Key takeaways
A HIPAA compliance policy documents how your practice protects protected health information (PHI) and meets federal requirements.
Covered entities and business associates must address three core rules. Those are the Privacy Rule, the Security Rule, and the Breach Notification Rule.
Required policies include access controls, workforce training records, risk assessments, business associate agreements, and annual policy reviews.
The download is a two-page starter outline. It supplies ten section headings and blank space, so your practice still drafts every word.
Practice management software like Pabau embeds technical safeguards into daily operations through audit logs, role-based access, and encrypted records.
Download your free HIPAA compliance policy outline
A two-page starter outline with ten headed sections: purpose, scope, definitions, privacy practices, security measures, breach notification, training, enforcement, policy review, and contacts. Each section is blank, so your practice drafts the wording that matches how it runs.
Download templateHealthcare practices handle sensitive patient information every day, from medical histories to insurance details to treatment plans. HIPAA is the federal law that governs how you safeguard that data. Knowing HIPAA exists and complying with it are two different jobs.
The outline above hands you ten section headings. Three sections a complete policy needs are missing from it, and every word under each heading is still yours to write. This guide walks the three HIPAA rules your policy must cover. Then it shows what the download does and does not give you.
What is a HIPAA compliance policy?
A HIPAA compliance policy is a written document covering the rules, procedures, and safeguards your practice applies to protected health information (PHI). It is a framework covering how staff handle data, who can access it, what happens after a breach, and how you answer regulators.
Think of it as your practice’s playbook for data protection. Instead of each staff member deciding how to handle patient records, a compliance policy creates consistency. Staff know where sensitive data lives, who can open it, how it gets transmitted, and what a violation costs.
The Office for Civil Rights (OCR) enforces HIPAA at the federal level. It expects every covered entity and business associate to keep documented compliance procedures on file. Policies must be reviewed annually and updated whenever your operations change.
Who must have a written policy?
Every covered entity and every business associate needs one. HIPAA sorts the organizations it binds into those two categories.
- Covered entities include healthcare providers (doctors, dentists, therapists, group practices), health plans (insurance companies, employer plans), and healthcare clearinghouses. If your practice handles PHI directly, you are a covered entity.
- Business associates are vendors and contractors that process PHI on your behalf. That includes billing companies, transcription services, IT contractors, cloud storage providers, and practice management platforms. Managing those partners through business associate agreements (BAAs) is part of HIPAA for medical offices.
- Subcontractors of business associates must comply too. Under the HIPAA Omnibus Rule (2013), the chain of accountability runs all the way down your vendor chain.
A solo practice, a multi-location group, and a healthcare technology vendor all sit under the same expectation. If you handle PHI electronically, you need a documented policy on file.
The three HIPAA rules your policy must address
Every HIPAA compliance policy covers three regulatory pillars: the Privacy Rule, the Security Rule, and the Breach Notification Rule. None of the three is optional. Together they form the foundation of federal compliance.
HIPAA Privacy Rule
The Privacy Rule (45 CFR Part 164 Subpart E) governs how healthcare organizations use and disclose patient health information. Your policy must define:
- Patient rights: the right to access, amend, and request restrictions on their own records.
- Uses permitted without consent: treatment, payment, operations, and certain public health activities.
- Minimum necessary standard: staff access only the PHI their job role needs.
- Notice of Privacy Practices: the document every patient receives explaining how their data is used.
HIPAA Security Rule
The Security Rule (45 CFR Part 164 Subpart C) requires three categories of safeguards for electronic PHI (ePHI): administrative, physical, and technical. A HIPAA compliance policy must detail how your organization implements each one.
- Administrative safeguards: access controls, workforce security, information security policies, workforce training, and incident response procedures.
- Physical safeguards: facility access restrictions, workstation security, and device disposal protocols.
- Technical safeguards: encryption, audit logs, access controls, integrity verification, and transmission security for data in transit.
Not every safeguard is mandatory. The rule separates required specifications, which you must implement, from addressable ones, which you assess and implement where reasonable. Encryption and audit logging sit at the center of EHR security, so document how your system handles both.
HIPAA Breach Notification Rule
The Breach Notification Rule applies when unsecured PHI is accessed, acquired, used, or disclosed without authorization. Your policy must set the notification timeline, which runs without unreasonable delay and no later than 60 days. It must also name who gets told. That means affected patients and the Department of Health and Human Services (HHS). Media notice is required when more than 500 residents of one state or jurisdiction are affected. Every decision you reach gets documented.
Required policies under the HIPAA Security Rule
The Security Rule mandates specific written policies. These are regulatory requirements rather than suggestions, and your practice must document and enforce each one.
How to conduct a HIPAA security risk analysis
Before you can write effective security policies, you need to know which risks your organization carries. The Security Rule requires a formal security risk analysis (SRA). That is a documented review of where PHI lives, who can access it, what could go wrong, and how you prevent it.
