| Agency: | City of Springfield |
|---|---|
| State: | Missouri |
| Type of Government: | State & Local |
| NAICS Category: |
|
| Posted Date: | Jul 16, 2026 |
| Due Date: | Jul 30, 2026 |
| Solicitation No: | 003-2027IFIB |
| Original Source: | Please Login to View Page |
| Contact information: | Please Login to View Page |
| Bid Documents: | Please Login to View Page |
| Bid Number: |
003-2027IFIB
|
| Bid Title: |
ONSITE PAPER SHREDDING SERVICES
|
| Category: | All Notifications – Division of Purchases |
| Status: | Open |
|
Attachment 1
HIPAA Compliance Manual 2025
2
Mission Statement:
Protect and improve community health.
Vision Statement:
Helping all people live longer, healthier, happier lives.
Value Statements:
Collaborate We are better together. We promote health through partnerships with people,
organizations and each other.
Elevate We strive for excellence. We believe progress comes through action and the process of
continuous improvement.
Serve We embody public service. We are steadfast in our efforts to support the community, each other
and ourselves.
227 E. CHESTNUT EXPWY, SPRINGFIELD, MO 65802 | 417-864-1658 | health.springfieldmo.gov
AN EQUAL OPPORTUNITY/AFFIRMATIVE ACTION EMPLOYER. SERVICES PROVIDED ON A NONDISCRIMINATORY BASIS.
| Date of | Description of Change | Change Made By |
|---|---|---|
| Change | ||
| 6/15/20 | Edited Table of Contents and fixed punctuation errors | Nancy Yoon |
| May 2023 | Reviewed and edited entire manual | Mary Bozarth Nancy Yoon |
| Dec 2024 | Reviewed and edited entire manual | Nancy Yoon |
| February 2025 | P. 10: The health care components of SGCHD: changed NEST to Family Connects and added DIS P. 11, Section 1.3: Changed frequency of manual review from every 2 years to every year. Added: The most current regulations are found here: https://www.ecfr.gov/current/title-45/subtitle- A/subchapter-C ). P. 12, Section 1.3h: Added: The Patagonia Service Organization Control (SOC) report will be acquired and reviewed annually by the HIPAA Privacy and Security Officers. Action items will be created and addressed with the responsible parties. The reports will be saved on the HIPAA Sharepoint drive. P. 20: Added: This form will be saved at: N:/Administration/HIPAA/PHI%20Disclosure/ P. 22, Section 3.6 (1): Added: either in person, or remote via phone or video device | Nancy Yoon |
| September | P. 27 - 29, physical controls: various edits and inclusion of controls | Jon Mooney, Tara |
| 2025 | of medical records storage. | Williams |
| P. 29, Audit Controls: edited frequency of audits and types of | ||
| reports reviewed | ||
| February 2026 | P . 10 Value Statement: updated to reflect current values | Tara Williams |
3
Record of Change
Date of Description of Change Change Made By
Change
6/15/20 Edited Table of Contents and fixed punctuation errors Nancy Yoon
May 2023 Reviewed and edited entire manual Mary Bozarth
Nancy Yoon
Dec 2024 Reviewed and edited entire manual Nancy Yoon
February P. 10: The health care components of SGCHD: changed NEST to
Nancy Yoon
2025 Family Connects and added DIS
P. 11, Section 1.3: Changed frequency of manual review from
every 2 years to every year. Added: The most current regulations
are found here: https://www.ecfr.gov/current/title-45/subtitle-
A/subchapter-C ).
P. 12, Section 1.3h: Added: The Patagonia Service Organization
Control (SOC) report will be acquired and reviewed annually by
the HIPAA Privacy and Security Officers. Action items will be
created and addressed with the responsible parties. The reports
will be saved on the HIPAA Sharepoint drive.
