Skip to main content

The HIPAA Essentials Resource Library

The Resource Library uses a single account model. Register once with your name and email address and you can download any resource in the library, with no separate form required for each file. When new resources are added, your account gives you immediate access without signing up again.

Every resource is developed by certified healthcare compliance professionals and grounded in current OCR enforcement priorities and primary regulatory sources.

Your free account includes:

  • Immediate access to every resource currently in the library
  • Automatic access to new resources as they are published, with no additional sign-up required
  • One registration covers all downloads, now and going forward
  • Resources written to current regulatory standards, with citations to primary sources

Create Your Free Account

OCR Enforcement Reference Guide

Format: Word document (.docx)

OCR is currently running three simultaneous enforcement initiatives targeting risk analysis failures under 45 CFR 164.308(a)(1)(ii)(A), right of access violations under 45 CFR 164.524, and ransomware and cybersecurity safeguard deficiencies. This guide compiles all 27 publicly announced OCR resolution agreements and civil money penalties from 2024 through June 2026, organized by violation category with the penalty factors OCR weighs under 45 CFR 160.408 and the corrective action plan patterns drawn from confirmed cases.

What Is Included

  • 27 verified OCR cases from 2024 through June 2026, sourced from official HHS.gov press releases and the OCR Resolution Agreements index
  • Cases organized by violation category for easy benchmarking against your own program
  • Penalty factors table under 45 CFR 160.408
  • Corrective action plan patterns drawn from published resolution agreements
  • Self-assessment checklists tied directly to documented OCR findings

Who This Is For

Privacy Officers and Security Officers who need to understand current OCR enforcement priorities before conducting internal gap assessments or briefing leadership. Compliance consultants building or auditing programs for covered entities and business associates who want enforcement-grounded documentation guidance rather than general regulatory summaries. Practice administrators and compliance coordinators at physician practices, dental offices, behavioral health providers, and other small to mid-size organizations who need a practical picture of what OCR investigates in their peer group. Any organization responding to an OCR inquiry or building a corrective action plan who needs to know what OCR has required of similarly situated organizations.

HIPAA Compliance Starter Kit

Format: ZIP archive (.zip)

A foundational set of HIPAA compliance resources for covered entities and business associates beginning or refreshing their compliance program. These six tools give you a starting point for identifying gaps, documenting training, and standing up basic breach response procedures without building everything from a blank page.

What Is Included

  • HIPAA Readiness Checklist, identify compliance gaps
  • Breach Response Quick Guide, step-by-step procedures for security incidents
  • Risk Assessment Worksheet, lite version of our risk assessment tool
  • Workforce Training Tips, best practices for effective HIPAA training
  • Training Attendance Log, record attendee names, roles, and completion status
  • Training Content Acknowledgement, document training topics and capture workforce attestation

Privacy Officer 101

Format: Web page

A practical guide to the Privacy Officer role under 45 CFR 164.530(a), covering core responsibilities, program requirements, and documentation obligations. Walks new Privacy Officers through what the role actually requires in practice, from the first 30 days on the job through breach response and sustaining a functioning privacy program long term.

What Is Included

  • Core duties of the Privacy Officer role under 45 CFR 164.530(a)
  • A first-30-days roadmap for stepping into the role
  • Privacy Rule fundamentals explained in practical, day-to-day terms
  • What a functioning privacy program looks like in practice
  • Breach response basics and how to sustain the program long term

Who This Is For

Newly appointed Privacy Officers who need a practical starting point rather than a regulatory summary. Practice managers, office administrators, and compliance coordinators who have been handed the Privacy Officer responsibility on top of their existing role. Solo compliance practitioners at small to mid-size covered entities who need to build a program from the ground up without prior privacy experience.

Privacy Officer AI Guide

Format: Web page

A guide to artificial intelligence governance obligations for Privacy Officers under HIPAA, covering AI use in clinical and administrative workflows and the documentation requirements that come with it. Built for the Privacy Officer managing more than one person can realistically handle, with practical guardrails for getting AI-assisted work done without creating new compliance exposure.

What Is Included

  • What AI can and cannot do with PHI under current HIPAA rules
  • Safe use guidelines for clinical and administrative AI workflows
  • A ready-to-use prompt library for compliance tasks
  • Recommended AI tools and what to check before adopting them

Who This Is For

Privacy Officers and compliance coordinators who are already using or considering AI tools to manage workload and want to do it without creating new HIPAA exposure. Solo compliance practitioners and small compliance teams at covered entities and business associates who need practical guardrails rather than a theoretical AI policy.

Privacy Officer 201

Format: Web page

A guide to the Privacy Officer role beyond the single covered entity, covering organized health care arrangements, affiliated covered entities, hybrid entities, behavioral health and substance use disorder records, AI vendor obligations, complex disclosure pathways, and multi-state governance. Picks up where Privacy Officer 101 left off and works through the situations that come up once your organization stops being simple.

What Is Included

  • OHCAs, affiliated covered entities, and hybrid entities: when each applies and how to document the designation
  • Psychotherapy notes and 42 CFR Part 2 in full, including the 2024 final rule changes
  • When an AI vendor is a business associate, subcontractor chain obligations, and de-identification claims
  • Research disclosures, the court order vs. subpoena distinction, and the six law enforcement pathways
  • Marketing, fundraising, and the sale of PHI: where the lines actually sit
  • Multi-state preemption analysis, telehealth, and the Information Blocking Rule

Who This Is For

Privacy Officers who have the fundamentals handled and are managing something more complex: a health system with multiple affiliated entities, a program with behavioral health or SUD treatment records, a vendor landscape that includes AI tools, or a multi-state footprint where more than one body of law applies at once. Compliance officers and legal counsel who need a structured reference for the provisions 101-level training typically names but does not fully develop.

Annual Vendor Review Template

Format: Word document (.docx)

A structured template for conducting annual privacy and security reviews of business associates and vendors with access to protected health information. Covers the BAA provisions you need on file under 45 CFR 164.504(e)(2) and the security control areas OCR expects you to be monitoring on an ongoing basis, not just at signing.

What Is Included

  • Vendor Profile
  • BAA tracking and 14-point provision checklist (45 CFR 164.504(e)(2))
  • Security and Privacy Controls assessment with HIPAA Security Rule citations
  • Incident documentation
  • Risk rating
  • Corrective actions
  • Approval signatures
  • Attachments checklist

HIPAA Workforce Training Log

Format: Excel spreadsheet (.xlsx)

A structured Excel log for documenting HIPAA workforce training activity, tracking completion dates, training topics, and staff attestations for audit documentation purposes under 45 CFR 164.530(b) and 164.308(a)(5).

What Is Included

  • Training log with dropdown validation for training type, delivery method, status, assessment result, and attestation
  • Instructions sheet with the regulatory basis for each field
  • Quick-reference sheet covering training types and applicable CFR citations