Free HIPAA Policy Templates
Policies are the foundation of any HIPAA compliance program and should reflect the standards, requirements, and expectations for how the team works. Every template below is de-branded, paired by topic, and mapped to the 45 CFR §164 controls. Filter to your organization type, replace the [bracketed]items with your organization's specifics, and review with counsel before adoption.
Access Management
- v1.0
Access Control
This Policy establishes how [Organization] grants, manages, and revokes access to information systems, applications, devices, and the electronic protected health information (ePHI) they contain, so that access is limi…
164.308(a)(3)(i) · 164.308(a)(3)(ii)(A) · 164.308(a)(3)(ii)(C) · 164.308(a)(4)(i) · 164.308(a)(4)(ii)(A) · 164.308(a)(4)(ii)(B) · 164.308(a)(4)(ii)(C) · 164.308(a)(5)(ii)(D) · 164.312(a)(1) · 164.312(a)(2)(i) · 164.312(a)(2)(ii) · 164.312(a)(2)(iii) · 164.312(d)
Download: Policy .md · Procedures .md
- v1.0
Access Request & Review Log
Evidence that access is granted deliberately and re-checked over time: the approval trail behind access authorization and establishment, plus the record of your periodic reviews.
164.308(a)(4)(ii)(B) · 164.308(a)(4)(ii)(C) · 164.308(a)(3)(ii)(A)
Download: Spreadsheet .xlsx
- v1.0
Onboarding / Offboarding Tracker
A per-person tracker for joining and leaving: the evidence that clearance happens on the way in and, critically, that access is cut on time on the way out.
164.308(a)(3)(ii)(B) · 164.308(a)(3)(ii)(C)
Download: Spreadsheet .xlsx
- v1.0
Role / Permission (Access) Matrix
A grid that documents who should be able to reach what, so you can grant the least each role needs and prove it: the access-decision record behind information access management and minimum necessary.
164.308(a)(4)(i) · 164.502(a)/(b)
Download: Spreadsheet .xlsx
Asset Management
- v1.0
Asset & ePHI Inventory
A ready-to-fill spreadsheet for the accountable inventory of every asset that stores or accesses ePHI: the record HIPAA's Device & Media Controls assume you keep, and the starting point for your Risk Analysis.
164.310(d)(1) · 164.308(a)(1)(ii)(A)
Download: Spreadsheet .xlsx
- v1.0
Data Flow Map
A fill-in map of where ePHI is created or received, where it's processed and stored, and where it goes: the artifact an auditor asks for (and most organizations skip because "diagram" sounds like work).
164.310(d)(1) · 164.308(a)(1)(ii)(A)
Download: Spreadsheet .xlsx
- v1.0
Device & Media Controls
This Policy establishes how [Organization] governs the use of workstations and the movement, re-use, and protection of the hardware and electronic media that create, receive, maintain, or transmit electronic protected…
164.310(b) · 164.310(c) · 164.310(d)(1) · 164.310(d)(2)(ii) · 164.310(d)(2)(iii) · 164.308(a)(5)(ii)(B)
Download: Policy .md · Procedures .md
- v1.0
Physical & Facility Security
This Policy establishes how [Organization] limits physical access to the facilities, workspaces, and systems that house or are used to access electronic protected health information (ePHI), so that only authorized per…
164.310(a)(1) · 164.310(a)(2)(i) · 164.310(a)(2)(ii) · 164.310(a)(2)(iii) · 164.310(a)(2)(iv) · 164.310(d)(2)(i)
Download: Policy .md · Procedures .md
Data Security
- v1.0
Data Security & Encryption
This Policy establishes how [Organization] protects electronic protected health information (ePHI) through encryption and integrity controls across its full lifecycle: at rest, in transit, and when equipment that hold…
164.312(c)(1) · 164.312(c)(2) · 164.312(e)(1) · 164.312(e)(2)(i) · 164.312(e)(2)(ii) · 164.312(a)(2)(iv) · 164.310(d)(2)(iv)
Download: Policy .md · Procedures .md
Policies & Governance
- v1.0
HIPAA Glossary & Definitions
Plain-language definitions of the terms and acronyms used across HowToHIPAA's policies, procedures, and the compliance posture assessment.
