Plans & Policies

HIPAA & Resident Privacy Policy for RCFEs

HIPAA requires every RCFE to provide residents with a written Notice of Privacy Practices. This policy covers all six resident rights under HIPAA, California CMIA protections, and the 15-day breach notification procedure.

Regulatory requirement HIPAA 45 CFR §164.520 & California CMIA (Civil Code §56) - Notice of Privacy Practices required

What’s included

  • Notice of Privacy Practices (NPP) in required HIPAA format
  • All 6 resident rights under HIPAA clearly enumerated
  • PHI use and disclosure categories with examples
  • California Confidentiality of Medical Information Act (CMIA) protections
  • Minimum necessary standard implementation guidance
  • 15-day breach notification procedure (California CMIA requirement)
  • Resident acknowledgment signature block and tracking log
  • Editable Microsoft Word format

Who needs this

  • All California RCFE operators (HIPAA applies as a business associate in the healthcare chain)
  • Facilities whose current privacy notice is outdated or missing California-specific CMIA provisions
  • Administrators preparing for a CDSS inspection who need documentation complete
Plans & Policies $49
  • Instant download
  • California RCFE compliant
  • Editable Word format
  • One-time purchase
View cart

Secure checkout · Instant delivery

Simple process

How it works

1

Purchase online

Add to cart and complete your order securely in minutes. We accept all major cards.

2

Receive your document

Download instantly. Your document is emailed and available in your order confirmation immediately after purchase.

3

Customize and use

Fill in your facility-specific details in the editable Word file and include it in your CDSS application or operations.

Questions answered

Frequently asked questions

Does HIPAA apply to RCFEs?

Yes. RCFEs receive and handle protected health information (PHI) from physicians, hospitals, and insurance providers on behalf of residents. As a healthcare business associate, HIPAA privacy requirements apply. Additionally, California's CMIA (Civil Code §56) imposes separate and often stricter privacy requirements.

What is a Notice of Privacy Practices (NPP)?

Under HIPAA 45 CFR §164.520, every covered entity must provide residents with a written NPP that explains how their health information is used, what rights they have, and how to file a complaint. The NPP must be given to residents at admission and posted in the facility.

What are the six resident rights under HIPAA?

Residents have the right to: (1) access and copy their health records, (2) request corrections to their records, (3) receive an accounting of disclosures, (4) request restrictions on certain uses of their information, (5) request confidential communications, and (6) file a complaint with HHS or the facility.

What is California's CMIA and how is it different from HIPAA?

The California Confidentiality of Medical Information Act (CMIA, Civil Code §56) protects residents' medical information and often exceeds HIPAA requirements. For example, California requires a 15-day breach notification to affected individuals (shorter than HIPAA's 60-day requirement). This policy covers both.

What happens if we have a data breach?

Under California CMIA, a covered entity must notify affected individuals within 15 days of discovering a breach of their medical information. HIPAA requires notification within 60 days. This policy includes the complete breach response procedure meeting the stricter California standard.