Example: Setting Up a Retention Policy to meet HIPAA Requirements
The customer we'll look at in this example is Community HMO, a health maintenance organization whose FileCloud users are both health care professionals and administrative personnel. In this example, your role is the FileCloud admin.
To meet the requirements for passing two of the rules in the Compliance Center's HIPAA screen, you must choose a retention policy that ensures you retain ePHI data. These rules are:
- 164.312(c)(1) - Technical Safeguards - Set up a retention policy to protect files and folders from deletion.
- 164.316(b)(2)(i)- Policies and procedures and documentation requirements - Use Retention Policy to retain files for 6 years.
This example will walk you through the process necessary to pass these requirements. The broader steps involve:
- Enabling the HIPAA retention policy rules in the Compliance Center.
- Creating a metadata attribute to tag files with ePHI data.
- Creating a pattern group that identifies file content as ePHI.
- Setting up a Smart Classification rule to locate and tag ePHI files.
- Setting up a retention policy that prevents these files from being deleted for 6 years after their creation.
- Choosing the retention policy in the Compliance Center for each of the requirements listed above.










































