The Health Insurance Portability and Accountability Act (HIPAA) regulations consist of two key parts: the Privacy Rule and the Security Rule. Together, they establish national standards for the appropriate use, disclosure, and protection of Protected Health Information (PHI). To comply with these rules, HIPAA requires the appointment of a university HIPAA Privacy and Security Officer. UW-Madison also requires the appointment of a HIPAA Privacy and Security Coordinator at the unit level. This policy defines the roles and responsibilities of these four roles.
This policy applies to all members of the University of Wisconsin–Madison Healthcare Component (UW HCC) and to UW-Madison units serving as business associates.
The Officers shall develop, implement, and maintain all shared policies, procedures, and documentation related to HIPAA compliance efforts across the university. The Officers or their delegates shall specifically:
The Officers shall facilitate HIPAA incident reporting, investigation, and follow-up processes. The Officers or their delegates shall:
The unit HIPAA Privacy and Security Coordinators are responsible for the following within their respective areas of expertise (i.e., the Privacy Coordinator leads when the issue is primarily privacy-related and the Security Coordinator leads when the issue is primarily security-related):
UW-100 Designation of the UW-Madison Health Care Component
UW-124 HIPAA Security - Risk Assessment and Mitigation
UW-126 HIPAA Security Auditing
UW-131 Notification and Reporting in the Case of Breach of Unsecured Protected Health Information
UW-137 HIPAA Privacy and Security Training
UW-141 Designation of Unit Privacy and Security Coordinators
12-08-2014: Effective date of the revised policy: 12-08-2014.
03-26-2020: Effective date of the revised policy: 03-26-2020.
03-01-2026: Effective date of the revised policy: 03-01-2026.