Trust Packet
One dated PDF answering “send us your HIPAA documentation”. It shows your programme as it actually stands — nothing is inferred or padded.
What goes in
Everything below is generated from your live data.
- Ready
Risk assessment summary
Readiness score 72, with per-safeguard breakdown and the date each control was last answered.
- Ready
Remediation status
1 closed, 6 open with owners and due dates.
- Ready
Policies and acknowledgements
4 policies, each with its version and who signed it when.
- Ready
Training certificates
3 of 6 staff current. Certificates carry names and completion dates.
- Ready
Vendor and BAA register
2 signed of 4 vendors that handle patient information.
- Ready
Incident log
2 recorded, with the assessment and any notification deadlines.
- Ready
Verified configuration checks
3 of 9 controls confirmed directly against Microsoft 365, with timestamps.
Generate
The packet is stamped with the moment it was generated and never implies it is fresher than the data behind it.
Last generated July 22, 2026.
Worth fixing first
These will be visible to whoever reads the packet.
- Tomas Alvarez has not completed training
- Agreement with Dropbox expired
- Overdue: Countersign BAA with Northbay Clearing
You can send it anyway. An honest packet with three open items reads better to a reviewer than a suspiciously perfect one.
Public trust page
Share a live link instead of a PDF, with per-section control over what is shown. Unlisted by default.
The packet documents your programme. It is not certification, not an audit opinion and not legal advice, and it does not establish that your organization complies with HIPAA — only that these records exist as of the date shown.