Policies
Policies your staff will actually read, and a record that they did.
A library of plain-language HIPAA policies you can adopt as written or adapt, with versioning and per-person acknowledgements. The document is the easy part — the signature trail is what gets asked for.
Last reviewed .
Written for a small organization
Not a hundred-page template pack cloned from a hospital. The policies describe controls a fourteen-person company can genuinely operate, which matters because a policy you do not follow is worse than one you never wrote.
Versioned, with the history kept
Publishing a new version asks staff to re-sign, because a signature against superseded text proves nothing. The previous version and its signatures stay in the record.
Acknowledgements with names and dates
Each person reads and signs in their own account. The register shows who has signed which version and when, and chases the people who have not.
Straight into the evidence pack
The policy list, current versions and acknowledgement dates are a section of the Trust Packet, so there is nothing to assemble when a client asks.
Common questions
- What are the three core rules of HIPAA?
- The Privacy Rule, which governs how protected health information may be used and disclosed; the Security Rule, which requires administrative, physical and technical safeguards for electronic PHI; and the Breach Notification Rule, which says who must be told when something goes wrong. Your written policies are where you state how your organization meets each one.
- What are the four HIPAA standards?
- The Administrative Simplification provisions group into four standards: privacy, security, national identifiers, and electronic transactions and code sets. For a small organization the first two are where nearly all the policy work sits — the templates here cover them in plain language you can edit to match how you actually operate.
Keep reading
- HIPAA risk assessment softwareGuided assessment with remediation tracking and carry-forward.
- Staff training and certificatesAnnual courses with dated certificates and chasing.
- Vendor and BAA registerWho touches patient data, what is signed, when it expires.
- Incident and breach logFour-factor assessment with the deadline counting down.
- Free BAA template generatorA plain-language agreement with every required provision, built in your browser.
Software and researched information, not legal advice. No product can make an organization “HIPAA certified” — no such designation exists under the HIPAA rules, and using this service does not establish that you comply with them.