Document policies, procedures, actions, activities or assessments implemented by Health Insurance Portability and Accountability Act of 1996 (HIPAA) covered entities and business associates to comply with the Security Standards for the Protection of Electronic Protected Health Information provided at 45 CFR Subpart C, including 45 CFR § 164.306. These records, found in all media (paper, digital, or other), must include:
- policies, procedures, actions, activities or assessments implemented to comply with 45 CFR Subpart C, including audit logs.
These records may also include, but not limited to: