Research listings are separate from implemented scans. No quote or assessment is available for this profile yet. Public uploads must contain no patient data or other restricted information.
Documents to review
Privacy policyResearch document type
Security policyResearch document type
Emergency preparedness planResearch document type
Infection control planResearch document type
Incident response planResearch document type
Scope questions
Industry alone does not establish legal applicability. Confirm location, activities, role, data and relevant thresholds.
Where does the organization operate, and which regulator, license, permit or contract governs the activity?
Which business activities, data types and organization roles does the document describe?
Do the relevant thresholds or exceptions change which requirements apply?
Unknown answers stay unresolved. Document detection does not answer these questions for you.
A fictional example to explore
This short policy outline demonstrates the document's structure and research questions. It is a navigation example; scans for this profile are not available yet.
PDF pages are counted exactly. DOCX and TXT use the disclosed word-count estimate, so the same policy can have different billable page counts.
Regulations and frameworks to explore
These are research candidates for this profile. Confirm the exact organization and activity before concluding that a rule applies.
Research only
HIPAA Security, Privacy, and Breach Notification Rules
45 CFR Parts 160 and 164
Applies to covered entities and business associates handling protected health information. Cloud providers that maintain electronic PHI can be business associates even when data is encrypted and they have no decryption key. Check the actual data/service role and business-associate agreement. A healthcare customer alone does not establish scope. Proposed Security Rule changes must be tracked separately from the currently effective rule.
Jurisdictions: US-FEDERAL
Research applicability questions
Are you a HIPAA covered entity, or do you create, receive, maintain or transmit PHI for a covered entity or another business associate?
Which protected health information does the service handle, and under whose business-associate agreement?
Does your service handle electronic PHI, including encrypted information for which you do not hold the decryption key?
What size, complexity, capabilities and risk factors affect implementation of your HIPAA safeguards?
For each addressable implementation specification, have you evaluated reasonableness and documented any alternative?
Provider-specific Medicare Conditions of Participation and Coverage
For provider and supplier types participating under the applicable Medicare/Medicaid Conditions of Participation or Coverage. Hospitals, home health agencies, hospices, ambulatory surgery centers and other providers have different conditions. Identify the specific facility and certification pathway; this umbrella family cannot supply one universal healthcare checklist.
Jurisdictions: US-FEDERAL
Research applicability questions
Which exact CMS provider or supplier category and facility certification apply?
Under which Medicare or Medicaid participation conditions is this facility certified?
Will any uploaded document contain electronic protected health information?
For provider and supplier categories covered by the CMS emergency-preparedness regulations. The program covers risk assessment/planning, policies and procedures, communication, and training/testing, with requirements that vary by provider category. Use the applicable provider regulation and survey guidance; a generic emergency plan does not establish facility compliance.
Jurisdictions: US-FEDERAL
Research applicability questions
Which CMS provider/supplier regulation governs this facility’s emergency-preparedness program?
What patient needs, local hazards, utilities, communications and continuity dependencies must its plan address?
Will any uploaded document contain electronic protected health information?
An emergency action plan is required when another OSHA standard triggers 29 CFR 1910.38. Confirm the triggering standard and state-plan coverage. A plan must generally be written and available to employees; employers with ten or fewer employees may communicate it orally. Do not infer a written-plan violation solely from the industry label.
Jurisdictions: US-FEDERAL
Research applicability questions
Which OSHA standard requires an emergency action plan for this workplace?
How many employees does the employer have, and does the ten-or-fewer oral-plan exception apply?
Does an OSHA-approved state plan apply, and does it impose different workplace requirements?
What work activities, hazards and other OSHA standards trigger this workplace emergency-plan duty?