Lakeside Family Medicine, PLLC
Medical practice
412 Harbor View Drive, Suite 210, Traverse City, MI 49684
- Version
- 2.0
- Effective
- September 1, 2026
- Privacy Official
- Dana Whitfield, Practice Administrator
- Security Official
- Marcus Oyelaran, IT & Security Lead
Contents
- P-01Privacy & Security Officer Designation164.530(a) · 164.308(a)(2)
- P-02Minimum Necessary Standard164.502(b) · 164.514(d)
- P-03Uses & Disclosures of PHI164.506 · 164.508
- P-04Patient Rights & Access to Records164.524 · 164.526 · 164.528
- P-05Workforce Training & Sanctions164.530(b),(e) · 164.308(a)(5)
- S-01Device & Media Controls164.310(d)
- S-02Access Control & Password Management164.312(a) · 164.308(a)(4)
- S-03Security Incident Response164.308(a)(6) · 164.400-414
- S-04Business Associate Management164.502(e) · 164.504(e)
- S-05Documentation & Record Retention164.316 · 164.530(j)
P-01Privacy & Security Officer Designation
45 CFR 164.530(a); 45 CFR 164.308(a)(2)PURPOSE Lakeside Family Medicine, PLLC designates a Privacy Official and a Security Official as required by 45 CFR 164.530(a)(1) and 164.308(a)(2). One person may hold both roles in a small practice; both roles must be filled at all times. DESIGNATIONS - Privacy Official: Dana Whitfield, Practice Administrator. Responsible for developing and implementing privacy policies, receiving complaints (164.530(d)), and answering questions about the Notice of Privacy Practices. - Security Official: Marcus Oyelaran, IT & Security Lead. Responsible for the Security Rule program: risk analysis, safeguards, access management, incident response, and contingency planning. PROCEDURE 1. Designations are recorded in this manual and posted on the staff bulletin board and intranet. 2. Contact details for the Privacy Official appear in the Notice of Privacy Practices. 3. If an officer leaves or changes role, the practice owner names a replacement within 10 business days and updates this policy, the Notice, and the revision history. 4. Both officers report at least quarterly to practice leadership on open findings, incidents, and training status.
P-02Minimum Necessary Standard
45 CFR 164.502(b); 45 CFR 164.514(d)PURPOSE When using, disclosing, or requesting protected health information (PHI), Lakeside Family Medicine, PLLC limits the information to the minimum necessary to accomplish the intended purpose (45 CFR 164.502(b)). EXCEPTIONS (minimum necessary does not apply) - Disclosures to or requests by a provider for treatment. - Disclosures to the patient or made under a valid patient authorization. - Disclosures required by law or to HHS for compliance investigations. PROCEDURE 1. Role-based access: the Privacy Official maintains a matrix listing each job role, the categories of PHI the role may access, and the conditions of access (164.514(d)(2)). The matrix is reviewed at every annual policy review. 2. Routine disclosures (billing, referrals, payer requests) follow written protocols that specify what is sent. Staff do not send a full chart when a visit note or itemized statement will do. 3. Non-routine disclosures and requests are reviewed individually by the Privacy Official using the criteria in 164.514(d)(3). 4. Requests from other covered entities may be relied on as the minimum necessary when the request is reasonable (164.514(d)(3)(iii)). 5. Staff who need PHI outside their role ask the Privacy Official; access is granted for the task and then removed.
P-03Uses & Disclosures of PHI
45 CFR 164.506; 45 CFR 164.508; 45 CFR 164.510; 45 CFR 164.512PURPOSE Lakeside Family Medicine, PLLC uses and discloses PHI only as permitted or required by the Privacy Rule. PERMITTED WITHOUT AUTHORIZATION (164.506) - Treatment, payment, and health care operations (TPO), including disclosures to other providers for their treatment or payment activities. - Disclosures to the patient and to HHS. PERMITTED WITH AN OPPORTUNITY TO AGREE OR OBJECT (164.510) - Facility directories and disclosures to family or friends involved in the patient's care. PERMITTED FOR PUBLIC-INTEREST PURPOSES (164.512) - As required by law, public health, abuse reporting, health oversight, judicial proceedings, law enforcement, and to avert a serious threat. Each such disclosure is logged for accounting purposes (164.528). AUTHORIZATION REQUIRED (164.508) - Marketing, sale of PHI, most uses of psychotherapy notes, and any purpose not listed above. - Authorizations must contain the core elements and required statements in 164.508(c); defective authorizations are rejected. PROCEDURE 1. Front-desk and billing staff use the TPO checklist before releasing records. Anything not on the checklist goes to the Privacy Official. 2. Verify the identity and authority of any requester before disclosure (164.514(h)). 3. Record every non-TPO disclosure in the accounting-of-disclosures log with date, recipient, description, and purpose. 4. Keep signed authorizations for six years from the date they expire.