P. 20: Added: This form will be saved at:
N:/Administration/HIPAA/PHI%20Disclosure/
P. 22, Section 3.6 (1): Added: either in person, or remote via
phone or video device
September P. 27 - 29, physical controls: various edits and inclusion of controls Jon Mooney, Tara
2025 of medical records storage. Williams
P. 29, Audit Controls: edited frequency of audits and types of
reports reviewed
February 2026 P . 10 Value Statement: updated to reflect current values Tara Williams
227 E. CHESTNUT EXPWY, SPRINGFIELD, MO 65802 | 417-864-1658 | health.springfieldmo.gov
AN EQUAL OPPORTUNITY/AFFIRMATIVE ACTION EMPLOYER. SERVICES PROVIDED ON A NONDISCRIMINATORY BASIS.
4
Contents
Definitions ..................................................................................................................................................... 6
1. INTRODUCTION ......................................................................................................................................... 8
What is HIPAA? .................................................................................................................................. 8
1.1 General Policy Statement ........................................................................................................................ 9
1.2 Business Associates ............................................................................................................................... 10
1.3 Privacy and Security Officers ................................................................................................................. 11
2. EMPLOYEE RESPONSIBILITIES .................................................................................................................. 12
2.1 Role-Based Access ................................................................................................................................. 12
2.2 Training 12
2.3 Violation and Discipline ......................................................................................................................... 13
3. PRIVACY PRACTICE PROCEDURES ............................................................................................................ 13
3.1 Notice of Privacy Practices .................................................................................................................... 13
3.2 Permitted Uses & Disclosures Without Authorization .......................................................................... 14
3.3 Treatment, Payment, and Health Care Operations .............................................................................. 14
3.4 HIPAA Authorization .............................................................................................................................. 15
3.5.1 Disclosures of PHI .............................................................................................................................. 18
3.5.2 Circumstances for Denying Access .................................................................................................... 20
3.6 Family and Others Involved in Individuals' Care .................................................................................... 21
3.6.1 Personal Representatives .................................................................................................................. 23
4. PUBLIC HEALTH AND SAFETY REPORTING ............................................................................................... 25
227 E. CHESTNUT EXPWY, SPRINGFIELD, MO 65802 | 417-864-1658 | health.springfieldmo.gov
AN EQUAL OPPORTUNITY/AFFIRMATIVE ACTION EMPLOYER. SERVICES PROVIDED ON A NONDISCRIMINATORY BASIS.
5
4.1 Public Health Activities .............................................................................................................. 25
4.2 Sunshine Law Requests ............................................................................................................. 26
4.3 Mandated Reports ..................................................................................................................... 26
5. SECURITY PRACTICES ............................................................................................................................... 26
5.1 Administrative Safeguards ......................................................................................................... 26
5.2 Physical Safeguards ................................................................................................................... 27
5.3 Technical Safeguards ................................................................................................................. 28
5.4 Data Retention and Storage of Personal Health Information.................................................... 30
6. OTHER CIRCUMSTANCES FOR DISCLOSURE ............................................................................................ 31
6.1 Court Orders, Subpoenas, and Warrants .................................................................................. 31
6.2 Research .................................................................................................................................... 33
6.3 Public Health Surveillance ......................................................................................................... 34
7. BREACHES ................................................................................................................................................ 35
7.1 Procedures ................................................................................................................................. 35
7.2 Investigation Protocol ............................................................................................................... 36
7.3 Mitigation and Corrective Action .............................................................................................. 36
7.4 Notification to Clients ................................................................................................................ 36
7.5 Notification to Governmental Authorities ................................................................................. 37
8. CLIENT RIGHTS ......................................................................................................................................... 38
APPENDIX .................................................................................................................................................... 42
227 E. CHESTNUT EXPWY, SPRINGFIELD, MO 65802 | 417-864-1658 | health.springfieldmo.gov
AN EQUAL OPPORTUNITY/AFFIRMATIVE ACTION EMPLOYER. SERVICES PROVIDED ON A NONDISCRIMINATORY BASIS.
6
Definitions
Administrative Safeguards: Administrative actions, policies, and procedures to manage the
development, implementation, and maintenance of security measures to protect electronic protected
health information and to manage the conduct of the covered entity's or business associate's employees
in relation to the protection of that information.
Authorization: A detailed document that gives covered entities permission to use protected health
information for specified purposes or to Disclose protected health information to a third party specified
by the individual.
Breach: An acquisition, access, use, or disclosure of protected health information in a manner not
permitted by the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") that
compromises the privacy or security of the protected health information.
