The HIPAA Foundation
The HIPAA foundation, free to use, cite and build on.
After eleven years building tools to close the gap between independent-practice HIPAA obligations and independent-practice resources, we made the foundation public. A collection of 18 resources: risk assessments, training, ePHI mapping, breach-cost modeling, implementation roadmaps, threat intelligence, a citable U.S. healthcare breach dataset, machine-readable references, templates, research, and open-source PHI-detection software.
- No paid subscription
- No sales call
- No credit card
- No paywall
CC BY 4.0 on data and reference materials. CC0 on the four operational templates (BAA, NPP, IRP, Risk Analysis). MIT on HIPAA Shield source code.
Same rules, a fraction of the resources
A solo dental practice with 1,200 patient records answers to the same federal HIPAA framework as Mayo Clinic.
Their federal responsibilities do not diminish with headcount. Their budgets do. Dental offices, medical practices, behavioral health clinics, chiropractic offices, physical therapy centers, optometry practices — the independent segment operates under hospital-grade HIPAA obligations without dedicated legal, compliance, or cybersecurity teams. IBM’s 2026 Cost of a Data Breach Report placed the average healthcare breach at $6.64 million — the highest of any industry for the 13th consecutive year.
The consequences do not require a sophisticated attack. In 2016, Raleigh Orthopaedic Clinic paid $750,000 after releasing X-ray films and protected health information for 17,300 patients to a vendor without a Business Associate Agreement. No ransomware. No zero-day. A routine vendor workflow and a missing agreement.
“We did not begin by asking independent providers to trust another compliance platform. We began by building the tools, data, and research they need to make better security decisions. Independent healthcare carries enterprise-level responsibility without enterprise-level infrastructure. We chose to make that foundation public.”
The paid Patient Protect platform is a fundamentally different offer. The public resources are finished products. They do not expire, withhold results, or convert into paid subscriptions. What they do not do is run a compliance program. Our commercial platform handles the continuous work: risk remediation, compliance scoring, workforce governance, vendor oversight, BAA tracking, training enforcement, security monitoring, audit evidence, and incident-response documentation. That work never finishes, which is why it is the product. From $39/month, no long-term contract.
Six capabilities, one foundation
18 resources across the six capabilities that raise the security standard.
Assess risk. Map exposure. Quantify consequences. Train the workforce. Track the threat landscape. Prevent disclosure. Plus the research and methodology behind the work.
Assess risk
Assessments, classification tools, and an AI assistant that reveal your actual compliance standing and starting point.
Risk Assessment
A unified risk and readiness assessment combining compliance readiness, entity classification, practice profile, and ePHI data flow into a single Patient Protect Score. Not a full HIPAA Security Risk Analysis — see the platform's guided SRA for that.
Ask PIPAA
An AI HIPAA compliance assistant that answers your questions about the Security Rule, Privacy Rule, breach response, risk analysis, and more — free, instant, no login required.
HIPAA Readiness Scan
See what your practice website exposes from the outside. Checks tracking technologies, security configuration, email protection, and required privacy notices — in about 30 seconds.
HIPAA Self-Assessment
A seven-question readiness check with action-oriented guidance and clear next steps.
Entity Determination Tool
Determine whether you operate as a covered entity, business associate, hybrid entity, or vendor.
Map exposure
Trace how patient information moves through employees, devices, vendors, and systems — then turn findings into sequenced work.
ePHI Data Flow Mapper
Map how patient data moves across vendors, devices, staff, and systems before something leaks.
HIPAA Compliance Roadmap
A step-by-step operational checklist designed to replace checkbox guidance with real work.
Secure Infrastructure Checklist
A technical baseline for hardening storage, devices, networks, and recovery readiness.
Quantify consequences
Model year-one and 10-year breach exposure using record count, practice size, security profile, and vendor surface.
Train the workforce
Public HIPAA training modules, a 203-term glossary with regulatory citations, and machine-readable references for acronyms, PHI identifiers, and state breach-notification law.
Free HIPAA Training
Five complete video modules covering HIPAA Fundamentals, Privacy Rule, Security Rule, Breach Notification, and real-world breach scenarios. Part of the 19-module HIPAA Foundations series (~1 hour 45 minutes of instruction, 95 assessment questions). Hosted on YouTube. Advanced Pro training series coming soon.
HIPAA Glossary — 203 Terms
203 HIPAA terms with definitions, regulatory citations, and cross-references. Schema.org DefinedTermSet markup for AI extraction. Bookmark for compliance reviews and BAA negotiations.
hipaa-toolkit on GitHub
Open-source HIPAA reference data under CC BY 4.0: 203-term glossary (CSV + JSON), 40+ acronyms, the 18 PHI Safe Harbor identifiers, and 50-state breach-notification quick reference. Plus four operational templates (BAA, NPP, IRP, Risk Analysis) released under CC0 for unrestricted use.
Track the threat landscape
The Breach Dashboard, HIPAA Response, Signal, and the open dataset provide different views of the same healthcare compliance and security landscape.
Breach Dashboard
A crawlable breach intelligence view with trends, severity framing, and HHS-context storytelling.
Patient Protect Signal
The free iOS app that packages breach intelligence, tools, and awareness for small practices.
HIPAA Response — Compliance & Security Intelligence
Verified compliance and security developments for independent practices. Each Response is checked against the source of record and published only when the evidence supports an operational takeaway.
Healthcare Breach Dataset
Citable CC BY 4.0 dataset of US healthcare breaches sourced from the HHS Office for Civil Rights Breach Portal. Severity scoring, editorial enrichment, no AI-modeled projections. CSV + JSON. License and attribution metadata included in the download body. For researchers, journalists, and AI-search engines.
Prevent disclosure
Protection at the moment of the decision — not another document explaining what should have happened afterward.
Cite the research
The methodology behind Patient Protect's breach-economic and threat-intelligence work. Free to read, free to cite.
From free tools to a running program
Ready to start the real work?
The HIPAA Foundation gives every practice a credible place to begin. The Patient Protect platform runs the continuous work — risk remediation, compliance scoring, workforce governance, vendor oversight, BAA tracking, security monitoring, audit evidence, and incident-response documentation. That work never finishes, which is why it is the product. From $39/month, no long-term contract.
Free tools stay free — no account needed. The 14-day platform trial asks for a card for identity verification; no charge before day 14, cancel any time.

