For solo and small practices going through HIPAA on their own

The HIPAA paperwork you can hand over — when your insurance company or an auditor asks.

You’re responsible for the patient information that lives on your computer, your phone, and in your email — and nobody taught you this in school. There are new cybersecurity rules now, and some take effect this November you’d have no way of knowing about. Once a year you’re meant to look at what could go wrong with your patients’ information and write down what you’ve done about it — the record you hand over if you’re ever asked. HIPAAPath walks you through it in plain language, one question at a time. Your answers stay in your browser, not on our servers.

Free: do one chapter at a time, save as you go, and the manual is yours to keep. Insurance-Ready Summary: one PDF you can hand your insurance company — at renewal, or any time they ask.

Already have a saved file? Restore your progress →

/ 00   The proof

What insurance companies actually want.

Carry — or shopping for — cyber-liability or malpractice coverage? This part is for you. We read five real cyber-insurance applications — including two forms our own broker sent us. Different companies, different wording — but every question they ask falls into the same eight topics. We’ve gone through the applications and matched each question to where HIPAAPath already has your answer. Here’s how they line up. No policy like that yet? These same eight answers still build the HIPAA Security Manual you keep for an audit — and they’re ready the day you do shop for coverage.

Coverage through a malpractice carrier like MedPro or The Doctors Company? Their cyber questionnaires follow the same pattern — the same eight topics below.

Identity & AccessIs multi-factor authentication enabled on email, EHR, and remote access, with a unique login per person?Captured from your responses
Data ProtectionAre laptops, mobile devices, and removable media encrypted — at rest and in transit?Captured from your responses
Backup & RecoveryAre backups encrypted, off-site, and restoration-tested?Captured from your responses
Endpoint & NetworkDo workforce devices run endpoint detection, and is patient-data infrastructure isolated from guest / IoT networks?Captured from your responses
Email SecurityIs email filtered for phishing, with SPF, DKIM, and DMARC authentication in place?Captured from your responses
Incident ResponseDo you have a documented, tested breach-response and notification procedure?Captured from your responses
People & ProcessIs there a named security officer, annual workforce training, and a recent vulnerability assessment?Captured from your responses
Compliance AttestationsCan you attest to HIPAA and HITECH compliance, plus any standards you follow (SOC 2, NIST CSF)?Captured from your responses

The free chapters produce your HIPAA Security Manual, laid out section by section the way an auditor or attorney reads. The $99 Insurance-Ready Summary takes the same answers and arranges them into the eight-topic layout insurance companies score. The manual is the one you keep all year; the summary is the one you hand over at renewal.

/ 01   Three ways to use it

Free for the chapters. $99 for the renewal PDF. $299/yr for the long haul.

There are three places you can stop. The chapters and your HIPAA Security Manual are free either way — no card needed; you sign in only to download. The paid tiers add things you only need at certain moments.

Free — yours to keep

The free version

$0

Walk the chapters at your own pace — no account needed to work. Save as you go. Your HIPAA Security Manual downloads to your computer when you finish — yours forever; you sign in once at download.

  • Full 17-section manual, in the order the HIPAA rule uses
  • Auto-fill within the document — answer once, use everywhere
  • Save as you go
  • Adopt-and-edit policy template (what happens if someone breaks the rules)
  • Your manual, downloaded to your computer, yours forever
  • Editable in your browser for 90 days from your last save — download a backup file any time
For renewal week

Insurance-Ready Summary

$99 — one-time

Insurance renewal coming up? This summary takes the work you’ve already done in the chapters and lays it out in the eight-topic format insurance companies score — built from five real cyber-insurance applications, including forms our own broker sent us. One PDF to hand your broker.

  • The eight topics insurance companies ask about, in the order they ask
  • Two answer styles: a written paragraph for applications that want an essay, and Yes/No-with-details for the ones with checkboxes
  • Appendix: a readiness checklist for the proposed 2026 rule update, plus how it all maps to the federal risk guide
  • Regenerate it any time while your answers are still editable — 90 days from your last save (about how long renewal prep takes). Download a backup file any time, or upgrade to Founding Member to keep editing for good.
Get the Insurance-Ready Summary $99 — one-time purchase
/ 02   What you walk out with

A real audit-ready manual.
Not a checklist.

