Skip to content

globerhofer/HIPAA-policies

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

21 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

#TODO - adjust for Pact

Catalyze HIPAA Compliance Policies

HIPAA compliance is complicated, but it doesn't have to be. Catalyze helps relieve the technical burden with our HIPAA-compliant cloud computing platform and solutions for healthcare.

In an effort to make compliance as easy as possible for companies working with protected health information (PHI), we decided to open source our company policies.

Our policies have been written with modern, cloud-based technology organizations in mind. We looked far and wide for policy examples that fit our company, and couldn't find any. So we wrote our own. Importantly, these policies have been through three external audits—two HIPAA audits and one HITRUST audit.

Do you handle PHI and not yet have your own HIPAA policies in place? Hopefully these policies can help you get started.

Why did we open source these policies?

HIPAA compliance has two halves. The first half includes all technical guidelines, both physical and digital. Encryption, logging, monitoring, backup - these are just a few examples of HIPAA technical requirements. The Catalyze platform addresses the technical requirements of HIPAA for our customers.

The second half of HIPAA is focused on administrative and organizational activities. This includes signing Business Associate Agreements (BAAs), risk management procedures, and policies for training, among other things. Crafting company policies that align with HIPAA administrative guidelines are straightforward, but an immense burden.

When we were creating our policies, we found lots of policy templates for healthcare providers (covered entities), but nothing for modern health technology companies. We spent a lot of time and effort writing our policies, then adapting them to meet the demands of external audits. We don't want people to reinvent the wheel; trust us, it's not fun. We also feel a broader community can improve these polices over time, making them better for everybody.

By open sourcing our own company policies, we hope other healthcare companies will benefit. It aligns with our company mission: to help you focus on fixing healthcare without spending all of your time on HIPAA.

What do I do with these policies?

As a healthcare company, it's critical you create and maintain your own policies to meet HIPAA requirements. To make use of our policies, we recommend the following steps.

  1. Read through all the enclosed policies to get an understanding of the structure.
  2. Download and adjust the policies to meet the specific needs of your organization.
  3. Comb through the policies for mentions of Catalyze or our business and change to appropriate references to your company.
  4. Implement internal procedures and technical controls to assure you're inline with the policies you are adopting. In the case of Catalyze customers, certain policies can be adopted in their entirety as Catalyze has implemented procedures and technical controls that our customers inherit.
  5. Publish your policies in a publicly available location. The files are markdown, so you may need to convert to HTML if you don't have a publishing platform capable of markdown format. You can either create an index page linking to each individual policy, or create a single page listing all the policies in line, much like we did. You can certainly choose to keep you policies private, but we have discovered that making our policies public helps us when we talk to large healthcare enterprises.
  6. Use Git for version control. We've discovered it's a great way to mainatin documentation for audits.

Who is behind this?

Catalyze.io, healthcare's trusted HIPAA-compliant platform.

We help healthcare companies who handle PHI, both business associates and covered entities, maintain compliance with our Platform as a Service, Mobile Backend as a Service, and managed data integration services. Think Heroku and Parse for healthcare. In addition, we also provide HL7 Integration for those who need to communicate with EHR vendors like Epic or Cerner.

To learn more, shoot us an email at hello@catalyze.io. We'd love to hear from you!

License

All policies are licensed under CC BY-SA 4.0.

Policy Index

Each policy is included as it's own markdown file in case you want to cherry pick specific policies. If you currently have no policies in place, we encourage you to consider utilizing all policies.

About

Pact HIPAA Policy Documentation

coming soon.

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Contributors 4

  •  
  •  
  •  
  •