An effective HIPAA security risk analysis follows five steps:
- Inventory your ePHI: List every system, device, and location where electronic patient data lives (EHR software, practice management platform, cloud backups, staff laptops, mobile devices).
- Identify threats: What could go wrong? Ransomware attacks, staff leaving devices unlocked, email sent to the wrong recipient, stolen hardware, and insider misuse all belong on the list.
- Assess vulnerabilities: Which systems lack encryption? Who holds access they no longer need? Are passwords weak? Is the practice WiFi unencrypted?
- Estimate impact: How bad would each threat be? A laptop stolen from a reception desk, with 1,000 or more patient records on it, outranks a single misfiled chart.
- Document and prioritize: Rank risks by likelihood and impact, then write your remediation plan. Which vulnerabilities will you fix, and by when?
The result is a written risk assessment that anchors your policy. It justifies every security control you put in place and shows the OCR that you took security seriously.
HIPAA workforce training requirements
Your policy is only as strong as your team’s understanding of it. The Security Rule requires that every staff member receive HIPAA training, that the training be documented, and that refreshers happen annually.
Your policy must specify:
- Who must complete training: all staff, including part-time and temporary workers and contractors.
- Training topics: password management, spotting phishing emails, correct handling of PHI, incident reporting, and disciplinary consequences.
- Frequency: initial training before first access to PHI, then an annual refresher.
- Documentation: how you track who completed training, when, and what it covered. Our guide to HIPAA training for employees sets out the topics to run and the records to keep.
- Sanctions: what follows if staff skip training or breach policy after completing it.
Business associate agreements and vendor oversight
If a vendor processes PHI on your behalf, you need a signed Business Associate Agreement (BAA) with them. That covers your billing company, your EHR provider, your cloud storage vendor, and even your document shredding company. The BAA is your legal protection and their compliance commitment.
Your policy must document:
- The inventory of every business associate your practice engages.
- Required BAA terms: what PHI they can access, how they safeguard it, and how they notify you of breaches. Spell out that they cannot use PHI outside treatment, payment, and operations.
- Subcontractor rules: your vendors need BAAs with their own vendors, because accountability extends downstream.
- Periodic review: you must verify that BAAs stay current and that vendors remain compliant.
How to write a HIPAA compliance policy: step-by-step
The work breaks into eight steps. The outline above hands you the section structure, and the wording under each heading comes from how your own practice runs.
- Conduct your security risk analysis: You cannot write effective policies without knowing your risks. Complete the SRA first.
- Define organizational scope: Which locations, systems, and staff are covered? A multi-location practice needs policies that apply consistently across sites.
- Draft policies by rule: Group them into Privacy Rule sections (patient rights, minimum necessary, data use) and Security Rule sections (administrative, physical, technical safeguards). Breach notification procedures form the third group.
- Assign roles and responsibilities: Who owns each policy? Who enforces it? Who responds to breaches? Name specific roles, such as privacy officer, IT manager, and practice director.
- Include timelines: When do breach notifications go out (within 60 days)? How often are policies reviewed (annually)? When do new staff get trained (before their first shift)?
- Document implementation: Don’t just list a policy. Describe how you implement it. Instead of “access controls are in place”, write: “Staff receive usernames and passwords in their first week. Passwords reset every 90 days. Access is disabled within 24 hours of termination.”
- Arrange for legal review: Have an attorney or compliance consultant read your draft. HIPAA compliance is non-negotiable, so professional review earns its cost.
- Train and communicate: Distribute the final policy to all staff and train them on it. Record who completed the training, and make it easy for staff to ask questions.
Use digital forms to track staff acknowledgment of the policy. Have each employee sign a form confirming they have read and understood it. That signed record becomes part of your documentation trail.
What to include, section by section
A complete HIPAA compliance policy covers the sections below. Treat this as your drafting checklist, and keep the supporting evidence for each section on file.
- Executive summary: A high-level overview of your commitment to HIPAA compliance and the scope of the policy.
- Privacy Rule policies: Patient rights, minimum necessary, uses and disclosures, Notice of Privacy Practices, and patient access requests.
- Security Rule administrative safeguards: Access management, workforce security, security incident procedures, workforce training, and risk assessment results.
- Security Rule physical safeguards: Facility access controls, workstation policies, and device disposal.
- Security Rule technical safeguards: Encryption standards, audit logging, password policies, and data backup and recovery.
- Breach notification procedures: How incidents are spotted, and how you run the four-factor risk assessment that decides whether notification is required. Name who you notify, and by when.
- Business associate management: Inventory of vendors, BAA requirements, and oversight procedures.
- Workforce sanctions policy: Disciplinary procedures for policy violations, with documented consequences.
- Document retention: How long policies and compliance records are kept, and where they are stored.
- Annual review and update: The schedule and sign-off process for each yearly review.
