What real HIPAA policies look like, and why templates fail the audit

A signed policy that does not match your clinic is not protection, it is evidence against you. OCR has penalized a behavioral health provider for exactly that. What a real policy is made of, using the one every clinic needs, and a five-question test for the ones on your shelf.

Last verified: 2026-07-14

An investigator sits across from an ABA clinic owner and asks for the termination policy: what happens to a departing employee’s access.

The owner hands it over, and it looks good. It is signed, it is dated, it says access to all systems is revoked within twenty-four hours of separation. Exactly what a policy should say.

Then the investigator asks one question. Which systems?

The owner starts listing from memory. The practice management system, email, the scheduling app. And forgets the fax portal, where a biller who left two months ago still has a live login. The policy did not fail because it was missing. It failed because it was not true. And now the gap between what it promised and what the clinic actually did is written down, signed, and sitting in an investigator’s hands.

This is not hypothetical. OCR settled with a five-facility behavioral health provider, Anchorage Community Mental Health Services, for one hundred fifty thousand dollars, after finding that the organization had adopted sample policies years earlier that were not being followed. The document existed. It just was not true, and a breach turned that gap into a finding.

That is the standard this article is about. The document existing is not the test. The document being true is.

Why templates fail structurally, not by accident

A template is written before anyone knows your clinic exists. That is not a flaw in a particular template; it is the nature of the thing. Whoever wrote it had to describe a clinic they had never seen, which leaves them exactly two ways to write a sentence, and both fail.

“The document existing is not the test. The document being true is”

They can speak in generalities: “all systems containing electronic protected health information.” Checkable by no one. A new hire cannot execute it, because it does not say what the systems are. An auditor cannot verify it, because it commits to nothing specific enough to verify.

Or they can leave blanks: “revoke access to [LIST SYSTEMS HERE].” Which somebody fills in once, in 2023, and never touches again.

Out of that come the three policies that fail an audit:

The generic policy says nothing checkable, so it cannot guide a staff member on a Tuesday or satisfy an investigator on any day.

The stale policy was true the day it was signed and went quietly wrong the day the clinic added a scheduling app nobody wrote into it.

The aspirational policy describes a procedure the clinic does not actually perform, and it is the most dangerous of the three, because it is documented evidence of a standard the clinic set for itself and then failed to meet. A promise you do not keep is worse than a promise you never made.

What a real policy is actually made of

A real policy is a set of commitments conditioned on facts about this clinic. Take the termination policy, the one every clinic needs because everyone has had someone leave, and make it concrete.

A real termination policy names the actual systems a departing employee holds accounts on: the EHR by its name, the email suite, the billing clearinghouse, the fax portal, the parent portal. It names who performs the revocation. And it distinguishes two different acts that a template collapses into one line: revoking accounts, and collecting devices. Those are two lists and two motions. The laptop coming back is not the same as the login being killed, and a policy that treats them as one thing will miss one of them. The full checklist, all three lists, is worth having written down before you need it.

The rule for what goes in is simple and it cuts both ways. If the clinic does not use a system, the policy should not mention it. If the clinic does, the policy must. A policy padded with systems you do not have is as untrue as one missing systems you do.

This is not a stylistic preference. It is the tailoring requirement in the regulation itself: policies must be reasonably designed, taking into account the size and the type of activities of the clinic (45 CFR 164.530(i)(1)). A policy that could belong to any clinic in the country has not taken yours into account, and it says so on its face. The related duties (retention, availability, and review, all Required at 45 CFR 164.316) assume a document that describes a real operation. There is nothing to review against reality if the document was never about your reality to begin with.

The part nobody tells you: policies decay

Even a perfect policy does not stay perfect, because a clinic is a moving target. You add a vendor. Someone signs up for a new app. You switch from one EHR to another. Every one of those changes silently invalidates any policy that named the old world, and nothing announces it. The policy still sits on the shelf, still signed, now quietly wrong.

The traditional answer is an annual review. Think about what that actually means. The policy is allowed to be wrong for up to a year at a stretch, and the review itself is a human being rereading a document against their memory of the clinic, which is the same fallible memory that forgot the fax portal in the opening scene.

The structural answer is different. If the policy is composed from the clinic’s live inventory of systems, then when the inventory changes, the policy is flagged or regenerated to match. The review stops being archaeology and becomes confirmation: not “let me reconstruct what we do and compare it to this document,” but “the system says these are our login systems, is that still right.” That is a review a busy clinic can actually perform, because it is a question rather than an investigation.

The audit-gate test

Take any policy off your shelf and ask it five questions.

Does it name your actual systems, or does it say “all applicable systems”? A real policy names them. A template hides behind the general.

Could a new hire execute it as written, without asking anyone what it means? If the procedure only works when someone already knows the answer, the policy is not carrying the knowledge. The person is.

If you added a software tool last quarter, does the policy know? If the policy has no idea your clinic changed, it is describing a clinic you used to be.

Does it describe anything you do not actually do? Every aspirational sentence is a standard you have documented and are failing. Find them and either start doing them or stop claiming them.

When was it last reviewed against reality, rather than just re-signed? A signature is not a review. Re-signing a wrong document makes it a wrong document with a fresh date.

Two or more misses, and what you are holding is a template wearing a policy’s clothes.

The honest standard

A policy is evidence that you gave your workforce real instructions. Real instructions are specific, current, and true. They name the systems, they name the people, they match the clinic, and they change when the clinic changes.

Anything short of that is paperwork, and paperwork costs you twice: once when you buy it, and again at the audit, when the thing you bought to protect you turns out to be the clearest evidence that the program was never real. The deeper version of why the binder itself is the finding is worth reading next, but the short version is the one the investigator started with. Which systems? A real policy already answered.

The short version

  • A policy fails not only when it is missing, but when it does not match what the clinic actually does. OCR has settled a case on exactly that finding.
  • Templates fail structurally, not by accident: written before your clinic existed, they can only speak in generalities or blanks nobody keeps current.
  • A real policy names your actual systems, names who does what, and omits anything you do not use. If it would fit the clinic across town unchanged, it does not fit yours.
  • Policies decay silently. Every new vendor or app makes any policy that named the old setup quietly wrong, and an annual review is a year of being wrong at a time.
  • Five questions tell you whether a policy on your shelf is real or a template in disguise. Two or more misses is your answer.

This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.

Sources

A policy that is true the day it is read.

WiseUpHIPAA composes your policies from your clinic's live inventory: your actual systems, named. When the inventory changes, the policy is flagged, so review means confirming facts rather than digging through a document nobody has read since it was bought.