P-04Patient Rights & Access to Records
45 CFR 164.524; 45 CFR 164.526; 45 CFR 164.528; 45 CFR 164.522PURPOSE Lakeside Family Medicine, PLLC honors every patient right in Subpart E of the Privacy Rule and responds within the required timeframes. RIGHT OF ACCESS (164.524) 1. Requests for access may be made verbally or in writing; the practice records the date received. 2. The practice acts on a request no later than 30 calendar days after receipt. One 30-day extension is allowed if the patient is told in writing, within the first 30 days, the reason for the delay and the date the practice will respond (164.524(b)(2)). 3. Records are provided in the form and format the patient requests if readily producible, including electronic copies of electronic records (164.524(c)(2)). 4. Fees are limited to a reasonable, cost-based fee for labor, supplies, and postage (164.524(c)(4)). No fee for viewing records. 5. Denials are limited to the grounds in 164.524(a); reviewable denials include instructions for requesting review. OTHER RIGHTS - Amendment (164.526): respond within 60 days; one 30-day extension. - Accounting of disclosures (164.528): six-year lookback; first accounting in any 12-month period is free. - Restrictions (164.522(a)): the practice must agree to restrict disclosures to a health plan when the patient paid in full out of pocket. - Confidential communications (164.522(b)): accommodate reasonable requests for alternate means or locations. PROCEDURE The Privacy Official logs every request, its response date, and its outcome. Overdue requests are escalated at day 20.
P-05Workforce Training & Sanctions
45 CFR 164.530(b); 45 CFR 164.530(e); 45 CFR 164.308(a)(5)PURPOSE Every workforce member of Lakeside Family Medicine, PLLC receives HIPAA training and is subject to documented sanctions for violations (164.530(b) and (e)). TRAINING (164.530(b); 164.308(a)(5)) 1. New hires, volunteers, students, and contractors with PHI access complete training within 30 days of start and before unsupervised access to PHI. 2. All workforce members complete refresher training at least annually and within a reasonable time after any material policy change. 3. Security awareness content includes phishing, password management, log-in monitoring, and malware protection (164.308(a)(5)(ii)). 4. The Privacy Official keeps a training log with names, dates, topics, and attestations for six years. SANCTIONS (164.530(e)) Sanctions are applied consistently, regardless of role, and documented in the personnel file: - Tier 1 (accidental, no harm): verbal counseling and retraining. - Tier 2 (negligent, e.g., unattended screen, records left in a shared area): written warning and retraining. - Tier 3 (knowing violation or repeat Tier 2): suspension and referral to practice leadership. - Tier 4 (malicious access, snooping, or disclosure for personal gain): termination and, where required, referral to law enforcement. No sanction is applied to a workforce member for filing a complaint with HHS, testifying, or opposing an unlawful practice in good faith (164.530(g)).
S-01Device & Media Controls
45 CFR 164.310(d)PURPOSE Lakeside Family Medicine, PLLC controls the receipt, movement, re-use, and disposal of hardware and electronic media that contain ePHI (45 CFR 164.310(d)(1)). PROCEDURE 1. Inventory: the Security Official maintains a list of every laptop, desktop, server, phone, tablet, USB drive, and backup drive that stores or accesses ePHI, with owner, location, and encryption status (164.310(d)(2)(iii)). 2. Encryption: all portable devices and removable media are full-disk encrypted before they leave the premises. 3. Disposal (164.310(d)(2)(i)): drives are wiped using NIST SP 800-88 clear/purge methods or physically destroyed. A certificate of destruction is retained for each device. 4. Re-use (164.310(d)(2)(ii)): ePHI is removed and verified before a device is reassigned or returned to a lessor. 5. Backup before moving equipment (164.310(d)(2)(iv)): a retrievable exact copy of ePHI is confirmed before a server or workstation is relocated. 6. Lost or stolen devices are reported to the Security Official the same day and handled under the Security Incident Response policy.
S-02Access Control & Password Management
45 CFR 164.312(a); 45 CFR 164.308(a)(4)PURPOSE Lakeside Family Medicine, PLLC allows access to ePHI only to persons and software programs that have been granted access rights (45 CFR 164.312(a)(1)). PROCEDURE 1. Unique user identification (164.312(a)(2)(i)): every user has a named account. Shared or generic log-ins are prohibited. 2. Authorization (164.308(a)(4)): the Security Official approves each account against the role-based access matrix before it is created. Access is reviewed quarterly and removed the same business day a workforce member leaves. 3. Emergency access procedure (164.312(a)(2)(ii)): a sealed break-glass credential is held by the Security Official and the practice owner; any use is logged and reviewed within 24 hours. 4. Automatic logoff (164.312(a)(2)(iii)): workstations lock after 10 minutes of inactivity; EHR sessions end after 15 minutes. 5. Encryption and decryption (164.312(a)(2)(iv)): ePHI at rest is encrypted on all endpoints and servers. 6. Passwords: minimum 12 characters, no reuse of the last 10, changed immediately on suspected compromise. Multi-factor authentication is required for the EHR, email, and any remote access. 7. Passwords are never shared, written on visible notes, or sent by email or text.
