Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

The HIPAA Foundation

The HIPAA foundation, free to use, cite and build on.

After eleven years building tools to close the gap between independent-practice HIPAA obligations and independent-practice resources, we made the foundation public. A collection of 18 resources: risk assessments, training, ePHI mapping, breach-cost modeling, implementation roadmaps, threat intelligence, a citable U.S. healthcare breach dataset, machine-readable references, templates, research, and open-source PHI-detection software.

  • No paid subscription
  • No sales call
  • No credit card
  • No paywall

CC BY 4.0 on data and reference materials. CC0 on the four operational templates (BAA, NPP, IRP, Risk Analysis). MIT on HIPAA Shield source code.

Same rules, a fraction of the resources

A solo dental practice with 1,200 patient records answers to the same federal HIPAA framework as Mayo Clinic.

Their federal responsibilities do not diminish with headcount. Their budgets do. Dental offices, medical practices, behavioral health clinics, chiropractic offices, physical therapy centers, optometry practices — the independent segment operates under hospital-grade HIPAA obligations without dedicated legal, compliance, or cybersecurity teams. IBM’s 2026 Cost of a Data Breach Report placed the average healthcare breach at $6.64 million — the highest of any industry for the 13th consecutive year.

The consequences do not require a sophisticated attack. In 2016, Raleigh Orthopaedic Clinic paid $750,000 after releasing X-ray films and protected health information for 17,300 patients to a vendor without a Business Associate Agreement. No ransomware. No zero-day. A routine vendor workflow and a missing agreement.

“We did not begin by asking independent providers to trust another compliance platform. We began by building the tools, data, and research they need to make better security decisions. Independent healthcare carries enterprise-level responsibility without enterprise-level infrastructure. We chose to make that foundation public.”
— Alexander Perrin, founder and CEO

The paid Patient Protect platform is a fundamentally different offer. The public resources are finished products. They do not expire, withhold results, or convert into paid subscriptions. What they do not do is run a compliance program. Our commercial platform handles the continuous work: risk remediation, compliance scoring, workforce governance, vendor oversight, BAA tracking, training enforcement, security monitoring, audit evidence, and incident-response documentation. That work never finishes, which is why it is the product. From $39/month, no long-term contract.

Six capabilities, one foundation

18 resources across the six capabilities that raise the security standard.

Assess risk. Map exposure. Quantify consequences. Train the workforce. Track the threat landscape. Prevent disclosure. Plus the research and methodology behind the work.

Assess risk

Assessments, classification tools, and an AI assistant that reveal your actual compliance standing and starting point.

Map exposure

Trace how patient information moves through employees, devices, vendors, and systems — then turn findings into sequenced work.

Quantify consequences

Model year-one and 10-year breach exposure using record count, practice size, security profile, and vendor surface.

Train the workforce

Public HIPAA training modules, a 203-term glossary with regulatory citations, and machine-readable references for acronyms, PHI identifiers, and state breach-notification law.

Track the threat landscape

The Breach Dashboard, HIPAA Response, Signal, and the open dataset provide different views of the same healthcare compliance and security landscape.

Prevent disclosure

Protection at the moment of the decision — not another document explaining what should have happened afterward.

Cite the research

The methodology behind Patient Protect's breach-economic and threat-intelligence work. Free to read, free to cite.

From free tools to a running program

Ready to start the real work?

The HIPAA Foundation gives every practice a credible place to begin. The Patient Protect platform runs the continuous work — risk remediation, compliance scoring, workforce governance, vendor oversight, BAA tracking, security monitoring, audit evidence, and incident-response documentation. That work never finishes, which is why it is the product. From $39/month, no long-term contract.

Free tools stay free — no account needed. The 14-day platform trial asks for a card for identity verification; no charge before day 14, cancel any time.