Run a 90-minute exercise by assigning policy owners and evidence recorders, presenting a realistic operational change, and testing whether participants can locate, apply, update, and retain the written documentation required by HIPAA. This written policy tabletop exercise facilitator guide uses timed injects, decision questions, and a hot-wash record to evaluate documentation practices under 45 CFR 164.316(b)(1), including six-year retention, availability to responsible personnel, and periodic updates.
What should the exercise objectives measure?
For a compliance officer, the goal is not to prove that a policy exists in a SharePoint folder. The goal is to determine whether the organization can use that policy during a real operational event and create defensible records of the decisions made. The exercise should test the documentation requirements in the HIPAA Security Rule at 45 CFR 164.316(b)(1) and the related requirements in 164.316(b)(2).
- Written form: Confirm that the applicable policy, procedure, review record, and action documentation exist in written or electronic form.
- Availability: Confirm that the people responsible for implementing the procedure can access the current approved version without relying on a single employee or informal knowledge.
- Retention: Determine whether the organization can retain the policy, approval history, incident-related records, and review evidence for six years from creation or last effective date, whichever is later.
- Updates: Test whether a material environmental or operational change triggers a documented policy review and, if needed, a controlled update.
- Evidence quality: Verify that records identify who acted, what was decided, when it occurred, what policy version applied, and where supporting evidence is stored.
| Time | Activity | Expected output |
|---|---|---|
| 0–15 minutes | Brief participants, state scope, distribute scenario | Named roles, identified policy repository, agreed evidence recorder |
| 15–45 minutes | Run timed injects and document decisions | Policy access findings, action log, identified documentation gaps |
| 45–70 minutes | Evaluate update, approval, and retention requirements | Draft policy-change path and records-retention plan |
| 70–90 minutes | Hot wash and assign remediation owners | Corrective-action register with dates and evidence requirements |
What does this written policy tabletop exercise facilitator guide cover in 90 minutes?
Invite the compliance officer to facilitate, with the privacy officer, security lead, IT operations manager, clinical operations representative, HR or training representative, and records-management owner participating. Assign one person as the evidence recorder; that person should capture decisions in real time rather than trying to reconstruct them after the session. Participants should have read-only access to the policy library, policy approval records, training records, change-management tickets, and document retention schedule.
A useful tabletop policy exercise is discussion-based, not a simulated technical incident response. Participants may open actual systems and records to validate claims, but they should not alter production settings during the exercise. The facilitator should repeatedly ask for the written record that supports a statement such as, “We reviewed that,” “The policy is current,” or “Staff know what to do.”
What scenario should participants work through?
HarborLine Telehealth is a mid-market virtual-care provider with 240 employees, 68 employed clinicians, and approximately 22,000 active patients. Its clinicians conduct scheduled video visits through Zoom for Healthcare, document care in eClinicalWorks, and access a clinician portal hosted in AWS. Workforce identity is managed through Okta, while policies, procedures, approval records, and annual security training materials are stored in Microsoft SharePoint Online. The organization uses Jira Service Management for IT changes and security incident tickets.
On a Monday morning, HarborLine’s clinical operations team announces that it has signed a contract with a regional employer plan that will increase evening and weekend appointment volume within 30 days. To support the new workflow, HarborLine plans to use a third-party virtual medical assistant service. The vendor’s staff will not access eClinicalWorks directly, but they will receive patient names, appointment dates, clinician names, and intake notes through a new secure message queue. The operations manager says the vendor needs access configured before the launch date and that the existing “Remote Workforce Security and Access Management Policy” should already cover the arrangement.
The security lead asks for the approved vendor-access procedure and the most recent risk assessment addressing third-party processing. The clinical operations representative locates a policy in SharePoint, but the displayed version is dated 2021 and its approval field identifies a former chief information officer. A second version appears in a departmental Teams channel, dated 2024, but it has no approval record and does not appear in the central policy index. The Teams version refers to an older secure messaging platform that HarborLine no longer uses.
Meanwhile, an IT analyst opens a Jira change request for the vendor integration. The ticket includes technical configuration details but no link to the applicable policy, risk analysis, business associate agreement review, or training requirement. The analyst explains that this is normal because operations “handles the paperwork separately.” The privacy officer then asks whether the organization has retained prior policy versions and reviews for the required period, especially where a prior policy was replaced after a significant platform migration.
