Public beta — features are evolving and AI-generated outputs may contain errors. Not legal, regulatory or compliance advice. Review before relying on any output. Share feedback
All starter packs

Healthcare starter pack

Three completed sample forms commonly required of US healthcare organisations that handle protected health information (PHI).

Example company: Northwind Health Clinic (US, 120 employees)

Educational examples only. Fictional data; not legal, regulatory or compliance advice.

HIPAA Security Rule
45 CFR § 164.308(a)(1)(ii)(A)

HIPAA Security Risk Assessment

Documents the analysis of risks and vulnerabilities to the confidentiality, integrity and availability of electronic PHI.

Regulator
HHS Office for Civil Rights (OCR) · United States
Frequency
Annual, plus after material changes

Organisation profile

Covered entity name
Northwind Health Clinic
Assessment period
January 1 – December 31, 2025
Privacy / Security Officer
J. Rivera, Director of Compliance
Number of workforce members with ePHI access
84
Systems in scope
EHR (Epic), patient portal, billing platform, encrypted email gateway, backup storage

Risk analysis summary

Identified threats
Phishing of clinician credentials, lost / stolen laptops, ransomware via third-party billing vendor, misconfigured cloud backup bucket.
↳ Cited: Incident log 2024-Q3, IT vulnerability scan 2025-02
Existing safeguards
MFA on EHR and email, full-disk encryption on all workstations, quarterly phishing simulations, BAAs with all vendors, immutable cloud backups.
↳ Cited: Security Policy v3.2 §4-7
Residual risk rating
Medium — phishing and vendor risk above target threshold; remediation plan tracked in §Remediation.

Remediation plan

Deploy FIDO2 hardware keys for clinicians
Owner: IT; Target: Q2 2026
Quarterly vendor security attestations
Owner: Compliance; Target: Q1 2026
Tabletop ransomware exercise
Owner: Security; Target: Q3 2026
Reviewer notes

Illustrative example only. Replace narrative entries with findings from your own risk analysis and ensure documentation is retained for at least six years per 45 CFR § 164.316(b)(2).

HIPAA Privacy Rule
45 CFR § 164.504(e)

Business Associate Agreement (BAA)

Contract that obligates a vendor handling PHI on the covered entity's behalf to safeguard that information.

Regulator
HHS Office for Civil Rights (OCR) · United States
Frequency
Per vendor, on engagement

Parties

Covered entity
Northwind Health Clinic
Business associate
BrightBill Revenue Cycle Services, Inc.
Effective date
March 1, 2026

Permitted uses and disclosures

Scope
Business associate may use PHI only to perform medical billing, claims submission, denial management and patient statement services described in the underlying service agreement.
Minimum necessary
Access is limited to the minimum data set required for each billing task; bulk PHI exports require written approval from the Privacy Officer.

Safeguards & breach reporting

Required safeguards
Encryption in transit and at rest, role-based access controls, annual workforce HIPAA training, documented incident response plan.
Breach notification window
Without unreasonable delay and no later than 30 calendar days after discovery.
↳ Cited: 45 CFR § 164.410
Subcontractors
Business associate must obtain written agreements equivalent to this BAA from any subcontractor that creates, receives, maintains or transmits PHI.
Reviewer notes

Sample contract language for illustration. Use vendor-specific names, scope and termination terms, and have qualified counsel review before signing.

HIPAA Breach Notification Rule
HHS Breach Portal

OCR Breach Notification (>500 individuals)

Required notice to HHS when unsecured PHI of 500 or more individuals is compromised.

Regulator
HHS Office for Civil Rights (OCR) · United States
Frequency
Within 60 days of breach discovery

Incident overview

Date of discovery
April 14, 2026
Date of breach
April 9, 2026
Individuals affected
1,842
Type of breach
Hacking / IT incident — phishing leading to unauthorised access to clinician mailbox
Location of breached information
Cloud email mailbox

PHI involved

Data elements
Names, dates of birth, appointment dates, diagnosis codes (limited subset)
Financial / SSN involved?
No

Response actions

Containment
Mailbox credentials rotated within 2 hours; forced sign-out and revocation of OAuth tokens; mailbox quarantined for forensic review.
Individual notification
Letters mailed April 30, 2026; toll-free hotline opened; 12 months of credit monitoring offered as a precaution.
Preventive measures
Mandatory FIDO2 keys for clinicians, advanced phishing detection rules, repeat training for affected workforce members.
Reviewer notes

Illustrative submission only. State law may impose shorter notice windows; check applicable state attorney general requirements in parallel.

Want forms tailored to your business?

The free AI assessment maps these requirements to your industry, region and data profile.