LOS ANGELES COUNTY
DEPARTMENT OF MENTAL HEALTH
  Policy 555.01 Data Security Documentation Requirements
 
Policy Category:  Administrative
Distribution Level:  Directly Operated Programs and Contracted Agencies
Responsible Party:  Chief Information Office
 
Reviewed and Approved on November 5, 2025
 
I.  POLICY STATEMENT
 
The purpose of this policy is to establish documentation requirements for data security policies and procedures in accord with standards, implementation specifications, or other requirements of the Health Insurance Portability and Accountability Act (HIPAA) Security Rule. (45 CFR § 164.316)

Contracted agencies shall develop an internal policy and associated procedures that are consistent with their organizational practices and meet the requirements set forth in this policy.

 
II.  DEFINITIONS
 
III.  POLICY
 
The Departmental Information Security Officer (DISO) shall maintain documentation standards and requirements of reasonable and appropriate data security policies and procedures to comply with the provisions of the HIPAA Security Rule.
 
IV.  PROCEDURES
 
V.  AUTHORITIES