practices should be posted and available

Communicating Changes to Workforce

When policies are updated, ensure all affected workforce members are informed:

  • Distribute updated policies to all staff
  • Conduct training on significant policy changes
  • Allow time for questions and clarification
  • Require acknowledgment of policy receipt
  • Monitor compliance with updated policies

Frequently Asked Questions

How often should HIPAA policies be reviewed?
HIPAA policies should be reviewed and updated at least annually. Additional reviews should be conducted when significant changes occur such as new systems, organizational restructuring, regulatory changes, or after security incidents. Many organizations conduct quarterly or semi-annual reviews to ensure policies remain current.
Which policies are required under HIPAA?
Required policies include: privacy policy, security policy, breach notification policy, acceptable use policy, access control policy, password policy, incident response procedure, business associate agreement, and audit logging policy. You may need additional policies based on your specific organizational circumstances.
When should policy changes be communicated to patients?
Material changes to privacy practices must be communicated to patients. If changes are less restrictive, notify with the next Notice of Privacy Practices. If more restrictive, notify at least 30 days before implementation. All changes should be documented.
Can policies reference other documents or appendices?
Yes, policies can reference other documents, but all referenced materials must be maintained and kept current. When the reference documents change, review your policy to ensure it still accurately describes the process.

Organize Your Annual Policy Review

Get templates, review checklists, and communication materials for your policy review process.

Get Policy Templates