The Health Insurance Portability and Accountability Act (HIPAA) seeks to protect patient privacy and data security by regulating how health information – including electronic protected health information (ePHI) – is collected, used, and shared. As a healthcare provider, UW-Madison is required under HIPAA to establish certain administrative safeguards for handling ePHI. This policy addresses the established security management standard (45 C.F.R :§164.308[a][1][i]) and evaluation standard (45 C.F.R. §164.308[a][8]).
This policy applies to all members of the UW HCC. It also applies to UW-Madison business associates of covered entities, whether individuals or units (hereafter collectively referred to as “units”).
UW-100 Designation of the UW–Madison Health Care Component
UW-116 Managing Business Associate Arrangements
UW-125 HIPAA Security Oversight
UW-126 HIPAA Security Auditing
UW-127 HIPAA Security Contingency Planning
UW-129 Email Communication Involving Protected Health Information
UW-130 Destruction/Disposal of Protected Health Information
UW-131 Notification and Reporting in the Case of Breach of Unsecured Protected Health Information
UW-132 HIPAA Security System Access
UW-134 HIPAA Security Data Management and Backup
UW-135 HIPAA Security Facilities Management
UW-137 HIPAA Privacy and Security Training
UW-141 Designation of Unit Privacy and Security Coordinators
12-08-2014: Effective date of the revised policy: 12-08-2014.
03-26-2020: Effective date of the revised policy: 03-26-2020.
10-19-2025