Saved · this browser
Chapter 7 · §164.316

Your Paperwork

Everything you’ve built so far only counts if you can put your hands on it later. Chapters 1–6 did the work — your BAA list, device inventory, password rules, workspace setup, incident plan, and training record. This chapter is about keeping it: written down, kept for six years, within reach of anyone who works with you, and looked over when things change.

Why this chapter exists, in plain English

§164.316 is the rule that says all the work you’ve done so far has to be written down, kept for six years, available to the people who follow it, and reviewed when things change. It’s the closing bracket on the administrative safeguards — §164.308 asked you to do the work; §164.316 asks you to preserve it.

The good news: chapters 1–6 have been building your HIPAA Security Manual the whole time. Your BAA list, device inventory, password procedures, workspace safeguards, incident-response plan, and training record are already the written policies and procedures the rule asks for. This chapter is about keeping them.

Four topics, one per part of the rule. How often you’ll review, and the date you last reviewed, live inside the last topic — because that’s exactly what §164.316(b)(2)(iii) asks for, not a separate question on its own.

01

The four topics

4 questions
§164.316(b)(1)

Your written manual:

one dated document built from your earlier chapters

The good news: Chapters 1–6 have been building this for you. Each chapter output — your BAA list, your device inventory, your password procedures, your workspace safeguards, your incident-response plan, your training record — is a section of your HIPAA Security Manual.

HIPAAPath produces that manual for you. Once you’ve worked through all nine chapters, download your complete HIPAA Security Manual — a dated, auditor-ready PDF — directly from HIPAAPath.

§164.316(b)(2)(i)

Keeping it for six years:

when the six-year clock starts, and where old versions go

First, the thing that trips everyone up: this six-year rule is about your policy paperwork — your written manual and its old versions — not your clients’ clinical records. How long you keep therapy records is a separate question, set by your state and your professional ethics (often seven to ten years); this chapter isn’t about those.

Within that, here’s what people miss: the six-year clock doesn’t start when you first wrote a policy — it starts when you last used it. So a policy you stopped using last year still has to be kept for six more years from the day you stopped, not from the day you wrote it.

The easiest way to handle this: keep your current manual in one place. When you update a policy, move the old version into a folder with the year in its name (like archive-2026/). Once a year, delete anything you stopped using more than six years ago. That’s it.

§164.316(b)(2)(ii)

Making it available:

reachable in under a minute, by everyone who follows it

For a solo or small practice, this is mostly a “do I know where it is” question. If you can pull up the manual from your laptop or phone in under a minute, you’ve met the standard.

For a two-person office, both of you need to reach the current version — a shared Drive or OneDrive folder is the usual way. If someone who works with you can’t get to the policies they’re supposed to follow, the rule isn’t met — and that’s something audits often catch.

§164.316(b)(2)(iii)

Your review routine:

how often you check, and what makes you check sooner

There are two reasons to look over your manual. The first is on a schedule you pick (once a year is the simplest). The second is whenever something big changes that could affect your patients’ health information — a new staff member, a new EHR (the software where you keep patient records), a new cloud service, a lost device, or a security scare. When one of those happens, look over the parts it touches; don’t wait for your yearly check.

How often you’ll review

Once a year, or when something changes — pick the one you’ll actually do.

The rule asks you to look things over on a schedule and whenever something big changes — so both answers below are fine. Checking once a year is what’s normally expected, and it lines up nicely with the training check in Chapter 6, so you can do them together. Checking only when something changes works too — but only if you write down what counts as a change (new staff, new software, a new service or vendor, a security scare) and you actually look when one happens. And if a whole year goes by with no changes, you’re due for a look anyway. Pick the one you’ll really do.

Last reviewed

First time through? Today is the right answer — working through this chapter is a review.

02

Where you stand

Not quite there yet

Answer all four topics, pick how often you’ll review, and set your last-reviewed date to see where you stand.

Can you help us make this better?

How easy is HIPAAPath to use so far?
HardEasy

Please don’t include patient information — this goes to us by email.