What the downloadable outline covers
The file above is a starter outline, not a finished policy. It runs to two pages and holds ten headed sections, each with an empty box underneath. No policy wording is pre-drafted, so downloading it saves you the structure work and none of the writing.
Three sections a complete policy needs are absent from the outline: an executive summary, business associate management, and document retention. Add those headings before you circulate the document. The last page carries a signature line, so staff can acknowledge the policy once you have written it.

Keeping your policy current
HIPAA compliance needs maintenance. Your policy must be reviewed at least annually. Update it whenever your practice changes, whether that means new software, new vendors, staff turnover, expanded services, or a physical relocation.
Your policy should include:
- Review schedule: Set a date each year for formal policy review, such as January or the end of your fiscal year. Record who reviewed it and what changed.
- Triggers for updates: New systems, staff roles with different PHI access, new business associates, changes to HIPAA regulations, and incidents that expose a weakness.
- Version control: Track policy versions such as v1.0, v1.1, and v2.0. Date every version and keep a change log.
- Staff notification: When policies change, retrain staff on the changes and record completion. Compliance depends on consistent understanding across the team.
- Compliance documentation: Keep dated records of every review, training session, and risk assessment. HIPAA compliance software can hold that evidence in one place.
How Pabau supports ongoing HIPAA compliance
Writing the policy is the first job. Showing that your team follows it every day is the harder one. Practice management software like Pabau embeds HIPAA safeguards into the workflow your staff already use, so the evidence accumulates as they work.
Compliance features that carry the documentation load include:
- Audit logs: Every access to a patient record is logged with user ID, timestamp, and action. That gives you the evidence the OCR expects to see.
- Role-based access controls: Staff see only the patient data their role requires. A receptionist sees appointment history, while a clinician sees the full medical notes.
- Encryption and BAAs: Pabau acts as a business associate and signs a BAA with your practice. Patient records are encrypted in storage and in transit.
- Training reminders: Schedule annual HIPAA training as recurring tasks and record who has completed it, so your training evidence stays current.
Compliance management software turns HIPAA from a checkbox into an operational habit. An audit request becomes a report you run, not a search through folders.
Turn your HIPAA policy into daily practice
Pabau logs every record access, limits patient data by staff role, and keeps your compliance evidence in one place. Your team follows the policy you wrote without adding paperwork to the day.
Conclusion
A HIPAA compliance policy only protects you if it describes how your practice works. The outline above saves you the structure work, and that is the smaller half of the job. The judgment calls about access, training, vendors, and breach response are yours, and the OCR reads them as yours.
So draft it once, have counsel review it, then keep it alive. Annual review, version control, and training records are what turn a written policy into a defensible one.
The practices that stay compliant are usually the ones whose systems record the work automatically. Book a demo to see how Pabau keeps your HIPAA evidence current while your team gets on with patient care.
Continue your research
Drafting the patient-facing half of your paperwork? HIPAA privacy policy template covers the disclosure rules your compliance policy points to.
Need the notice you hand to patients? Notice of Privacy Practices template gives you the patient-facing document the Privacy Rule requires.
Moving your records off paper first? How to run a paperless practice that stays HIPAA compliant walks through the digital safeguards your policy has to describe.
Wondering what happens after a slip? What to do if you violate HIPAA sets out the reporting steps your breach section should mirror.
Writing the document retention section? How long to keep medical records gives you the retention periods to name in the policy.
Frequently asked questions
Is the downloadable outline ready to use as it is?
No. It gives you ten headed sections with blank space under each one, so you write the policy content yourself. You also need to add an executive summary, business associate management, and document retention. Split the security measures box into administrative, physical, and technical safeguards.
What is the penalty for not having a HIPAA compliance policy?
Civil money penalties are tiered by culpability and adjusted for inflation each year, so check the current figures with HHS. Minimums start in the low hundreds of dollars per violation, and the annual cap for one violation type runs into the millions. A breach without documented policies also costs you patient trust.
Do small solo practices need written HIPAA policies?
Yes. HIPAA applies to every covered entity, whatever its size. A solo therapist with one staff member still needs policies documenting how PHI is protected, how access is controlled, and how breaches are handled.
How often should the policy be updated?
At minimum, annually. Update it sooner whenever your practice adds systems, vendors, staff roles, or services. After a security incident or an audit finding, update it without delay and fix the weakness it exposed.
Do business associates need their own written policies?
Yes. Business associates such as billing companies, software vendors, and IT contractors must hold their own written policies for safeguarding PHI. Their BAAs with healthcare organizations require it.
Who enforces HIPAA?
The Office for Civil Rights (OCR) within the Department of Health and Human Services (HHS) investigates HIPAA complaints and enforces the law. OCR can conduct audits, impose fines, and require corrective action plans.
How does a compliance policy differ from a privacy notice?
A HIPAA compliance policy is your internal operating manual for protecting PHI. A Notice of Privacy Practices is what you hand patients, explaining their rights and how you use their information. You need both.