River
Y CombinatorBacked by Y Combinator
FREE TEMPLATE

HIPAA Policies and Procedures Template

Four documents and four sheets that pair every Security Rule safeguard with the dated artifact proving it operated, not the policy claiming it.

Free download  ·  No account needed

Safeguard Evidence Register

One row per implementation specification

Arrives seeded with all forty-eight rows and their citations. You fill the two columns on the right, and they never borrow from each other.

CitationImplementation specificationTypePolicy claims itDated artifact
164.308(a)(1)(ii)(A)Risk analysisRequiredyes
164.308(a)(3)(ii)(C)Termination proceduresAddressableyes
164.308(b)(3)Written contract or other arrangementRequiredyes
164.310(d)(2)(i)DisposalRequiredyes
164.312(a)(2)(iii)Automatic logoffAddressableyes
164.312(a)(2)(iv)Encryption and decryptionAddressableyes
164.316(b)(2)(i)Time limitRequiredyes

19 Required · 22 Addressable · 7 standards with no labeled specification

A downloaded policy set fills the fourth column completely and the fifth column not at all. The fifth column is the one an information request asks for.

Remaining columns: Standard, Artifact Date, Evidence Location, Status, Addressable Decision, Decision Date, Owner, Notes.

Every free HIPAA policy pack for a medical practice is the same object. A folder of Word documents covering privacy, security, breach and workforce, adopted verbatim and filed on a shared drive. It is the cheap half of the work. Nobody examining a practice reads the binder for its own sake. They ask for the dated artifact behind it, and a policy set with nothing behind it does not read as partial compliance. It reads as a written record of what the practice knew it was supposed to be doing.

So the register in this pack has forty-eight rows and two columns that never borrow from each other. One names the policy claiming a safeguard. The other names the dated artifact evidencing it. Forty-one of those rows are the implementation specifications the Security Rule labels Required or Addressable, nineteen and twenty-two respectively, and seven are standards carrying no labeled specification. Addressable is the trap. Skipping one without a written assessment produces an undocumented gap rather than a considered decision, and no policy template produces that record.

Marlbrook Family Health scored its downloaded binder against the register. Policy text covered forty-one of forty-one specifications. Twelve had a dated artifact behind them. Two more were closed by a written decision not to implement, which is a valid outcome, leaving twenty-seven open: eleven Required with nothing behind them, sixteen Addressable skipped with no assessment recorded anywhere. Its 2019 access policy, replaced in January 2024, has to survive until January 2030 rather than March 2025, because the retention clock runs from the later of the two dates.

Every document in the pack

The Safeguard Evidence Register, the BAA Register, and the Training and Attestation Tracker.

Safeguard Evidence Register

Illustrative scoring for a fictional practice, Marlbrook Family Health.

OutcomeRequiredAddressableTotal
Dated artifact on file8412
Written decision not to implementn/a22
Open111627
Labeled specifications192241

The binder scores 41 of 41. The register scores 12. Every one of the forty-one rows had policy text claiming the safeguard, because that is what a downloaded policy set does. Twelve had something dated behind them.

The sixteen are the finding. Not the eleven. A Required specification with no artifact is a gap the practice can see. An addressable specification skipped with no assessment recorded is a gap nobody knows exists, because addressable reads as optional and is not.

Seven further rows cover the standards in this range that carry no labeled specification, for forty-eight rows in all.

BAA Register

Built from an eighteen-month payment export rather than from the vendor list the practice wrote from memory.

StepCountWhat it means
Recurring vendors in the export31Money is the honest source
Create, receive, maintain or transmit PHI14Each with the reasoning recorded
Signed agreement on file95 have none at all
Counterparty verified still current72 name an acquired entity

Seven of fourteen are covered. The five with no agreement are the answering service, the patient survey platform, the copier lease, an ambient scribe tool a clinician started using, and the online intake form vendor. None of them appeared on the list the practice wrote from memory. All five appeared on the card statement.

The two acquired entities are worse than the five. They look closed. An agreement naming a company absorbed two years ago is an agreement with nobody, and nothing in a folder of signed PDFs surfaces that.

The register also records the agreed reporting window, who bears notification cost, and whether subcontractors are disclosed. The regulation sets none of those.

Training and Attestation Tracker

Three obligations tracked separately, because they have different clocks and different triggers.

ObligationOwedRecordedWhere the record lives
Every workforce member23914 only in a closed portal
New joiners44Practice records
Material change retraining110No rows ever opened

The vendor dashboard said 23 of 23 complete. The practice changed training platforms and exported nine attestations before the old contract ended. Fourteen people were trained and there is no retrievable record that they were, which is a different problem from not training them and needs a different fix.

