[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-1-en-105":3,"doc-seo-162623-105":53,"doc-detail-162623-en":126},{"code":4,"msg":5,"data":6},0,"success",[7,14,19,24,29,34,39,44,49],{"id":8,"doc_module":9,"doc_module_name":10,"category_name":11,"show_sort_weight":12,"slug":13},11,1,"Template","Presentations",90,"presentations",{"id":15,"doc_module":9,"doc_module_name":10,"category_name":16,"show_sort_weight":17,"slug":18},12,"Resumes",80,"resumes",{"id":20,"doc_module":9,"doc_module_name":10,"category_name":21,"show_sort_weight":22,"slug":23},14,"Invoices",70,"invoices",{"id":25,"doc_module":9,"doc_module_name":10,"category_name":26,"show_sort_weight":27,"slug":28},15,"Posters",60,"posters",{"id":30,"doc_module":9,"doc_module_name":10,"category_name":31,"show_sort_weight":32,"slug":33},16,"Social Media",50,"social-media",{"id":35,"doc_module":9,"doc_module_name":10,"category_name":36,"show_sort_weight":37,"slug":38},17,"Forms",40,"forms",{"id":40,"doc_module":9,"doc_module_name":10,"category_name":41,"show_sort_weight":42,"slug":43},18,"Letters",30,"letters",{"id":45,"doc_module":9,"doc_module_name":10,"category_name":46,"show_sort_weight":47,"slug":48},21,"Paper Templates",5,"papers-templates",{"id":50,"doc_module":9,"doc_module_name":10,"category_name":51,"show_sort_weight":4,"slug":52},158,"General","general-158",{"code":4,"msg":54,"data":55},"ok",{"site_id":56,"language":57,"slug":58,"title":59,"keywords":60,"description":61,"schema_data":62,"social_meta":119,"head_meta":121,"extra_data":123,"updated_unix":125},105,"en","iowa-countyregion-policies-and-procedures-for-compliance-with-the-health-insurance-portability-and-accountability-act-of-1996-hipaa","Iowa County/Region Policies and Procedures for Compliance with the Health Insurance Portability and Accountability Act of 1996 - HIPAA","","HIPAA compliance policies and procedures template for Iowa counties and regions, outlining governance and operational requirements under the Health Insurance Portability and Accountability Act of 1996. Includes guidance for designating covered entities and roles, managing HIPAA records, and implementing a privacy manual covering permitted uses and disclosures of PHI, individual rights, authorizations, complaints, and data protections such as de-identified data and limited data sets. Provides breach notification tools, business associate requirements, and security manual controls spanning risk analysis, safeguards, workforce clearance, training, and security monitoring, updated through later amendments.",{"@graph":63,"@context":118},[64,80,101],{"@type":65,"itemListElement":66},"BreadcrumbList",[67,71,74,77],{"item":68,"name":69,"@type":70,"position":9},"https://docshare.wps.com","Home","ListItem",{"item":72,"name":10,"@type":70,"position":73},"https://docshare.wps.com/template/",2,{"item":75,"name":36,"@type":70,"position":76},"https://docshare.wps.com/template/forms/",3,{"item":78,"name":59,"@type":70,"position":79},"https://docshare.wps.com/template/iowa-countyregion-policies-and-procedures-for-compliance-with-the-health-insurance-portability-and-accountability-act-of-1996-hipaa/162623/",4,{"url":78,"name":59,"@type":81,"image":82,"author":87,"headline":59,"publisher":90,"fileFormat":93,"inLanguage":57,"description":61,"dateModified":94,"datePublished":95,"encodingFormat":93,"isAccessibleForFree":96,"interactionStatistic":97},"DigitalDocument",{"url":83,"@type":84,"width":85,"height":86},"https://docshare.wps.com/thumbnails/iowa-countyregion-policies-and-procedures-for-compliance-with-the-health-insurance-portability-and-accountability-act-of-1996-hipaa/162623.png","ImageObject",442,249,{"name":88,"@type":89},"Ava Thompson","Person",{"url":68,"name":91,"@type":92},"DocShare","Organization","application/vnd.openxmlformats-officedocument.wordprocessingml.document","2026-09-23","2026-08-30",true,{"@type":98,"interactionType":99,"userInteractionCount":47},"InteractionCounter",{"@type":100},"ViewAction",{"@type":102,"mainEntity":103},"FAQPage",[104,110,114],{"name":105,"@type":106,"acceptedAnswer":107},"What is the purpose of this HIPAA compliance manual for Iowa counties and regions?","Question",{"text":108,"@type":109},"It establishes policies and procedures to support