Audit-proof documentation before the underwriter asks.
The 2026 HIPAA Security Rule made MFA and encryption mandatory by November. Your insurance application now demands proof. HIPAAPath gets your risk assessment done — in plain language, in the format your underwriter recognises — and your documents stay in your browser, not on our servers.
Free SRA: do one chapter at a time, save as you go, manual yours to keep. Insurance-Ready Summary: a carrier-mapped PDF for the renewal moment.
Already have a saved file? Restore your progress →
What cyber-liability carriers actually want.
We pulled eight cyber-liability applications — Beazley, Coalition, Chubb, Travelers, Hiscox, CNA, MedPro, and The Doctors Company. They ask for the same eight things. Different wording, same eight control groups. We’ve walked the apps and lined the questions up with HIPAAPath. Here’s the crosswalk.
The free SRA produces your §164-formatted Practice Security Manual — the document an auditor or attorney reads. The $99 Insurance-Ready Summary repackages the same data into the eight-group format underwriters score against. The manual is your year-round artifact; the summary is your renewal-week artifact.
Free for the chapters. $99 for the renewal artifact. $299/yr for the long haul.
Three places this can stop. The chapters and the Practice Security Manual are free either way — no card needed; you sign in only to download. The paid tiers add things you only need at specific moments.
The free SRA
$0Walk the chapters at your own pace — no account needed to work. Save as you go. Your Practice Security Manual downloads to your computer when you finish — yours forever; you sign in once at download.
- ✓Full 17-section §164-formatted manual
- ✓Auto-fill within the document — answer once, use everywhere
- ✓Save as you go
- ✓Adopt-and-edit sanction policy template
- ✓Your manual, downloaded to your computer, yours forever
- ✓Browser-editable for 90 days from your last save — download a JSON backup any time
Insurance-Ready Summary
$99 — one-timeInsurance renewal coming up? The Carrier-Mapped Summary takes the work you’ve already done in the chapters and re-formats it into the eight-group structure underwriters score against — Beazley, Coalition, Chubb, Travelers, Hiscox, CNA, MedPro, The Doctors Company. One PDF to hand your broker.
- ✓Eight carrier control groups, in carrier order
- ✓Two answer formats: free-text paragraph for essay-style carriers, Yes/No-with-detail for checkbox-style carriers
- ✓Appendix: 2026 mandate checklist + NIST 800-30 mapping
- ✓Regenerate any time while your assessment is editable — 90 days from your last save (matches typical renewal prep). JSON backup any time, or upgrade to Founding Member to keep editing indefinitely.
Founding Member
$299 / yrFor practices treating compliance as an ongoing relationship, not a one-time task. Your assessment stays editable across renewal cycles — no 90-day clock. Includes the Carrier-Mapped Summary, 13 NIST-anchored policy template bodies in your manual, the quarterly compliance brief, and every paid tool we ship while you’re a member.
- ✓Assessment editable indefinitely — no 90-day clock; come back across renewal cycles
- ✓Carrier-Mapped Summary regenerations any time
- ✓13 NIST-anchored policy template bodies in your manual (sanction, risk analysis, contingency, training, …)
- ✓Quarterly compliance brief — opt-in live in your account
- ✓Every paid feature we ship while you’re a member
A real audit-ready manual.
Not a checklist.
Nine chapters of guided questions produce a 17-section manual formatted to §164 of the HIPAA Security Rule — the same structure an auditor reads.
Other tools give you a checklist or a blank template. We give you the document.
Answer once. Use everywhere.
Tell us about your practice in Chapter 1. We auto-fill those answers wherever they show up later — your risk analysis, your inventory, your safeguards.
Save as you go, one chapter at a time — stop and pick up exactly where you left off.
Your answers save in your browser.
Your practice details, device serial numbers, and risk findings save in your browser’s local storage, not on our servers. You can verify that in your browser’s developer tools (Application → IndexedDB).
When you finish, your manual downloads to your computer. Sign-in (when you choose to) only carries your email — not your answers.
For the long haul.
Free covers the §164 manual you can finish today. The Founding Member tier is for practices treating compliance as an ongoing relationship — these are the tools we’re shipping while you’re a member.
Quarterly compliance brief.
OCR settlements and rule-change updates in plain English, on a quarterly cadence. Opt-in is live in your account today; the first issue ships when we send it.
Adopt-and-edit policy templates.
Thirteen NIST-anchored policy frameworks — sanction policy, risk analysis, contingency, incident response, BAA clauses, training, and more — included with the Founding Member tier. Free-tier manuals list what’s in the section so you know what you’re upgrading for.
Built for auditors to read.
Questions practices actually ask.
Start the first chapter. Stop when you want.
Your work saves as you go, right in your browser. No card to enter, nothing to install — you sign in only when you’re ready to download your manual.
