164.316(b)(1) Policies and Procedures

Documentation

High Risk Moderate Medium

Maintain the policies and procedures implemented to comply with this subpart in written (which may be electronic) form.

Implementation Guidance

Maintain the policies and procedures implemented to comply with this subpart in written form, which may be electronic. Where an action, activity or assessment is required to be documented, maintain a written record of it.

The second half is where organisations fail. Policies are usually written; the record of the required activities frequently is not. Under the Security Rule the evidence effectively is the compliance — an activity you cannot evidence is treated as an activity that did not happen.

Documentation must cover:
• Policies and procedures for every standard and implementation specification
• The risk analysis and risk management decisions, including accepted risks and why
• Decisions on every addressable specification, with equivalent alternatives where applicable
• Security incidents, their investigation and their outcomes
• Workforce training delivery, attendance and content version
• Sanctions applied under the sanction policy
• Information system activity reviews, including what was examined and what was found
• Periodic evaluations under 164.308(a)(8)
• Access authorisations, modifications and terminations
• Business associate agreements and related assurances
• Contingency plan testing and revision
• Facility access and maintenance records

Implementation approach:
- Assign an owner to each documentation type; unowned records are the ones that stop being kept
- Define where each record lives, so it can be produced quickly under time pressure
- Timestamp records at the time of the activity. Reconstructed evidence is visibly reconstructed and damages credibility
- Protect documentation integrity and restrict who can alter it
- Index the set so a regulator request can be answered in days rather than weeks
- Apply the six-year retention rule at 164.316(b)(2) consistently
- Include electronic evidence such as configuration exports, log extracts and ticket records

OCR investigations routinely begin with a documentation request. The speed and completeness of that response shapes everything that follows.

Required Documentation

• Complete written policy and procedure set, electronic form acceptable
• Documentation inventory listing each required record, its owner and its location
• Risk analysis reports and risk management decision records
• Addressable specification decision records
• Security incident files, including investigation and resolution
• Training records with dates, attendees and material version
• Sanction records where policy was breached
• Information system activity review records
• Periodic evaluation reports under 164.308(a)(8)
• Access authorisation, modification and termination records
• Business associate agreements and due diligence evidence
• Contingency plan test results and revisions
• Retention and disposal schedule aligned to 164.316(b)(2)

Best Practices

• Maintain a documentation inventory naming the owner and storage location for each record type
• Generate evidence as a by-product of the activity rather than as a separate later exercise
• Timestamp at the time of the activity; contemporaneous records carry far more weight
• Centralise compliance documentation in one indexed, access-controlled repository
• Automate collection where possible: log exports, configuration snapshots, ticket records
• Rehearse a regulator documentation request annually to find the gaps before OCR does
• Restrict who can alter compliance records, and log changes
• Align retention and disposal to the six-year rule with a written schedule
• Keep the index current so any record can be produced within days

Common Violations

• Policies documented but required activities not evidenced
• Risk analysis performed but never written up, or written up without a date
• Training delivered with no attendance record
• Activity reviews claimed but with no record of what was examined
• Addressable specification decisions never documented
• Records scattered across individuals' mailboxes and drives, unretrievable under pressure
• Evidence assembled after a regulator request, visibly reconstructed
• Retention shorter than six years, so historic evidence no longer exists
• No documentation owner, so record-keeping lapses unnoticed
• Sanctions applied but never recorded

Testing Procedures

• Request the documentation inventory and confirm each required record type is listed with an owner
• Sample each record type and confirm it exists, is dated and is retrievable
• Test retrieval speed by requesting a specific historic record without notice
• Confirm records are timestamped contemporaneously rather than assembled retrospectively
• Verify the risk analysis is documented, dated and covers the whole ePHI estate
• Confirm addressable specification decisions are recorded in writing
• Check training records reconcile against the current staff list
• Confirm activity review records show what was examined, not merely that review occurred
• Verify retention meets six years by retrieving a record from the earliest period
• Confirm documentation integrity controls prevent undetected alteration

Implementation Resources

Download expert-developed templates and checklists to implement this control:

Quick Facts

Control ID 164.316(b)(1)
Category Policies and Procedures
Risk Level High
Difficulty Moderate
Est. Cost Medium
Timeframe 2-4 months
Last Updated Sep 3, 2026

Need Help Implementing This Control?

Our certified HIPAA experts can help you implement this control correctly and efficiently.