164.316(a) Policies and Procedures

Policies and Procedures

High Risk Complex High

Implement reasonable and appropriate policies and procedures to comply with the standards, implementation specifications, or other requirements of this subpart.

Implementation Guidance

Implement reasonable and appropriate policies and procedures to comply with the standards, implementation specifications and other requirements of the Security Rule, taking into account the factors at 164.306(b)(2). A covered entity or business associate may change its policies and procedures at any time, provided the changes are documented and implemented in line with 164.316.

Policies must map to the rule and to your own environment. A purchased template adopted without tailoring is a recurring finding, because the policy describes controls the organisation does not operate — which is worse than an acknowledged gap, since it evidences a failure to know your own environment.

Implementation approach:
• Build a policy set that covers every standard and addressable specification, and record where each is addressed
• Distinguish policy from procedure: policy states what and why; procedure states who, how and how often. Auditors ask for both, and organisations most often have only the first
• Tailor to your systems, size, complexity and the risk analysis findings. The 164.306(b)(2) factors — size and capability, technical infrastructure, cost, and the probability and criticality of risks — are the stated basis for reasonableness
• Have each policy formally approved by the Security Officer or an authorised body, with the approval dated
• Version every document, and keep superseded versions; you must be able to show what was in force at any past date
• Distribute so the workforce can actually reach the current version, and record acknowledgement
• Review at least annually, and on any material change to operations, technology or regulation. Record the review even when nothing changes — an undated policy is treated as unmaintained
• Where a policy exists but is not followed, you hold documented evidence of your own non-compliance; fix the practice or fix the policy

Maintain a control-to-policy matrix. It is the single most useful artefact for demonstrating coverage, and it makes gaps visible to you before they are visible to a regulator.

Required Documentation

• Complete policy and procedure set covering every Security Rule standard and specification
• Control-to-policy matrix mapping each requirement to the document addressing it
• Documented decisions for every addressable specification, including equivalent alternatives
• Approval records showing approver, role and date for each document
• Version history, with superseded versions retained
• Distribution and workforce acknowledgement records
• Annual review records, including reviews that resulted in no change
• Change log capturing what changed, why, and when it took effect
• Evidence that procedures reflect actual operating practice
• Retention evidence meeting the six-year requirement at 164.316(b)(2)

Best Practices

• Maintain a control-to-policy matrix so coverage and gaps are both visible
• Write procedures that name the responsible role and the frequency, so they are testable
• Tailor every document to your actual systems; generic templates produce findings
• Version and date everything, and retain superseded copies
• Review annually on a schedule, and record the review even when unchanged
• Tie policy updates to change control so operational changes trigger document updates
• Capture workforce acknowledgement at induction and after material revisions
• Record the reasoning for addressable specifications inside or alongside the relevant policy
• Keep documents readable; policies nobody can follow are not implemented in practice

Common Violations

• Purchased templates adopted verbatim, describing controls the organisation does not operate
• Policies present with no corresponding procedures, so nobody knows who does what
• Documents with no approval date, owner or version
• No review for several years, leaving policies describing retired systems
• Addressable specifications passed over with no documented decision
• Policies that contradict observed practice, evidencing non-compliance in the organisation's own records
• Superseded versions discarded, making it impossible to show what was in force historically
• No workforce acknowledgement records
• Whole standards unaddressed because no coverage mapping exists

Testing Procedures

• Compare the policy set against every Security Rule standard and specification to identify gaps
• Confirm each addressable specification has a documented decision, not silence
• Check that every document carries an owner, approval date and version
• Sample policies and confirm a corresponding procedure exists with named roles and frequencies
• Interview staff and compare what they actually do against the documented procedure
• Confirm review dates are current and that reviews are evidenced even where nothing changed
• Confirm workforce acknowledgement records exist and cover current staff
• Retrieve a superseded version to confirm historic versions are retained and identifiable
• Verify the policies reflect this organisation's systems rather than generic template content
• Trace a recent operational change through to the policy update it should have triggered

Implementation Resources

Download expert-developed templates and checklists to implement this control:

Quick Facts

Control ID 164.316(a)
Category Policies and Procedures
Risk Level High
Difficulty Complex
Est. Cost High
Timeframe 3-6 months
Last Updated Sep 3, 2026

Need Help Implementing This Control?

Our certified HIPAA experts can help you implement this control correctly and efficiently.