Are there requirements for covered entities to have written privacy policies? If so, what has to be addressed in the policy?

We will be happy to critique your thinking