S-03Security Incident Response
45 CFR 164.308(a)(6); 45 CFR 164.400-414PURPOSE Lakeside Family Medicine, PLLC identifies and responds to suspected or known security incidents, mitigates harmful effects, and documents incidents and their outcomes (45 CFR 164.308(a)(6)). DEFINITION A security incident is the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information, or interference with system operations (164.304). PROCEDURE 1. Report: any workforce member who suspects an incident tells the Security Official immediately, by phone if after hours. No one attempts to investigate or delete evidence on their own. 2. Contain (same day): isolate affected devices, disable compromised accounts, and preserve logs. 3. Assess (within 5 business days): the Security and Privacy Officials complete the incident report and, if unsecured PHI may be involved, a four-factor risk assessment under 164.402(2). 4. Notify: if a breach is confirmed, affected individuals are notified without unreasonable delay and no later than 60 calendar days after discovery (164.404). HHS is notified per 164.408, and media per 164.406 when 500 or more residents of a state are affected. Business associates report to the practice under 164.410. 5. Remediate: root cause is fixed, and the risk analysis is updated. 6. Document: the incident report, risk assessment, notifications, and remediation are retained for six years.
S-04Business Associate Management
45 CFR 164.502(e); 45 CFR 164.504(e); 45 CFR 164.308(b)PURPOSE Lakeside Family Medicine, PLLC discloses PHI to a business associate only after obtaining satisfactory assurances, in a written business associate agreement (BAA), that the associate will safeguard the information (45 CFR 164.502(e)(1); 164.504(e); 164.308(b)). PROCEDURE 1. Identification: before any vendor receives, stores, transmits, or can view PHI, the requesting staff member notifies the Privacy Official. Common examples: EHR, billing service, cloud storage, email, e-fax, IT support, shredding, transcription, answering service. 2. Agreement: a BAA meeting every element of 164.504(e)(2) is signed before PHI is shared. Vendors that refuse a BAA do not receive PHI. 3. Inventory: the Privacy Official keeps a BA register with vendor name, service, PHI involved, BAA date, and renewal date. 4. Annual review: each BAA is reviewed annually for scope changes; the vendor's security posture is reassessed if a breach or material change is reported. 5. Termination: on contract end, the vendor returns or destroys PHI as the BAA requires, or documents why that is infeasible. 6. Known violations: if the practice learns of a pattern of activity that breaches the BAA, it takes reasonable steps to cure the breach and, if unsuccessful, terminates the contract (164.504(e)(1)(ii)).
S-05Documentation & Record Retention
45 CFR 164.316; 45 CFR 164.530(j)PURPOSE Lakeside Family Medicine, PLLC maintains its HIPAA policies and procedures in writing and keeps the records the Rules require (45 CFR 164.316; 164.530(j)). PROCEDURE 1. Written policies: this manual is the official policy set. Changes are approved by the Privacy Official, dated, and recorded in the revision history (164.316(b)(1)). 2. Retention (164.316(b)(2)(i); 164.530(j)(2)): policies, risk analyses, training logs, BAAs, authorizations, accounting-of-disclosures logs, complaint records, sanction records, incident reports, and Notice of Privacy Practices versions are kept for six years from the date of creation or the date last in effect, whichever is later. 3. Availability (164.316(b)(2)(ii)): the current manual is available to every workforce member on the intranet and in print at the front office. 4. Periodic review (164.316(b)(2)(iii)): the manual is reviewed Annually, and after any material change in operations, systems, or law. The Security Official also updates the risk analysis at that time. 5. Format: documentation may be paper or electronic. Electronic records are backed up under the contingency plan. EFFECTIVE DATE This manual, version 2.0, is effective 2026-09-01 and supersedes all prior versions.
Revision History
Rows are editable. Retain each superseded version for six years (164.316(b)(2)).
| Ver. | Date | Change | Approved by |
|---|---|---|---|
| 1.0 | 2023-03-15 | Initial policy manual adopted | Dana Whitfield |
| 1.1 | 2024-10-02 | Added device & media controls after laptop refresh; updated sanctions tiers | Dana Whitfield |
| 2.0 | 2026-09-01 | Annual review; incident response timelines aligned to breach-notification procedures | Dana Whitfield |
Adoption & Approval
The undersigned adopt this manual, version 2.0, as the official HIPAA policies and procedures of Lakeside Family Medicine, PLLC, effective September 1, 2026. It will be reviewed annually, and after any material change in operations, systems, or law.
Privacy Official — Dana Whitfield
Security Official — Marcus Oyelaran
Practice Owner / Managing Partner
Date
