HIPAA requires covered entities to have policies and procedures reflecting HIPAA's privacy and security mandates. City health plans that are subject to HIPAA must have policies and procedures that reflect these mandates.
If a city sponsors more than one health plan, HIPAA allows for the city to designate these plans as an Organized Health Care Arrangement (OHCA). This allows the city to satisfy the HIPAA privacy requirements together, as if they are a single covered entity.
The League worked with Darcy Hitesman of Hitesman & Associates to develop a template of HIPAA policies and procedures reflecting the privacy and security rules that cities are able to customize on their own. Templates of the policies and procedures are available to member cities at no charge.