compliance with HIPAA requirements, including privacy and security obligations for handling PHI.","Answer",{"name":111,"@type":106,"acceptedAnswer":112},"What privacy topics are covered in the HIPAA privacy manual?",{"text":113,"@type":109},"It covers permitted uses and disclosures of PHI, individual rights (access, requests, amendments), documentation and accounting, authorizations, confidentiality protections, breach notification, and related business associate responsibilities.",{"name":115,"@type":106,"acceptedAnswer":116},"Which security areas are addressed in the HIPAA security manual?",{"text":117,"@type":109},"It provides controls for general security compliance, assigned responsibilities, risk analysis and risk management, sanctions, workforce clearance, security training, and ongoing security activity review.","https://schema.org",{"og:url":78,"og:type":120,"og:title":59,"og:site_name":91,"og:description":61},"article",{"robots":122,"canonical":78},"index,follow",{"doc_id":124,"site_id":56},162623,1788127596,{"code":4,"msg":5,"data":127},{"doc_id":124,"user_id":128,"nickname":88,"user_avatar":129,"doc_module":9,"category_id":35,"category_name":36,"doc_title":59,"doc_description":61,"doc_content":130,"file_id":131,"file_url":132,"file_type":133,"file_size":134,"view_count":47,"is_deleted":4,"is_public":9,"is_downloadable":9,"audit_status":9,"page_count":135,"language":136,"language_code":57,"site_id":56,"html_lang":57,"table_of_contents":137,"faqs":138,"seo_title":139,"seo_description":61,"update_tm":125,"read_time":140},1649267921044,"https://us-avatar.wpscdn.com/avatar/1800007509477c92dfb?_k=1786009248482753345","[COUNTY/REGION NAME]\u000bPOLICIES AND PROCEDURES\u000b\u000bFOR\u000b\u000bCOMPLIANCE WITH THE\nHEALTH INSURANCE PORTABILITY\u000b\u000bAND ACCOUNTABILITY ACT OF 1996\u000b\u000b“HIPAA”\nAmended December 2013\nAmended June 2018\nThis HIPAA compliance manual was prepared for the benefit of the Iowa State Association of Counties in 2013. The manual was updated in 2018 to correct minor typographical errors and update the policy on Iowa law to include information about care coordination. No other amendments or updates have been made since that time to include any changes in the applicable laws or interpretations of the laws.  and has not been updated or amended since that time to include any changes in the applicable laws or interpretations of the laws.  This HIPAA compliance manual is not intended to be legal advice and should not be relied upon as a substitute for legal advice or professional services.  Persons seeking legal advice regarding the application of this HIPAA compliance manual, or HIPAA, should consult with an attorney.\nTABLE OF CONTENTS\nPage\n\u0013 TOC \\t \"Title,1,Title Appendix,2,Title TOC,1,Title 2,2\" \u0014Workforce Designation\t\u0013 PAGEREF _Toc522198791 \\h \u00148\u0015\nHybrid Entity Designation\t\u0013 PAGEREF _Toc522198792 \\h \u001410\u0015\nAffiliated Covered Entity Designation\t\u0013 PAGEREF _Toc522198793 \\h \u001411\u0015\nHIPAA Record Retention Policy\t\u0013 PAGEREF _Toc522198794 \\h \u001412\u0015\nHIPAA Privacy Manual\t\u0013 PAGEREF _Toc522198795 \\h \u001418\u0015\nOverview:  Handling Uses and Disclosures of PHI\t\u0013 PAGEREF _Toc522198796 \\h \u001419\u0015\nIowa Laws Requiring Greater Protections Policy\t\u0013 PAGEREF _Toc522198797 \\h \u001428\u0015\nAccessing PHI Policy\t\u0013 PAGEREF _Toc522198798 \\h \u001435\u0015\nIndividual Request for PHI\t\u0013 PAGEREF _Toc522198799 \\h \u001441\u0015\nNotice of Decision Regarding Individual Request for PHI\t\u0013 PAGEREF _Toc522198800 \\h \u001442\u0015\nDocumentation Policy\t\u0013 PAGEREF _Toc522198801 \\h \u001444\u0015\nAccounting of Disclosures Policy\t\u0013 PAGEREF _Toc522198802 \\h \u001446\u0015\nAccounting Disclosure Log\t\u0013 PAGEREF _Toc522198803 \\h \u001450\u0015\nRequest for Accounting of Disclosures\t\u0013 PAGEREF _Toc522198804 \\h \u001451\u0015\nAmending PHI Policy\t\u0013 PAGEREF _Toc522198805 \\h \u001452\u0015\nIndividual’s Request for Amendment of PHI\t\u0013 PAGEREF _Toc522198806 \\h \u001456\u0015\nRequests for Privacy Protection for PHI Policy\t\u0013 PAGEREF _Toc522198807 \\h \u001457\u0015\nRequest for Alternative Means or