The Health Insurance Portability and Accountability Act (HIPAA) establishes national standards for protecting sensitive patient health information (PHI). It requires covered entities and their business associates to implement administrative, physical, and technical safeguards.
Healthcare providers, health plans, healthcare clearinghouses, and their business associates.
12 policies required for HIPAA compliance, organized by category.
Administrative, physical, and technical safeguards.
Breach identification and reporting procedures.
Technical policies for controlling access to ePHI per §164.312(a).
Mechanisms for recording and examining access to ePHI per §164.312(b).
Policies to protect ePHI from improper alteration or destruction per §164.312(c).
Technical safeguards for protecting ePHI during electronic transmission per §164.312(e).
Completed Security Risk Analysis artifact required by 45 CFR §164.308(a)(1)(ii)(A) — the most frequently cited deficiency in OCR HIPAA investigations.
Answer questions about your infrastructure and PoliWriter generates all 12 HIPAA policies customized to your organization. Audit-ready in hours, not months.
Get Started FreeNo credit card required. 3 documents free.
Service Organization Control 2 - Trust Services Criteria covering Security, Availability, Processing Integrity, Confidentiality, and Privacy. Requires an observation period of 3-12 months demonstrating controls operate effectively over time.
22 templatesGeneral Data Protection Regulation - EU data protection and privacy regulation.
10 templatesInternational standard for information security management systems (ISMS).
11 templatesPayment Card Industry Data Security Standard — security controls for organizations that store, process, or transmit payment cardholder data.
12 templatesCalifornia Consumer Privacy Act / California Privacy Rights Act — grants California consumers rights over their personal information collected by businesses.
8 templatesNIST Cybersecurity Framework — voluntary guidance for managing cybersecurity risk across five core functions: Identify, Protect, Detect, Respond, and Recover.
10 templatesSOC 2 Type I — Point-in-time assessment of your security controls design. Ideal for first-time certification before progressing to Type II.
22 templatesISO/IEC 42001 — International standard for Artificial Intelligence Management Systems (AIMS), covering responsible AI development, deployment, and governance.
8 templatesNIS 2 Directive (EU 2022/2555) — EU-wide cybersecurity legislation requiring essential and important entities to implement comprehensive risk management and incident reporting.
10 templatesNIST SP 800-53 — Comprehensive catalog of security and privacy controls for federal information systems, widely adopted by private sector organizations.
10 templates