HIPAA GENERAL OPERATING POLICY #40
POLICIES AND PROCEDURES
I. General
The University of Maine System must implement policies and procedures with respect to PHI that are designed to comply with the standards and requirements of the regulations. The policies and procedures must be reasonably designed, considering the size and activities related to PHI of the HCC, to ensure compliance.
II. Changes to Policies and Procedures
a. The University must change its policies and procedures as necessary and appropriate to comply with changes in the law and regulations.
b. When the University changes a privacy practice that is stated in the notice, and makes corresponding changes to its policies and procedures, it may make the changes effective for PHI created or received prior to the effective date of the notice revision if it has included in the notice a statement reserving its right to make such a change in its privacy practices; or
c. The University may make any other changes to policies and procedures at any time, provided that the changes are documented and implemented in accordance with HIPAA documentation requirements.
III. Changes in Law
Whenever there is a change in law that necessitates a change to its policies or procedures, it must promptly document and implement the revised policy or procedure. If the change in law materially affects its notice, the University must promptly make the appropriate revisions to the notice. Nothing in this paragraph may be used to excuse a failure to comply with the law.
IV. Changes to Privacy Practices Stated in the Notice
a. To implement a change in its policies and procedures to reflect a change in a privacy practice that is stated in its notice, the University must:
i. Ensure that the policy or procedure, as revised to reflect a change in a privacy practice that is stated in its notice, complies with the regulations;
ii. Document the policy or procedure, as revised, as required by HIPAA documentation requirements ; and
iii. Revise the notice as required to state the changed practice and make the revised notice available as required. The University may not implement a change to a policy or procedure prior to the effective date of the revised notice
V. Changes to Other Policies and Procedures
The University may change, at any time, a policy or procedure that does not materially affect the content of the notice, provided that:
a. The policy or procedure, as revised, complies with the standards, requirements, and implementation specifications of the regulations; and
b. Prior to the effective date of the change, the policy or procedure, as revised, is documented as required by HIPAA documentation requirements.