Location of Confidential Communications\t\u0013 PAGEREF _Toc522198808 \\h \u001460\u0015\nAuthorizations Policy\t\u0013 PAGEREF _Toc522198809 \\h \u001461\u0015\nAuthorization for Disclosure of PHI\t\u0013 PAGEREF _Toc522198810 \\h \u001468\u0015\nFamily, Friend Involvement/Personal Representatives and Deceased Individual Policy\t\u0013 PAGEREF _Toc522198811 \\h \u001470\u0015\nHealth Oversight Uses and Disclosures Policy\t\u0013 PAGEREF _Toc522198812 \\h \u001473\u0015\nJudicial or Administrative Purposes Disclosures Policy\t\u0013 PAGEREF _Toc522198813 \\h \u001476\u0015\nLaw Enforcement Disclosures Policy\t\u0013 PAGEREF _Toc522198814 \\h \u001478\u0015\nRequired By Law Disclosures Policy\t\u0013 PAGEREF _Toc522198815 \\h \u001482\u0015\nResearch Uses and Disclosures Policy\t\u0013 PAGEREF _Toc522198816 \\h \u001484\u0015\nSpecialized Government Functions Disclosures Policy\t\u0013 PAGEREF _Toc522198817 \\h \u001488\u0015\nSerious Threat to Health or Safety Disclosures Policy\t\u0013 PAGEREF _Toc522198818 \\h \u001491\u0015\nBreach Notification Policy\t\u0013 PAGEREF _Toc522198819 \\h \u001493\u0015\nBreach Notification Flowchart\t\u0013 PAGEREF _Toc522198820 \\h \u001499\u0015\nBreach Risk Assessment Tool\t\u0013 PAGEREF _Toc522198821 \\h \u0014103\u0015\nSample Breach Notification Letter\t\u0013 PAGEREF _Toc522198822 \\h \u0014105\u0015\nBusiness Associate Assurances Policy\t\u0013 PAGEREF _Toc522198823 \\h \u0014106\u0015\nBusiness Associate Agreement\t\u0013 PAGEREF _Toc522198824 \\h \u0014110\u0015\nComplaints, Non-Retaliation and Waiver of Rights Policy\t\u0013 PAGEREF _Toc522198825 \\h \u0014122\u0015\nConfidential Report of Concern\t\u0013 PAGEREF _Toc522198826 \\h \u0014125\u0015\nCompliance Report of Concern Investigation\t\u0013 PAGEREF _Toc522198827 \\h \u0014126\u0015\nHealth Privacy Complaint Form\t\u0013 PAGEREF _Toc522198828 \\h \u0014127\u0015\nDe-Identified Information and Re-Identification Policy\t\u0013 PAGEREF _Toc522198829 \\h \u0014128\u0015\nLimited Data Set Policy\t\u0013 PAGEREF _Toc522198830 \\h \u0014131\u0015\nData Use Agreement\t\u0013 PAGEREF _Toc522198831 \\h \u0014134\u0015\nGroup Health Plan Policy\t\u0013 PAGEREF _Toc522198832 \\h \u0014139\u0015\nHIPAA P","cbCainF1toaHYttI","https://ap.wps.com/l/cbCainF1toaHYttI","docx",281121,262,"English","# Workforce Designation\n## Hybrid Entity Designation\n## Affiliated Covered Entity Designation\n# HIPAA Record Retention Policy\n# HIPAA Privacy Manual\n## Overview: Handling Uses and Disclosures of PHI\n## Iowa Laws Requiring Greater Protections Policy\n## Accessing PHI Policy\n## Individual Request for PHI\n## Notice of Decision Regarding Individual Request for PHI\n## Documentation Policy\n## Accounting of Disclosures Policy\n## Amending PHI Policy\n## Authorizations Policy\n## Business Associate Assurances Policy\n## Complaints, Non-Retaliation and Waiver of Rights Policy\n## De-Identified Information and Re-Identification Policy\n# HIPAA Security Manual\n## General Security Compliance\n## Assigned Security Responsibility Policy\n## Risk Analysis Policy\n## Risk Management Policy\n## Training Policy\n## Information System Activity Review Policy","[{\"question\":\"What is the purpose of this HIPAA compliance manual for Iowa counties and regions?\",\"answer\":\"It establishes policies and procedures to support compliance with HIPAA requirements, including privacy and security obligations for handling PHI.\"},{\"question\":\"What privacy topics are covered in the HIPAA privacy manual?\",\"answer\":\"It covers permitted uses and disclosures of PHI, individual rights (access, requests, amendments), documentation and accounting, authorizations, confidentiality protections, breach notification, and related business associate responsibilities.\"},{\"question\":\"Which security areas are addressed in the HIPAA security manual?\",\"answer\":\"It provides controls for general security compliance, assigned responsibilities, risk analysis and risk management, sanctions, workforce clearance, security training, and ongoing security activity review.\"}]","Iowa County/Region Policies and Procedures for Compliance with the Health Insurance Portability and Accountability Act of 1996 - HIPAA | DOCX",92]