Your HIPAA Security Path
Nine chapters in three steps — work through them in order or skip to whatever’s most urgent; your answers save automatically in this browser and never leave your device until you download your Practice Security Manual.
Pre-flight
Your Practice
Practice name, sanction official, cure period, and compliance archive location — the four facts that personalize every policy template in your manual.
Set up →
Step 1 · 0 of 3 done
Set the foundation
The big-three gaps for solo or small practices — mostly tech setup.
- Not started
Chapter 1
3 questionsBAAs & Email
Confirm your email provider offers a HIPAA Business Associate Agreement — the biggest gap most solo or small practices miss.
Start→
- Not started
Chapter 2
2 questionsYour Devices
Inventory the laptops, phones, and tablets that touch patient data and confirm each one is encrypted.
Start→
- Not started
Chapter 3
2 questionsYour Passwords
List the accounts that reach patient information and turn on a password manager and multi-factor authentication.
Start→
Step 2 · 0 of 3 done
Run your practice
How patient data flows through your week.
- Not started
Chapter 4
2 questionsYour Workspace
Walk through the physical spaces where you see patients or work with records, and secure the basics.
Start→
- Not started
Chapter 5
6 questionsYour Training
Build a short, honest training record — security reminders, malware, logins, and password management.
Start→
- Not started
Chapter 6
3 questionsIf Something Goes Wrong
Pre-decide how you would handle a lost device, ransomware, a mis-sent email, or a breach — before it happens.
Start→
Step 3 · 0 of 3 done
Document your program
What an auditor (or future-you) reads to see what you've built.
- Not started
Chapter 7
4 questionsYour Paperwork
Set a review cadence and confirm your written policies, retention, and availability are in shape.
Start→
- Not started
Chapter 8
7 questionsYour Security Foundation
Risk analysis, risk management, sanctions, activity review, the named Security Official, and periodic evaluation.
Start→
- Not started
Chapter 9
7 questionsYour Systems
Technical safeguards — unique accounts, emergency access, auto-logoff, encryption, audit logs, integrity, transmission.
Start→
Your progress