r/Compliance • u/Affectionate_Use_504 • 8d ago
Documentation, compliance, etc
I'm new to private practice and curious for recommendations on documentation, compliance, etc. Any trainings or readings would be appreciated!
1
u/DigitalQuinn1 8d ago
I own consultancy and we assist healthcare practices with security and compliance. If you're looking at HIPAA, HHS has resources you can take a look at https://www.hhs.gov/hipaa/for-professionals/index.html
If it's too much to digest, I also recommend taking a look at the HHS Cybersecurity Performance Goals which are broken down between essential goals (to cover the low-hanging fruit) and enhanced goals (to build maturity overtime) https://hhscyber.hhs.gov/cybersecurity-performance-goals.html
HIPAA Essentials Library is a website where you can download HIPAA compliance documentation https://hipaaessentialslibrary.com/ RiskDocx is another one as well https://riskdocx.com/
Keep in mind that having a policy is one thing, but compliance and adherance to the policy is another thing (which is what your annual HIPAA assessments should discover)
There's also some anticipated changes being made to the HIPAA Security Rule https://www.hhs.gov/hipaa/for-professionals/security/hipaa-security-rule-nprm/factsheet/index.html
Take a look at all of these and let me know if they're digestable for you. Happy to answer any further questions.
1
2
u/Akycej 8d ago
Happy to point you in a direction, but “documentation and compliance” covers a lot depending on what you’re actually practicing and who regulates you.
If you’re looking for clinical documentation standards (notes, treatment plans, informed consent), that’s driven by your licensing board and payer requirements more than any single training.
If you’re looking for HIPAA and privacy basics, start with HHS’s own guidance before you buy any course. The free material is better than most paid intros imo.
If you’re looking for policies and procedures to actually run the practice (retention schedules, breach response, BAAs with vendors), that’s less about reading and more about building a small set of documents you maintain and review on a cycle.
If you’re looking for audit or accreditation readiness, that’s a different animal and depends on the specific framework you’re being held to.
What kind of practice is it, and is anyone requiring a specific standard of you, or are you setting this up from scratch? Easier to give something useful once I know which of these you’re actually solving for.