Pre-flight · personalize your manual

Your Practice

A few facts about your practice that personalize the policy templates throughout HIPAAPath. Every policy template references your practice by name, names a specific person to enforce it, gives a concrete remediation window, and points at the place you archive compliance records. Filling these in once means every template you see from here on out reads like it was written for your practice — not a generic placeholder.

Your answers save automatically and stay on this device. Empty fields just leave the literal placeholder visible so you (and a future auditor) can see what still needs to be filled in — except the schedules and timeframes below, which come pre-filled with standard values you can edit.

Your practice’s legal entity or registered DBA name. Used wherever a policy template says [Practice Name].

Whoever investigates security incidents and enforces consequences. For a solo practice that’s typically you; for a small office it’s usually the owner or practice manager.

The window a workforce member has to complete mandatory retraining after a minor infraction. Pick a number that fits your operating rhythm — 5 business days and 14 calendar days are both common.

Where you securely keep personnel files and compliance records for six years. Describe it in the same words you’d use in the policy itself.

Security Official designation · optional

HIPAA’s §164.308(a)(2) standard only asks that you name a security official — typically you in a solo practice, or the owner or practice manager in a small office. The alternate and contact line are operational-resilience extras, not a legal requirement. Fill in whatever’s useful; anything you leave blank simply keeps the bracketed placeholder in your Security Official policy template. The name you enter here also stands in for every role below that you leave blank.

The person responsible for your HIPAA security program. In a solo practice that’s usually you; in a small office, the owner or practice manager. Fills [Security Official Name] in the Security Official policy template.

Who steps in if the primary official is unavailable or leaves the practice. Fills [Alternate Official].

One line — email and phone — so staff know how to reach the security official. Fills [Contact Information].

Official roles · optional — your Security Official covers these

In a solo or small practice, one person wearing every one of these hats is fully HIPAA-compliant — the rule only asks that each job gets done, not that a different person does each one. Any role you leave blank automatically uses your Security Official from above. Name someone else — a staff member or an outside company — only where that’s genuinely who handles it.

Who creates, changes, and removes logins across the tools your practice uses. Often the owner, an office manager, or an outside IT company. Fills [Account Administrator].

Who approves each person’s access to patient information when they join, change roles, or leave. Fills [Authorizing Official].

Who runs the periodic security check-up and sees the fixes from your risk analysis through. Fills [Evaluating Official].

Who looks through system activity records — sign-in reports and access logs — and signs off on each review. Fills [Reviewing Official].

Who takes charge when something goes wrong — a lost phone, a malware warning, a suspected breach. Fills [Incident Response Coordinator].

Who keeps your compliance documents for the required six years and disposes of them securely after. Fills [Records Custodian].

Who runs security training and keeps the completion records. Fills [Training Coordinator].

Who gets told first when an activity review turns up something worrying. Fills [Escalation Contact].

Schedules & timeframes · pre-filled with standard values

Each field starts with the standard value most small practices use — nothing to figure out. Change any of them to match how your practice actually runs; your policy templates pick up whatever’s written here. Clearing a field puts the bracketed placeholder back in the template until you refill it.

How often everyone completes security training. Yearly is the standard for a small practice. Fills [Training Schedule].

How often you look through your record system’s sign-in and access reports. For a solo or small practice, once a year — right alongside the rest of your annual review — is a sensible, defensible rhythm. Step it up to quarterly or monthly if you add staff or your patient volume grows. Fills [Review Schedule].

How often you do the overall security check-up (the periodic evaluation). Once a year is standard. Fills [Evaluation Schedule].

How often you redo your risk analysis, on top of redoing it after any big change. Yearly is standard. Fills [Reassessment Schedule].

How often you test that your backups actually restore. Once a year is standard. Fills [Testing Schedule].

When the fixes your risk analysis calls for are finished by. The 90-day mark is a widely used standard. Fills [Mitigation Deadline].

How fast access is cut off when someone leaves the practice. Same day is the standard to aim for. Fills [Offboarding Window].

How fast a vendor holding patient information must tell you about a breach. Five business days keeps your own 60-day notification clock safe. Fills [Notification Window].

How long you have to tell patients about a breach. Federal law allows 60 days; if your state sets a shorter deadline, put it here. Fills [State Notification Window].

How long a screen sits idle before it locks itself. 15 minutes is a sensible ceiling — shorter is fine too. Fills [Inactivity Timeout].

How paper documents past their six-year retention date are destroyed. Fills [Destruction Method].

The checks you run before someone new gets access to patient information. Fills [Clearance Process].

The big changes that trigger a security check-up right away, without waiting for the scheduled one. Fills [Special Conditions].

What you use for patient records
0 of 4 filled in — the rest will keep showing as bracketed placeholders.

You don’t have to finish in one sitting. Any field you leave empty stays visible as its literal placeholder (e.g. [Practice Name]) in the rendered templates, which is also what an auditor would see — except the schedules and timeframes, which come pre-filled with standard values you can edit. Filling the rest in just makes the templates read in your practice’s own voice.

Can you help us make this better?

How easy is HIPAAPath to use so far?
HardEasy

Please don’t include patient information — this goes to us by email.