Business Associate: An entity or person who works with a covered entity and creates, receives,
maintains, or transmits protected health information. Their work can include legal, accounting,
consulting, data aggregation, accreditation, or financial services. A covered entity may be a business
associate of another covered entity.
Confidentiality: Refers to the property that data or information is not made available or disclosed to
unauthorized persons or processes.
Covered Entity: A health plan, a health care clearinghouse, or a health care provider who transmits any
health information in electronic form to another party to carry out financial or administrative activities
related to health care.
Covered Function - Those functions of a Covered Entity of which the performance makes the entity a
health plan, health care provider, or health care clearinghouse.
Disclosure: The release, transfer, provision of access to, or divulging in any other manner of protected
health information outside of the Springfield-Greene County Health Department.
Electronic Protected Health Information ("e-PHI"): Any protected health information that is covered
under HIPAA security regulations and is produced, saved, transferred, or received in an electronic form.
Encryption: Mechanism used to transform data into a form in which there is a low probability of
assigning meaning without use of a confidential process or key.
Health Care Operations: Certain administrative, financial, legal, and quality improvement activities of a
Covered Entity that are necessary to run its business and to support the core functions of treatment and
payment.
Highly Confidential Information: Human immunodeficiency virus ("HIV")-related information, substance
abuse treatment records, mental health treatment records, and clinical laboratory results.
HIPAA: The Health Insurance Portability and Accountability Act of 1996, as amended by the Health
Information Technology for Economic and Clinical Health Act of 2009, is a federal law that establishes a
national standard for the privacy, Confidentiality, and security of health information.
227 E. CHESTNUT EXPWY, SPRINGFIELD, MO 65802 | 417-864-1658 | health.springfieldmo.gov
AN EQUAL OPPORTUNITY/AFFIRMATIVE ACTION EMPLOYER. SERVICES PROVIDED ON A NONDISCRIMINATORY BASIS.
7
HIPAA Rules: The HIPAA Privacy Rule, Security Rule, and Breach Notification Rule, more fully detailed
below, are sometimes collectively referred to herein as the HIPAA Rules.
Hybrid Covered Entity - A single legal entity that is a Covered Entity whose business activities include
both covered and non-=Covered Functions and that designates its health care components, i.e., any
component that would meet the definition of a Covered Entity or Business Associate if it were a
separate legal entity.
Privacy: Refers to the right of an individual to keep their health information private.
Privacy Officers: Springfield-Greene County Health Department's Administrator of Communicable Disease
and Public Health Resource Manager, who develop and implement policies and procedures in order to
make sure the organization is in compliance with the HIPAA Rules.
Protected Health Information ("PHI"): Individually identifiable health information that is transmitted or
maintained in any form or medium by the Springfield-Greene County Health Department. It includes
demographic/registration information (ex., address, telephone number, date of birth, citizenship, SSN,
spouse/partner/relative names) and any medical information that relates to past, present, or future
physical or mental health conditions of an individual, provision of health care to an individual, or
payment for the provision of health care to an individual that identifies or could be reasonably used to
identify an individual. Examples of medical information: medical records, photos, videotapes,
diagnostic/therapeutic reports, laboratory/pathology samples, patient business records (such as
insurance information or bills for service), verbal information provided by or about a patient, and/or
visual observations of clients receiving care or accessing services.
Security Officer: Springfield-Greene County Health Department's Security Officer is an employee from the
Office of Community Health Strategy who works with the Privacy Officers to implement, support, monitor,
investigate, and recommend information security policies and procedures.
Technical Safeguards: The technology, policy, and procedures that protect e-PHI and control access to
it.
Use: The sharing, application, review, utilization, examination, or analysis of PHI within the entity that
maintains the PHI.
User: A person or entity with authorized access.
Violation: Failure to comply with an administrative simplification provision.
227 E. CHESTNUT EXPWY, SPRINGFIELD, MO 65802 | 417-864-1658 | health.springfieldmo.gov
AN EQUAL OPPORTUNITY/AFFIRMATIVE ACTION EMPLOYER. SERVICES PROVIDED ON A NONDISCRIMINATORY BASIS.