Download: Policy .md
- v1.0
HIPAA Policy Management & Documentation
This Policy is the meta-policy that governs every other policy and procedure in [Organization]'s HIPAA compliance program.
164.316(a) · 164.316(b)(1) · 164.316(b)(2)(i) · 164.316(b)(2)(ii) · 164.316(b)(2)(iii) · 164.530(i) · 164.530(j)
Download: Policy .md · Procedures .md
- v1.0
Sanction Record
The confidential record that your sanction policy has teeth (each violation, the outcome, and the action applied), the proof an auditor looks for that consequences are real.
164.308(a)(1)(ii)(C) · 164.530(e)
Download: Spreadsheet .xlsx
- v1.0
Training Roster & Completion Log
The per-person roster that shows your whole workforce completed security-awareness and HIPAA training: the evidence behind the training requirement, kept current as people join.
164.308(a)(5)(i) · 164.530(b)
Download: Spreadsheet .xlsx
- v1.0
Workforce Security, Training & Sanctions
This Policy establishes how [Organization] manages the people dimension of protecting electronic protected health information (ePHI) and protected health information (PHI): screening workforce members before they are …
164.308(a)(3)(ii)(B) · 164.308(a)(5)(i) · 164.308(a)(5)(ii)(A) · 164.308(a)(1)(ii)(C) · 164.530(b) · 164.530(e) · 164.530(g)
Download: Policy .md · Procedures .md
Privacy
- v1.0
Accounting of Disclosures Log
Covered entities onlyThe running record of accountable PHI disclosures, so you can produce an accounting on request: the artifact behind an individual's right to know where their information went.
164.528
Download: Spreadsheet .xlsx
- v1.0
Amendment Request Form & Log
Covered entities onlyThe record that you handle PHI-amendment requests properly and on time: an intake form for the request and a log that tracks each one to a decision within the legal deadline.
164.526
Download: Spreadsheet .xlsx
- v1.0
Notice of Privacy Practices (NPP)
Covered entities onlyThe public notice a Covered Entity must give individuals describing how it uses and discloses PHI and their rights.
164.520
Download: Policy .md
- v1.0
Privacy
Covered entities onlyThis Policy establishes how [Organization] uses and discloses protected health information (PHI), and how it honors the privacy rights of the individuals whose information it holds, so that PHI is used and shared only…
164.502(a)/(b) · 164.502(g) · 164.506 · 164.508 · 164.510 · 164.512 · 164.514(a)-(c) · 164.514(d) · 164.514(f)/(g) · 164.520 · 164.522 · 164.524 · 164.526 · 164.528 · 164.530(d) · 164.530(h)
Download: Policy .md · Procedures .md
Process Diligence
- v1.0
Audit Controls & Activity Review
This Policy establishes how [Organization] records, protects, and reviews activity in the information systems, applications, and devices that create, receive, maintain, or transmit electronic protected health informat…
164.312(b) · 164.308(a)(5)(ii)(C) · 164.308(a)(1)(ii)(D)
Download: Policy .md · Procedures .md
- v1.0
Breach Notification
This Policy establishes how [Organization] determines whether an impermissible use or disclosure of unsecured protected health information (PHI) is a reportable breach, and how it notifies affected individuals, the me…
164.402 · 164.404 · 164.406 · 164.408 · 164.410 · 164.412 · 164.414
Download: Policy .md · Procedures .md
Resilience & Continuity
- v1.0
Contingency Plan Test Record
The evidence that your contingency plans are exercised, not shelf-ware: each test, its result, and the gaps you found and fixed.
164.308(a)(7)(ii)(D) · 164.308(a)(7)(ii)(B)
Download: Spreadsheet .xlsx
- v1.0
Contingency Planning
This Policy establishes how [Organization] prepares for, responds to, and recovers from emergencies and other events (fire, system failure, cyberattack, vendor outage, natural disaster) that could damage systems conta…
164.308(a)(7)(i) · 164.308(a)(7)(ii)(A) · 164.308(a)(7)(ii)(B) · 164.308(a)(7)(ii)(C) · 164.308(a)(7)(ii)(D) · 164.308(a)(7)(ii)(E)
Download: Policy .md · Procedures .md
- v1.0
Data Backup Plan
The specific, fillable plan for creating and maintaining retrievable exact copies of ePHI: the annex your Contingency Planning Policy points to.