The eleven are the obligation nobody tracks. A material change to a policy opens a retraining obligation for every person whose functions it affects, running from the date the change took effect. Nothing creates those rows unless the policy revision creates them.

The tracker's most useful column asks whether the attestation can be exported from the practice's own records. It takes an afternoon while the contract is live and is impossible afterwards.

What's in the pack

01

Safeguard Evidence Register

Forty-eight seeded rows carrying the citation, the policy that claims the safeguard and, in a column that never borrows from it, the dated artifact that evidences it. Same split a SOC 2 evidence register makes for a control.

02

Where the risk analysis fits

Row one of the register is the risk analysis at 164.308(a)(1)(ii)(A), and every other safeguard decision refers back to it. It is enough work to have its own pack: the HIPAA security risk assessment template rates assets rather than specifications.

03

Policy Register

Runs the retention clock properly. Documentation is kept six years from creation or from the date it last was in effect, whichever is later, so a superseded version outlives its replacement.

04

BAA Register

One row per vendor found in a payment export, with the two checks that quietly fail: whether the counterparty still exists, and what the agreement says about the terms the regulation leaves open. Pairs with tracking vendor renewals on the commercial side.

05

Training and Attestation Tracker

Separates the course from the record of the course, tracks all three training obligations rather than one, and asks whether the attestation is exportable from the practice's own records.

06

Policy Set by Domain

Which policies this practice needs, what each has to cover, and the artifact that evidences each one. A map rather than a binder to adopt verbatim.

07

Breach Response Plan

The first hour, the first four days and the first sixty. Built around the two decisions made under pressure: when the clock started, and whether to preserve or repair. The incident and breach response pack runs the four-factor test and both notification thresholds once that clock is running.

08

Business Associate Agreement Template

The provisions the regulation requires, and separately the commercial terms it leaves silent, which are where a vendor's standard form quietly gives the practice less.

09

Evidence and Training Sweep

A weekly read for the things that fail silently. A vendor acquired, a policy revised with no retraining rows opened, an attestation stranded in a portal nobody can log into.

How to use it

  1. 1

    Open in River, or download it

    Open the pack in River and let the agent score your existing binder against the register, or download the blank Word and CSV files instantly and fill them in yourself.

  2. 2

    Send documents, not information

    The binder in whatever state it is in, an eighteen-month payment export, your training completion report, signed agreements, any prior risk analysis or insurer questionnaire. Photographs of signed sheets count.

  3. 3

    Watch the two columns diverge

    The policy column fills almost completely and the artifact column does not. The rows where they disagree are the work, sorted by how much each one costs to leave open.

  4. 4

    Close the addressable gaps in writing

    Each skipped addressable specification gets an assessment, a decision, a date and a name. Termination procedures is the one an examiner tests first, so start where your joiner and leaver record already lives.

Frequently asked questions

Is this template free?

Yes. Download the whole pack as Word documents and CSV sheets with no credit card. "Edit with AI" is a separate, optional path for practices that want the agent to read their existing documents and score them against the register. Other packs are in the template library.

What format are the downloaded files?

Word documents (.docx) for the four documents and CSV (.csv) for the four sheets, zipped into one file. They open natively in Word, Pages, Google Docs, Excel, Numbers and Sheets, with nothing to convert and no macros.

Does adopting these policies make my practice HIPAA compliant?

No, and any pack claiming otherwise is selling you the cheap half. Policies describe operations only your practice knows, and a policy describing a workflow you do not run documents the gap rather than closing it. This pack is built to show you which claims have nothing behind them.

What does addressable actually mean?

Not optional. You assess whether the specification is reasonable and appropriate in your environment, then either implement it or document why not and implement an equivalent alternative where one is reasonable. Skipped with nothing written down is an undocumented gap, and it is the most common thing this register surfaces.

Why build the vendor register from invoices instead of asking?

Because asked to list their vendors, a practice names the record system, the clearinghouse and the biller, and the missing agreements are never with those three. They are with the answering service and the survey tool somebody trialled and kept. Money remembers what people do not.

Is this legal advice?

No. The pack records what exists and what does not, with dates and citations. It will not tell you whether a gap is a violation, what a penalty would be, or whether an incident is reportable. It exists so that conversation with counsel starts from an accurate picture. When the request is for records rather than policies, use the audit response pack.

What does 'Edit with AI' actually do?

It creates a free River account, installs this exact pack as a private workspace, and opens it ready to read whatever you send. Nothing is written until you send something. The same workspace also handles security questionnaires that ask for the same artifacts.

Find out what your binder actually has behind it

Download the blank pack as Word and CSV files, or open this exact pack in River and let the agent score your existing policies against the evidence register.

Edit with AI