8
1. INTRODUCTION
The purpose of the Springfield-Greene County Health Department ("SGCHD" or the
"Department") HIPAA Manual (the "Manual") is to provide a framework for divisions and
programs within the Department that may Use, Disclose, or have access to PHI in order to ensure that
PHI contained in any Department record is Used or Disclosed pursuant to HIPAA and its applicable
rules. This Manual provides guidance on how employees can perform the necessary duties of their job
while meeting legal requirements and protecting the privacy of people who receive SGCHD services or
benefits.
A major goal of this Manual is to ensure that individuals' confidential information is properly protected
and released to the Minimum Necessary Standards; while allowing the flow of health information
needed to provide and promote standardized, high-quality health care and to protect the public's health
and well-being.
What is HIPAA?
HIPAA (the Health Insurance Portability and Accountability Act of 1996, as amended by the Health
Information Technology for Economic and Clinical Health Act of 2009) is a federal law that establishes a
national standard for the privacy, confidentiality, and security of health information. Regulations issued
under HIPAA (the "HIPAA Rules") include:
* The Privacy Rule requires covered entities and business associates to implement appropriate
safeguards to protect the privacy of PHI, sets limits and conditions on the uses and disclosures
that may be made of such information without an individual's authorization, and gives
individuals rights over their PHI, including rights to examine, obtain a copy of, direct
transmission of copies, and request corrections to their health records.
* The Security Rule requires appropriate administrative, physical, and technical safeguards to
ensure the confidentiality, integrity, and security of e-PHI that is created, received, used, or
maintained by a covered entity or business associate.
* The Breach Notification Rule requires HIPAA covered entities and their business associates to
provide notification following a breach of unsecured PHI.
Other federal and state laws contain additional requirements protecting specific types ofhighly
confidential Information. If HIPAA and one of these laws apply to the same records and their
requirements conflict, the SGCHD must follow the law that is most protective of the individual who is
the subject of the record.
Why is HIPAA (Privacy) Important?
Many SGCHD services expose employees to private and confidential aspects of other people's lives.
Health records can include some of the most intimate details about a person's life, documenting a
person's physical and mental health, social behaviors, personal relationships, and financial status. When
227 E. CHESTNUT EXPWY, SPRINGFIELD, MO 65802 | 417-864-1658 | health.springfieldmo.gov
AN EQUAL OPPORTUNITY/AFFIRMATIVE ACTION EMPLOYER. SERVICES PROVIDED ON A NONDISCRIMINATORY BASIS.
9
people use SGCHD services, they trust employees to respect their privacy rights by maintaining the
confidentiality and security of their personal information. When breaches occur, this may cause the
individual to suffer financial harm, anxiety, and stigma, and in some cases, may jeopardize the
individual's immigration status, child custody, ability to obtain insurance coverage, employment
eligibility, or access to benefits.
What Are the Risks of Non-Compliance?
The U.S. Department of Health and Human Services ("HHS") Office for Civil Rights ("OCR") enforces non-
compliance. OCR may assess civil penalties for violations of the HIPAA Privacy Rule. These penalties may
be up to:
* $100-$50,000 or more per incident, capped at $1.5M per calendar year for violations of the
same requirement. In addition, the OCR may seek criminal penalties of up to:
* $50,000 and one year in prison for wrongfully obtaining or disclosing PHI.
* $100,000 and five years in prison for obtaining such information under "false pretenses."
* $250,000 and ten years in prison for obtaining or disclosing such information with the intent to
transfer or Use it for commercial or personal advantage or malicious harm.
In addition to penalties to SGCHD, individual employees found in non-compliance may face employment
and legal consequences.
1.1 General Policy Statement
All SGCHD employees are required to comply with the policies and procedures in this manual. All
employees must take reasonable steps to safeguard information from any intentional or unintentional
Use or disclosure in violation of the HIPAA Rules and the policies in this manual. Information to be
safeguarded may be in any medium, including paper, electronic, oral, and visual representations of
confidential information. All business associates, consultants, and volunteers must also adhere to the
HIPAA regulations, where applicable.
