Navigating HIPAAgps

Ready to start your HIPAAgps journey?

In this set of slides, you’ll learn how to navigate our simple, easy platform, so that you can get on the road to HIPAA compliance.

If you’d like to skip the tutorial, click on the green “Dashboard” button in the top right of your screen.

HIPAAgps Tools

Dashboard
Risk Assessment
Policies and Procedures
Employee Training
Business Associate Agreements
Resources

The Dashboard

The dashboard is your ultimate progress and support tool. It contains progress reports for each section, this tutorial, and a link to the support team.

At any time while using the HIPAAgps platform, you can click and go to your dashboard to gauge where you are at on the road to completing HIPAAgps.

The Dashboard

See your progress for each section of the platform.

The Dashboard

Use the “Continue” button to jump to the home page of each section.

The Dashboard

Stay informed with HIPAAgps updates and changes through notifications.

The Dashboard

Find support for your questions.

Risk Assessment

The Risk Assessment combines about 500 HIPAA-compliance questions, based on the National Institute of Standards and Technology’s (NIST) assessment, with guidance and support to help you get your organization up-to-speed with HIPAA compliance.

The assessment is long, but the process is easy. Feel free to take breaks. We’ll have your information saved and you can pick up where you leave off.

Risk Assessment

Features include: instructional statements that simplify wordiness and jargon, best practice recommendations, policy and procedure templates, and questions support.

Risk Assessment

Pick a section and start the assessment.

We recommend starting with Administrative Safeguards.

Risk Assessment

Read the question and select your answer.

Tip: Answer questions honestly based on the current status of your organization, not based on what you know your answer should be.

Risk Assessment

Follow instructions for text-box answers and documentation uploads.

 

Tip: Use the text boxes not only when an answer is required, but also as a note-taking aid on all the questions. Any record/note keeping will help you in case of a HIPAA investigation.

Risk Assessment

When questions require a document, you can:

  • Upload a new document.
  • Select a previously uploaded document.
  • Download one of our templates, adjust it, and then re-upload.
  • Or, select that you have the documentation, but will be keeping it locally rather than uploading.

Risk Assessment

Please note: If you choose to keep the document locally rather than uploading it, the document will not be available for download in the Policies and Procedures section or for assignment in the Employee Training tool.

Risk Assessment

Remember: Never upload documents that contain ePHI, passwords, alarm codes, or any other sensitive information to the HIPAAgps system.

Risk Assessment

Download our policy and procedure templates and adjust them to fit your organization.

Tip: Red lettering in the templates indicates that you need to insert specific information into the document, like your organization’s review frequency.

Risk Assessment

Click the “INFO” tab for question guidance, document templates and additional support.

Risk Assessment

Click the “Best Practices” tab on questions that provide a best practice recommendation.

Our Best Practice recommendations give you specific advice concerning various HIPAA standards like review-and-update time frames.

Risk Assessment

Click the Next, Back, or dot buttons to navigate to other questions.

Risk Assessment

Use the dot indicators to see your complete and incomplete questions.

  •  Good job! You’ve completed this question satisfactorily according to the HIPAAgps standards.
  •  We recommend that you review this question and perform any necessary actions to change or complete your answer.
  •  You have not answered this question yet.

Risk Assessment

The dot indicators provide an at-a-glance task list to help you see and jump to questions that need more attention and/or still need addressing.

Tip: Each question pertains to a HIPAA requirement, so a question that needs attention is an area of HIPAA compliance that your organization needs to address.

Policies and Procedures

HIPAA requires extensive documentation.

 

The Policies and Procedures section provides a list of required documents, file storage, version control and starter templates.

You can easily store your HIPAA policies, procedures, plans, lists, training documents and inventories in one convenient place.

Policies and Procedures

Tip: If you have completed all of the documentation requirements in the Risk Assessment, then the Policies and Procedures will show complete.

However, you will need to continue to update your documents and add new custom documents as you see fit.

Policies and Procedures

Upload a new document or select one that you’ve already uploaded.

Tip: You may have one document that incorporates several of the documentation requirements.

Policies and Procedures

Create your own custom required documents, like training documents.

Tip: You can use the Custom Documentation section in the P&P tool to detail your in-house employee training sessions. Then assign that document to employees who attended the training for sign-off and tracking purposes.

Policies and Procedures

Tip: When creating your policies and procedures, keep in mind:

  • Your organization’s size, complexity and the services you provide.
  • Your organization’s technical infrastructure, hardware and software capabilities.
  • The cost of your security measures
  • The potential day-to-day security risks and your critical operations.

Policies and Procedures

Tip: You cannot upload any ePHI, passwords, alarm codes, or any other sensitive information to the HIPAAgps system, so please do not include these in your P&P documents.

Employee Training

The Employee Training tool incorporates two separate platforms: one for you, as the administrator, and one for your organization’s employees.

The administrator tool allows you to create employee profiles; assign specific policies, procedures and training documents; and monitor employee progress.

Employee Training

In the employee platform, your workforce members will watch educational HIPAA videos, take quizzes, as well as read and sign all the policies, procedures and training documents that you assign to them.

Employee Training

Create employee training profiles.

Insert the employee’s name and email.

Assign specific policies, procedures and training documents for that employee to read and sign.

Employee Training

Tip: Use the Custom Documentation section in the Policies and Procedures tool to create documents detailing your in-house employee training sessions and then assign the training documents to the employees who attended to track attendance.

Employee Training

Track employee progress.

Employee Training

In the employees’ profiles, they will watch training videos, take quizzes, and read and initial for assigned documents.

Business Associate Agreements

The Business Associate Agreements tool is simple to use and helps you meet the HIPAA business associate contract standards.

Business Associate Agreements

Create profiles for each of your business associates.

Construct agreements by downloading our Business Associate Agreement Template or uploading your own agreement document.

Business Associate Agreements

Insert your associate’s email and information, sign for the document and then send.

Business Associate Agreements

Your associate will receive an email with a link to the document signing page.

They can sign and download the document for their records.

Business Associate Agreements

Once they sign, your BAA administrative view will show their agreement as complete with a time stamp.

Resources

The Resources section provides additional information and services to help you achieve and maintain HIPAA compliance. Additions include: best practice recommendations, templates for sensitive PHI and employee documentation, HIPAA educational training videos, and a thorough breakdown of what HIPAA is.

Resources

The Resources section provides additional information and services to help you achieve and maintain HIPAA compliance. Additions include: best practice recommendations, templates for sensitive PHI and employee documentation, HIPAA educational training videos, and a thorough breakdown of what HIPAA is.

Resources

Read more about the history, purpose, and structure of HIPAA.

Resources

Watch the educational HIPAA training videos.

 

Tip: We highly recommend that you watch these videos before assigning employee training.

    • As one of your organization’s main points of contact for HIPAA, it’s important that you know and are prepared to help your employees with their HIPAA questions.

Resources

Stay up-to-date with our best practice recommendations.

Resources

Download templates that will contain sensitive information like PHI when filled out. These templates cannot be found in the Risk Assessment or Policies and Procedures sections.

Resources

PHI cannot be uploaded, typed in a text box, or in any other way detailed in the HIPAAgps system.

For example, having a Patient Privacy Policy signed by each of your patients is a HIPAA requirement. While an unsigned Patient Privacy Policy will most likely not include any PHI, as soon as the document receives a signature or patient name, it becomes a PHI document, and therefore must NOT be uploaded to the HIPAAgps system.

Let's Get Started!

It’s time to start your engine and hit the HIPAAgps road!

 

If you have any questions along the way, you can always reference this tutorial in your dashboard, view mini-tutorials in each section, or contact us!