Free tool
Checklists don't make you compliant. They show you how far you are.
Most HIPAA programs start with a policy template and stop there. This roadmap works differently — 17 operational steps, each with specific tasks, the regulation behind it, and how Patient Protect automates the work. Track your progress. Find the gaps. Close them.
17
Steps
From entity classification to continuous monitoring
58
Tasks
Actionable items across all 17 steps — each one checkable
5
Phases
Foundation, Safeguards, Operations, Response, Continuous
100%
Free
No login, no credit card, no trial expiration
Sample roadmap
What an in-progress roadmap looks like.
A preview of the roadmap mid-way through implementation. Each task carries an owner, a status, and a CFR anchor where the regulation is specific. Yours will populate as you check items off.
Where you are
20 of 58 tasks complete · 3 critical open · Next review: 30 days
Foundation phase closed. Safeguards phase in progress. Operations, Response, and Continuous phases have not been started.
Phase 01 · Foundation
Complete · 8 of 8 tasks
[x]Classify entity type — covered entity confirmed · §160.103
Owner: Compliance Officer · Signed off
[x]Complete Security Risk Analysis · §164.308(a)(1)(ii)(A)
Owner: Compliance Officer · Signed off
Phase 02 · Safeguards
In progress · 12 of 18 tasks
[~]Deploy encryption at rest — §164.312(a)(2)(iv) · Ready for review
Owner: Practice Manager · IT verification pending
[!]Enforce MFA on all workforce accounts — §164.312(d) · Critical
Owner: Practice Manager · Blocked on vendor rollout
Phase 03 · Operations
Pending · 0 of 12 tasks
[ ]Run workforce security awareness training — §164.308(a)(5), on a documented cadence · Not started
Owner: Practice Manager · Queued
Sample data. Your roadmap will populate with your own progress as you work through the steps below.
Compliance readiness
Foundation
Establish your compliance baseline — classification, risk assessment, and policies.
Safeguards
Physical, technical, and administrative controls that protect ePHI.
Operations
Vendor management, patient rights, organizational readiness.
Breach Preparedness
Incident response, breach notification, and disaster recovery.
Continuous Compliance
Monitoring, automation, auditing, and regulatory agility.
How to use this
Three ways to get value from this roadmap.
Self-assess
Work through each phase with your compliance or privacy officer. Expand each step to see the specific tasks. Check the ones you can confirm are done. The progress bar shows your compliance standing at a glance.
Understand the why
Every step includes the regulatory rationale and the enforcement reality behind it. The “why it matters” section connects each requirement to real-world OCR actions, breach consequences, and audit outcomes.
Find the automation
The “Patient Protect” panel on each step shows exactly what the platform handles for you. Unchecked tasks are your manual exposure — the roadmap shows you where to start and what to automate.
Why checklists fail
A policy on a shelf is not compliance. Operations are compliance.
When OCR investigates a breach, they do not ask whether you have a HIPAA policy. They ask whether you implemented it, monitored it, and updated it. The distinction is everything. A well-written policy that was never enforced is worse than no policy at all — it proves you knew what to do and chose not to.
This roadmap is structured around operational compliance, not documentation for its own sake. Each of the 17 steps maps to a specific HIPAA requirement — risk assessment (§164.308(a)(1)), workforce training (§164.308(a)(5)), access controls (§164.312(a)(1)), incident response (§164.308(a)(6)), business associate management (§164.308(b)(1)), and breach notification (§164.404-410). The tasks under each step are the actions that create defensible evidence.
For independent practices, the biggest risk is not a sophisticated cyber attack. It is compliance drift — the slow erosion that happens when training lapses, BAAs expire, risk assessments go stale, and nobody notices until an incident forces an audit. This roadmap makes the drift visible. The progress bar is your compliance heartbeat.
Related tool
Secure Infrastructure Checklist
This roadmap covers the operational compliance program. The Infrastructure Checklist covers the 20 technical controls underneath it — encryption, network security, access control, monitoring, vendor validation, and disaster recovery.
Check Your InfrastructureGet a full picture
Unified Risk Assessment
The roadmap shows where your program has gaps. The Unified Risk Assessment scores your overall exposure across compliance readiness, entity classification, and ePHI data flow in a single evaluation.
Take the Free AssessmentPart of the HIPAA Foundation · Free tools & resources
See the full collectionMap exposure
The roadmap shows what needs to happen. The platform assigns owners, tracks completion of every task, and captures the evidence for audit.
Next in the sequence
Secure Infrastructure ChecklistTrace how patient information moves through employees, devices, vendors, and systems — then turn findings into sequenced work.
From free tools to a running program
Ready to start the real work?
The roadmap shows what needs to happen. Patient Protect makes it happen — automated risk assessments, policy management, training tracking, vendor oversight, and incident response in one platform built for independent practices.
Free tools stay free — no account needed. The 14-day platform trial asks for a card for identity verification; no charge before day 14, cancel any time.