The exercise is not intended to decide whether the vendor arrangement is legally permissible. Instead, participants must decide how HarborLine will locate the governing written documentation, determine which version is effective, make it available to responsible implementers, document its review in response to the workflow change, and preserve the resulting evidence. The central question is whether the organization can demonstrate a controlled documentation process rather than relying on disconnected copies, verbal assurances, or untraceable email approvals.
What injects should occur at 15, 30, and 45 minutes?
| Exercise time | Facilitator inject | Decision participants must document |
|---|---|---|
| 15 minutes | The SharePoint policy owner is on leave. The current policy index links to a file marked “Draft,” while the compliance officer has an email from 2024 stating that leadership approved “the revised access policy.” | Which document is currently effective, who can make that determination, and where will the organization retain the version-control and approval evidence? |
| 30 minutes | The vendor implementation date moves up by two weeks. Clinical operations asks IT to provision the message queue immediately because appointment scheduling has begun. | What written procedure controls the change, what documentation must be completed before implementation, and who needs access to those records? |
| 45 minutes | A records-management review finds that the 2021 policy was deleted from a shared drive after the 2024 draft was created. A PDF exists in an Outlook archive, but it has no metadata showing when it ceased to be effective. | How will HarborLine establish retention status, preserve available evidence, and correct its process for the six-year retention period in 164.316(b)(2)(i)? |
How should the facilitator lead the discussion?
Use a neutral, evidence-first approach. Do not accept “someone owns that” or “we would update it” as an answer. Ask participants to identify the specific repository, record owner, approval authority, and retention location. The facilitator should keep the group focused on documentation control rather than allowing the discussion to become a broad vendor-risk assessment.
What questions should the facilitator ask?
- Where is the authoritative policy library, and how do implementers distinguish an approved policy from a draft or convenience copy?
- Can the IT analyst, clinical operations manager, and privacy officer each access the procedure relevant to their responsibilities?
- What event in this scenario requires a documented review under 164.316(b)(2)(iii), and who has authority to approve a revised policy?
- What records must be linked to the policy review: risk analysis, vendor review, change ticket, training update, meeting minutes, or approval record?
- How will the organization record the policy’s effective date, superseded date, version number, approver, and distribution method?
- Which repository is the system of record for retention, and what prevents deletion before the six-year retention period ends?
- If an auditor requested the records in 18 months, could the organization produce a coherent timeline without relying on individual mailboxes?
For each answer, the evidence recorder should capture the system name and record location. For example: SharePoint Online / Compliance / HIPAA Policies / Access Management / version 4.2, Jira JSM change CHG-18427, and Microsoft Purview retention label: HIPAA Security Documentation - 6 Years. This turns a policy tabletop facilitation session into a repeatable test of evidence availability.
What should the hot-wash debrief template include?
Reserve the final 20 minutes for the hot wash. The compliance officer should read each finding aloud, confirm the accountable owner, and distinguish immediate evidence-preservation actions from longer-term policy improvements. Avoid closing with general statements such as “improve communication.” Each action should produce a verifiable record.
Exercise date: July 18, 2026 Scenario owner: Compliance Officer Applicable requirement: 45 CFR 164.316(b)(1) and 164.316(b)(2) Finding: The approved vendor-access procedure could not be identified within 15 minutes. Risk: Personnel may implement a workflow using an unapproved or outdated procedure. Corrective action: Create a controlled SharePoint policy index with version, effective date, approver, owner, retention label, and link to superseded versions. Action owner: Director of Compliance Due date: August 15, 2026 Required evidence: Approved index, policy approval minutes, Purview retention report Validation method: Repeat a 30-minute policy-access drill with IT and operations
| Debrief question | Record to capture |
|---|---|
| What worked as intended? | Named systems, accessible records, and responsible personnel who could locate them |
| What failed or caused delay? | Missing approvals, duplicate copies, unclear ownership, inaccessible repositories, or retention gaps |
| What must change? | Specific policy, procedure, repository, training, or change-management correction |
| How will closure be verified? | Owner, due date, evidence artifact, reviewer, and follow-up exercise or spot check |
Next step: Schedule this 90-minute exercise with your policy owners this quarter and retain the agenda, participant list, inject log, hot wash, and corrective-action evidence alongside your HIPAA documentation.