About Us Contact Blog
Governance DocsGovernance Docs
Which Toolkit?SoA GeneratorFree TemplatesAboutBlogContactMy AccountCart
FOX v.2.4.9
Browse Toolkits
Governance Docs
  • Browse All Toolkits
  • Information Security & Cybersecurity
  • Data Privacy & Protection
  • Governance, Risk & Compliance
  • Quality Management
  • Health, Safety & Environment
  • AI Governance

My Account

CART

No products in the cart.

Category: HIPAA

HIPAA is the US law governing the privacy and security of protected health information. It applies to covered entities — health plans, clearinghouses and most healthcare providers — and, since the HITECH Act, directly to their business associates.
Two rules do most of the work and are routinely confused. The Privacy Rule governs how PHI in any form may be used and disclosed, and establishes patient rights. The Security Rule applies only to electronic PHI and requires administrative, physical and technical safeguards, anchored on a documented security risk analysis.
The risk analysis is the requirement most often found missing in enforcement actions. It is not a questionnaire; it is a documented assessment of where ePHI lives, what threatens it, how likely and how damaging a compromise would be, and what you are doing about it. Its absence is treated as a compliance failure in its own right.
Business Associate Agreements are the other recurring gap. Every vendor that creates, receives, maintains or transmits PHI on your behalf needs one, with the provisions HHS requires it to contain.
The guides below cover the compliance checklist rule by rule, how to conduct a risk assessment, what a BAA must contain, the policy set you need, and how the Security and Privacy Rules differ.

HIPAA BAA guide - what a business associate agreement is and its required provisions

HIPAA Business Associate Agreement (BAA): A Guide

Governance Docs17th July 2026

A HIPAA BAA is required whenever a vendor handles protected health information for you. Here is what a…
Read More
HIPAA compliance checklist covering Privacy Rule, Security Rule, breach notification and BAAs

HIPAA Compliance Checklist for Vendors & Small Practices

Governance Docs17th July 2026

A practical HIPAA compliance checklist, organised by the Privacy and Security Rules, breach notification, and business associates -…
Read More
HIPAA risk assessment steps from mapping ePHI to risk management and remediation

How to Conduct a HIPAA Risk Assessment

Governance Docs17th July 2026

The HIPAA risk assessment is the foundation of the Security Rule. Here is what it is, why it…
Read More
HIPAA Security Rule vs Privacy Rule - protecting electronic PHI versus governing use and disclosure

HIPAA Security Rule vs Privacy Rule Explained

Governance Docs17th July 2026

HIPAA Security Rule vs Privacy Rule: one protects electronic health data, the other governs its use and disclosure.…
Read More
HIPAA policies checklist including privacy, security, risk assessment and breach notification

HIPAA Required Policies & Documentation Checklist

Governance Docs17th July 2026

HIPAA requires documented policies and procedures. Here are the essential HIPAA policies, the records you must keep, and…
Read More
HIPAA compliance explained - the Privacy and Security Rules, PHI, and covered entities

HIPAA Explained: A Complete Compliance Guide

Governance Docs20th April 2026

HIPAA compliance is a legal requirement for anyone handling US health data. A complete guide to the rules,…
Read More

Recent Posts

ITIL 4 to ITIL 5 - what needs rewriting
ITIL 4 to ITIL 5: What Needs Rewriting

August 31, 2026

Experience level agreement - measuring experience alongside performance
Experience Level Agreements: A Complete Guide

August 31, 2026

ITIL value stream mapping - the five steps and four time metrics
ITIL Value Stream Mapping: A Complete Guide

August 31, 2026

AI governance in ITSM - scaling oversight to capability
AI Governance in ITSM: A Practical 2026 Guide

August 31, 2026

ITIL AI Capability Model - the six capabilities
ITIL AI Capability Model: The 6 Capabilities

August 31, 2026

Categories

  • Articles
  • DORA
  • GDPR
  • HIPAA
  • ISO 27001
  • ISO 42001 & AI governance
  • ISO 9001
  • Management systems
  • NIS2
  • Security frameworks
  • SOC 2
Governance DocsGovernance Docs

Reliable ISO & compliance documentation toolkits that help your business meet regulatory standards with ease.

Governance Docs LLC
1209 Mountain Road Pl NE, Suite R
Albuquerque, NM 87110, USA
info@governancedocs.com
+1 812 227 5662

Toolkits

  • ISO 27001:2022
  • GDPR
  • SOC 2
  • PCI-DSS v4.0
  • HIPAA
  • ISO 42001
  • All toolkits →

Company

  • About Us
  • Blog
  • Contact
  • FAQ
  • Which toolkit do I need?
  • Free templates
  • SoA generator
  • RSS feeds

Policies

  • Privacy Policy
  • Terms & Conditions
  • Refund & Return Policy
  • Delivery Policy
Browse by topicISO 27001ISO 42001 & AI governanceGDPRSOC 2HIPAANIS2DORAISO 9001Management systemsSecurity frameworks
© 2026 Governance Docs LLC. All rights reserved.
Secure checkoutstripeVISA