SGCHD is a Hybrid Covered Entity under HIPAA. A Hybrid Covered Entity performs both health care and
non-health care functions as part of its daily business operations. As a Hybrid Covered Entity, SGCHD
must ensure that its health care components comply with the HIPAA Privacy Rule. In particular, a Hybrid
Covered Entity, and not merely the health care components of such, must ensure that:
(A) Its health care component does not disclose PHI to another component of the Covered
Entity in circumstances in which the HIPAA Privacy Rule would prohibit such disclosure if the
health care component and the other component were separate and distinct legal entities;
(B) Its health care component protects e-PHI with respect to another component of the Covered
Entity to the same extent that it would be required to protect such information if the health
care component and the other component were separate and distinct legal entities;
227 E. CHESTNUT EXPWY, SPRINGFIELD, MO 65802 | 417-864-1658 | health.springfieldmo.gov
AN EQUAL OPPORTUNITY/AFFIRMATIVE ACTION EMPLOYER. SERVICES PROVIDED ON A NONDISCRIMINATORY BASIS.
10
(C) If a person performs duties for both the health care component in the capacity of a member
of the workforce of such component and for another component of the entity in the same
capacity with respect to that component, such workforce member must not use or disclose PHI
created or received in the course of or incident to the member's work for the health care
component in a way prohibited by the HIPAA Privacy Rule.
(D) The Covered Entity is responsible for designating the components that are part of one or
more health care components of the Covered Entity and documenting the designation, provided
that, if the Covered Entity designates one or more health care components, it must include any
component that would meet the definition of a Covered Entity or Business Associate if it were a
separate legal entity. Health care component(s) also may include a component only to the
extent that it performs covered functions.
The health care components of SGCHD are those programs that provide health care and receive and/or
transmit PHI as part of their health care operations. These include activities within the following
divisions and programs, to the extent that they perform Covered Functions: Business Office; Chronic
Disease and Prevention (Family Connects, Community Health Advocates); Outreach; Community Health
and Epidemiology (Sexually Transmitted Infection "STI" Clinic, Disease Intervention Specialists (DIS),
Tuberculosis "TB" Clinic, Epidemiology); Community Health Strategy and Emerging Public Health (Lab
and Vaccination services).
Reference: 45 CFR 164.105
To implement a policy or procedure change, SGCHD's health care components must:
* Ensure that the revised policy or procedure complies with the standards, requirements, and
implementation specifications of 45 CFR 164.530 and 45 CFR 164.400;
* Document the revised policy or procedure; and
* Changes will be presented to Departmental administrators and directors for consideration and
adoption.
* Revise the notice as required by 45 CFR 164.520(b)(3) to state the changed practice and make
the revised notice available as required by 45 CFR 164.520(c).
* SGCHD's health care components may not implement a change to a policy or procedure prior to
the effective date of the revised notice.
Reference: 45 CFR 164.530
1.2 Business Associates
SGCHD does not carry out all of its health care activities and functions by itself. SGCHD often utilizes the
services of a variety of other health care organizations. A Business Associate is a person or entity, who is
not a SGCHD employee, who works with the SGCHD and creates, receives, maintains, and transmits PHI.
227 E. CHESTNUT EXPWY, SPRINGFIELD, MO 65802 | 417-864-1658 | health.springfieldmo.gov
AN EQUAL OPPORTUNITY/AFFIRMATIVE ACTION EMPLOYER. SERVICES PROVIDED ON A NONDISCRIMINATORY BASIS.
With Free Trial, you can:
You will have a full access to bids, website, and receive daily bid report via email and web.
Number: 674039 Title: 26-RFP-674039-TJL Freightway On-Call Technical and Professional Consultant Type: RFI All
St. Louis region
Bid Due: 8/05/2026
Sport Court Improvements - Auburn, KS 25-1272M StatusAccepting Bids Bid Date 8/12/26 11:00am
Drexel Technologies
Bid Due: 8/12/2026
JCL RFP - Website Services 2026
Jefferson County Library
Bid Due: 8/07/2026
Basic Information Negotiation MODOT 0000000350SL,1 Title On-Line Surplus Auction Services Negotiation Type REQUEST
State Government of Missouri
Bid Due: 8/17/2026