About Us Contact Blog
Governance DocsGovernance Docs
All ToolkitsWhich Toolkit?AboutBlogContactMy AccountCart
FOX v.2.4.9
Browse Toolkits
Governance Docs
  • Browse All Toolkits
  • Information Security & Cybersecurity
  • Data Privacy & Protection
  • Governance, Risk & Compliance
  • Quality Management
  • Health, Safety & Environment
  • AI Governance

My Account

CART

No products in the cart.

Category: HIPAA

HIPAA is the US law governing the privacy and security of protected health information. It applies to covered entities — health plans, clearinghouses and most healthcare providers — and, since the HITECH Act, directly to their business associates.
Two rules do most of the work and are routinely confused. The Privacy Rule governs how PHI in any form may be used and disclosed, and establishes patient rights. The Security Rule applies only to electronic PHI and requires administrative, physical and technical safeguards, anchored on a documented security risk analysis.
The risk analysis is the requirement most often found missing in enforcement actions. It is not a questionnaire; it is a documented assessment of where ePHI lives, what threatens it, how likely and how damaging a compromise would be, and what you are doing about it. Its absence is treated as a compliance failure in its own right.
Business Associate Agreements are the other recurring gap. Every vendor that creates, receives, maintains or transmits PHI on your behalf needs one, with the provisions HHS requires it to contain.
The guides below cover the compliance checklist rule by rule, how to conduct a risk assessment, what a BAA must contain, the policy set you need, and how the Security and Privacy Rules differ.

HIPAA BAA guide - what a business associate agreement is and its required provisions

HIPAA Business Associate Agreement (BAA): A Guide

Governance Docs17th July 2026

A HIPAA BAA is required whenever a vendor handles protected health information for you. Here is what a…
Read More
HIPAA compliance checklist covering Privacy Rule, Security Rule, breach notification and BAAs

HIPAA Compliance Checklist for Vendors & Small Practices

Governance Docs17th July 2026

A practical HIPAA compliance checklist, organised by the Privacy and Security Rules, breach notification, and business associates -…
Read More
HIPAA risk assessment steps from mapping ePHI to risk management and remediation

How to Conduct a HIPAA Risk Assessment

Governance Docs17th July 2026

The HIPAA risk assessment is the foundation of the Security Rule. Here is what it is, why it…
Read More
HIPAA Security Rule vs Privacy Rule - protecting electronic PHI versus governing use and disclosure

HIPAA Security Rule vs Privacy Rule Explained

Governance Docs17th July 2026

HIPAA Security Rule vs Privacy Rule: one protects electronic health data, the other governs its use and disclosure.…
Read More
HIPAA policies checklist including privacy, security, risk assessment and breach notification

HIPAA Required Policies & Documentation Checklist

Governance Docs17th July 2026

HIPAA requires documented policies and procedures. Here are the essential HIPAA policies, the records you must keep, and…
Read More
HIPAA compliance explained - the Privacy and Security Rules, PHI, and covered entities

HIPAA Explained: A Complete Compliance Guide

Governance Docs20th April 2026

HIPAA compliance is a legal requirement for anyone handling US health data. A complete guide to the rules,…
Read More

Recent Posts

ISO 27001 internal audit seven-step cycle under clause 9.2, from audit program to corrective action
ISO 27001 Internal Audit: The Complete 2026 Guide to Clause 9.2

August 11, 2026

ISO 27001 Stage 1 vs Stage 2 audit comparison infographic
ISO 27001 Stage 1 vs Stage 2: The Complete 2026 Audit Guide

August 10, 2026

ISO 27001 gap analysis chart for governance documentation and compliance.
ISO 27001 Gap Analysis: The Complete 2026 Step-by-Step Guide

August 9, 2026

ISO 27001 risk assessment process showing the six steps from criteria to treatment decision
ISO 27001 Risk Assessment: The Complete 2026 Method

August 7, 2026

ISO 27001 Statement of Applicability infographic showing all 93 Annex A controls across four themes
ISO 27001 Statement of Applicability: The Complete 2026 Guide

August 6, 2026

Categories

  • Articles
  • DORA
  • GDPR
  • HIPAA
  • ISO 27001
  • ISO 42001 & AI governance
  • ISO 9001
  • Management systems
  • NIS2
  • Security frameworks
  • SOC 2
Governance DocsGovernance Docs

Reliable ISO & compliance documentation toolkits that help your business meet regulatory standards with ease.

Governance Docs LLC
1209 Mountain Road Pl NE, Suite R
Albuquerque, NM 87110, USA
info@governancedocs.com
+1 812 227 5662

Toolkits

  • ISO 27001:2022
  • GDPR
  • SOC 2
  • PCI-DSS v4.0
  • HIPAA
  • ISO 42001
  • All toolkits →

Company

  • About Us
  • Blog
  • Contact
  • FAQ
  • Which toolkit do I need?

Policies

  • Privacy Policy
  • Terms & Conditions
  • Refund & Return Policy
  • Delivery Policy
© 2026 Governance Docs LLC. All rights reserved.
Secure checkoutstripeVISA