164.308(a)(7)(ii)(A) · 164.310(d)(2)(iv)
Download: Policy .md
- v1.0
Disaster Recovery Plan
The step-by-step for restoring systems and ePHI after a disruptive event.
164.308(a)(7)(ii)(B)
Download: Policy .md
- v1.0
Emergency Mode Operation Plan
How you keep critical, PHI-protecting processes running while systems are down: the bridge between disaster and full recovery.
164.308(a)(7)(ii)(C) · 164.312(a)(2)(ii)
Download: Policy .md
- v1.0
Incident Response Runbook
The operational play the Incident Response Team runs when a security incident is suspected: the hands-on annex to your Security Incident Response Policy.
164.308(a)(6)(i) · 164.308(a)(6)(ii)
Download: Policy .md
- v1.0
Security Incident Response
This Policy establishes how [Organization] identifies, responds to, documents, and mitigates suspected or known security incidents affecting its information systems and the electronic protected health information (ePH…
164.308(a)(6)(i) · 164.308(a)(6)(ii) · 164.530(f)
Download: Policy .md · Procedures .md
Risk Management
- v1.0
Risk Register
The living record of the risks you identified and what you're doing about each one: the evidence behind HIPAA's risk-management requirement, kept current rather than filed once and forgotten.
164.308(a)(1)(ii)(B)
Download: Spreadsheet .xlsx
- v1.0
Security & Privacy Program Charter
The one-page mandate that establishes your HIPAA program: who owns it, what it covers, and the authority behind it.
164.308(a)(1)(i) · 164.308(a)(2)
Download: Policy .md
- v1.0
Security & Privacy Program
This Policy establishes [Organization]'s overall security and privacy program, the umbrella under which every other policy in this library operates.
164.308(a)(1)(i) · 164.308(a)(1)(ii)(A) · 164.308(a)(1)(ii)(B) · 164.308(a)(2) · 164.530(a) · 164.530(c) · 164.308(a)(8)
Download: Policy .md · Procedures .md
Vendor & BAA Management
- v1.0
Breach Reporting to Covered Entity
This Policy establishes how [Organization], as a Business Associate, detects and reports breaches of unsecured PHI to the affected covered entity, without unreasonable delay and within the required timeframe, with the…
164.410 · 164.410 / SLA · 164.502(e)/.504(e)
Download: Policy .md
- v1.0
Business Associate Agreement (BAA)
This is a contract between a Covered Entity (or a Business Associate) and its Business Associate.
164.502(e)/.504(e) · 164.314(a)(1)
Download: Policy .md
- v1.0
Business Associate HIPAA Obligations
This Policy establishes the obligations [Organization] accepts as a Business Associate (BA) when it creates, receives, maintains, or transmits protected health information (PHI) on behalf of a covered entity or anothe…
164.502(a)(3) · 164.502(a)(4) · 164.502(a)(5)(ii) · 164.502(a)/(b) · 164.514(d) · 164.502(b) / .514(d) · 164.502(e)/.504(e)
Download: Policy .md · Procedures .md
- v1.0
Subcontractor Business Associate Agreement
This is the downstream BAA between a Business Associate and its Subcontractor.
164.502(e)/.504(e) · 164.502(e)(1)(ii)
Download: Policy .md
- v1.0
Subcontractor Management
Business associates onlyThis Policy establishes how [Organization], as a Business Associate, engages and oversees subcontractors that create, receive, maintain, or transmit protected health information (PHI) on its behalf, so that the protec…
164.502(e)(1)(ii) · 164.308(b)(2)-(3) · 164.504(e)(2)(ii)
Download: Policy .md · Procedures .md
- v1.0
Vendor & Business Associate Management
This Policy establishes how [Organization] selects, contracts with, and oversees the third-party vendors and service providers it relies on, and, where those vendors create, receive, maintain, or transmit protected he…
164.308(b)(1) · 164.502(e)/.504(e) · 164.314(a)(1) · 164.314(a)(2) · 164.314(b)
Download: Policy .md · Procedures .md
Not sure which of these you actually need? Our free self-assessment turns this library into your own prioritized list.
Take the free assessment