Nine chapters of plain questions produce a 17-section manual, laid out in the same order as the HIPAA Security Rule — the order an auditor reads.

Other tools give you a checklist or a blank template. We give you the document.

17
manual sections
1
Downloadable PDF
A real page from a HIPAAPath HIPAA Security Manual — §164.308 Administrative Safeguards, showing the Security Management Process, Assigned Security Responsibility, and Workforce Security standards, each marked verified.
An actual manual page — the Administrative Safeguards section (§164.308)
Download this sample page (PDF)
/ 03   Why it’s less work than it looks

Answer once. Use everywhere.

Tell us about your practice in Chapter 1. We fill those answers in wherever they come up again — the report on what could go wrong, your list of devices, your safeguards.

Save as you go, one chapter at a time — stop and pick up exactly where you left off.

/ 04   Your answers stay yours

Your answers save in your browser.

Your practice details, device serial numbers, and what you find along the way all save in your browser’s own storage, not on our servers. If you like to check things yourself, you can see it right in your browser’s developer tools (under Application → IndexedDB) — there’s nothing on our end to find.

When you finish, your manual downloads to your computer. Signing in (when you choose to) only carries your email — never your answers.

/ 06   Trust

Built for auditors to read.

Standard45 CFR 164 Subpart C — the HIPAA Security Rule
StructureLaid out section by section, the way an auditor reads
PrivacyYour answers save in your browser, not our servers — you can check it yourself
GroundingPolicy templates built on the federal government’s official HIPAA guidance (NIST SP 800-66 Rev. 2)
/ 07   FAQ

Questions practices actually ask.

No. We help you document your safeguards. For legal questions about your specific situation, talk to a healthcare attorney.
We line your answers up with what cyber-insurance companies ask for — eight topics drawn from the five real applications we read, including two forms our own broker sent us. What we can't do is approve your application for them — that's the insurance company's call. What we do is make sure their questions don't catch you off guard, and that your answers are written down and dated the way they expect.
No. It's the paperwork insurance companies ask for, organized the way they ask for it — not a promise of approval or a particular price. A complete, honestly-answered summary helps your renewal go smoothly, but the decision still belongs to your insurance company and your broker.
Cyber-insurance questions are strikingly similar from one company to the next — a second login step, security software on your devices, backups, scrambled (encrypted) records, keeping guest Wi-Fi separate from work devices, what you do if something goes wrong, a list of your devices, and a dated to-do list for anything you still need to fix. If your insurance company uses a different form, those same eight topics still answer the substance of what it's asking.
Business Associate Agreement. It's a contract where a vendor that handles your patient data takes on some of the HIPAA responsibility. The catch: a BAA only covers the services it covers. Personal Gmail, your laptop, and your phone aren't covered by your records-system vendor's BAA — those are still on you. That's most of what we help you document.
You keep it forever — it's already on your computer. If you want it filled in for you next year, that's the paid tier. If you'd rather redo it from scratch, the free version is always here.
Your answers save in your browser's own storage, not on our servers. If you like to check things yourself, you can see it right in your browser's developer tools (under Application → IndexedDB). When you finish, the manual downloads to your computer.
Two groups. Small practices that handle patient health information — solo therapists, doctors, dentists, small clinics. And the companies that handle that information for them — medical billing companies, CPA firms with healthcare clients, IT providers. HIPAA calls them business associates and holds them to the same security rules. If you’re a tech startup that needs SOC 2 (a different security standard), you want Vanta or Drata. If you’re a small practice — or a business your clients trust with patient data — and you need a real HIPAA manual without spending $10K on a consultant, you want us.
Ready when you are

Start the first chapter. Stop when you want.

You don’t have to know any of this going in — that’s the point. Your work saves as you go, right in your browser. No card to enter, nothing to install — you sign in only when you’re ready to download your manual.

Can you help us make this better?

How easy is HIPAAPath to use so far?
HardEasy

Please don’t include patient information — this goes to us by email.