The HIPAA Foundation: 15+ Free Tools for Independent Practices
The HIPAA Foundation is Patient Protect's free layer for independent healthcare — 15+ tools, an open breach dataset, an iOS app, a Chrome extension, and research. No paid subscription. No sales call. No credit card. No paywall.
Written and reviewed by the Patient Protect team — Joseph A. Perrin, CTO (federal infrastructure background, platform security architect), Angie Perrin, CSO (Certified HIPAA Consultant, 10+ years clinical practice), and Alexander Perrin, CEO (20 years enterprise SaaS, primary author of the Secure Care Research Institute research program). See editorial standards.

The HIPAA Foundation: 15+ Free Tools for Independent Practices
Same rules, a fraction of the resources
A solo dental practice with 1,200 patient records answers to the same federal HIPAA framework as Mayo Clinic. Federal responsibilities do not diminish with headcount. Budgets do.
That gap is not new — but it has been quietly widening. IBM's 2024 Cost of a Data Breach Report puts the average healthcare breach at $9.77 million, the highest of any industry for the fourteenth consecutive year. Attacks on independent providers have risen roughly six times since 2021. And most of the tools that would help those practices see the problem clearly have been priced into subscription tiers and behind sales calls.
After eleven years building compliance and security tools for independent healthcare, Patient Protect made the foundation public. We call it the HIPAA Foundation. No paid subscription. No sales call. No credit card. No paywall.
Explore the full collection at patient-protect.com/free-tools.
What "the foundation" actually means
The HIPAA Foundation is a working collection of 15+ tools, datasets, references, an iOS app, a Chrome extension, and research — deliberately built so an independent practice can arrive with no context, take a first-order action within five minutes, and walk out with a keepable artifact.
Each free tool is a standalone web resource. None of them manage or store your ePHI. They draw on the same research, threat modeling, and compliance framework that inform the paid Patient Protect platform, but they are intentionally separated from platform infrastructure — so they stay simple, fast, and safe as a starting point.
The collection is organized around the six capabilities that actually raise the security standard.
1. Assess risk
Where do you stand? Start here.
- Risk Assessment — The flagship. A comprehensive HIPAA risk analysis combining compliance readiness, entity classification, practice profile, and ePHI data flow into a single Patient Protect Score. Five minutes, no login. Free · proprietary.
- Ask PIPAA — An AI HIPAA assistant that answers questions about the Security Rule, Privacy Rule, breach response, and risk analysis — with citations. Free · proprietary.
- HIPAA Readiness Scan — See what an OCR investigator sees when they look at your practice website: tracking pixels, security gaps, email vulnerabilities, missing HIPAA documents. Thirty seconds. Free · proprietary.
- HIPAA Self-Assessment — A seven-question readiness check with action-oriented guidance. Free · proprietary.
- Entity Determination Tool — Determine whether you operate as a Covered Entity, Business Associate, Hybrid Entity, or Vendor under HIPAA. Free · proprietary.
2. Map exposure
Trace how patient data actually moves before something leaks.
- ePHI Data Flow Mapper — Map how patient data moves through employees, devices, vendors, and systems. Export as SVG or JSON. Free · proprietary.
- HIPAA Compliance Roadmap — Fifty-eight sequenced tasks across five phases (Foundation, Safeguards, Operations, Response, Continuous) with owners and CFR anchors. Free · proprietary.
- Secure Infrastructure Checklist — Twenty-two technical controls with severity-weighted scoring and 2026 NPRM readiness signal. Free · proprietary.
3. Quantify consequences
Put a number on what a breach would actually cost.
- HIPAA Breach Cost Calculator — Model year-one and 10-year exposure using record count, vendor surface, and security tier. Built from SSRN #5257628 methodology. Free · proprietary.
4. Train the workforce
Reference and training material the workforce can actually use.
- Free HIPAA Training — Four complete modules on the Privacy Rule, Security Rule, and compliance fundamentals. Part of an 80-module curriculum. Free · proprietary.
- HIPAA Glossary — 203 Terms — Definitions, regulatory citations, and cross-references with Schema.org DefinedTermSet markup for AI extraction. Data is CC BY 4.0.
- hipaa-toolkit on GitHub — Open reference data: 203-term glossary (CSV + JSON), 40+ acronyms, the 18 PHI Safe Harbor identifiers, 50-state breach-notification quick reference, plus four operational templates (BAA, NPP, IRP, Risk Analysis) released under CC0 for unrestricted use. Repository is CC BY 4.0.
5. Track the threat landscape
Situational awareness at the industry level.
- Breach Dashboard — Every reported HHS OCR breach, mapped by state, filterable by entity type and vector, cross-referenced against six additional community sources across twelve analytical views. Free · proprietary.
- Healthcare Breach Dataset — A citable dataset of U.S. healthcare breaches sourced from the HHS OCR Breach Portal. CSV + JSON. License and attribution metadata included inside the download body. CC BY 4.0.
- HIPAA Response — Verified compliance and security developments for independent practices, checked against the source of record. Free · proprietary.
- Patient Protect Signal — The mobile pillar of the HIPAA Foundation. Push notifications the moment HHS publishes a breach, compliance scoring you check between patients, and every reported breach mapped by state. Free iOS app, no account required. Free · proprietary.
6. Prevent disclosure
Protection at the moment of the decision.
- HIPAA Shield — Browser Extension — A Chrome extension that warns when PHI is typed or pasted into a browser form — especially consumer AI chat tools like ChatGPT, Claude, and Gemini. Detection runs inside the browser. Zero network requests, no telemetry. MIT licensed.
Plus the research behind the work
- Patient Protect Research — Two SSRN working papers from the Secure Care Research Institute — The Cyber-Economic Stack and The Economics of ePHI Exposure — plus quarterly state-of-compliance reports. Free to read and cite. Papers are proprietary; commercial reuse or derivative analytical products require written authorization.
The Platform: turning awareness into automation
The free layer helps you see the problem clearly. The Patient Protect platform runs the continuous work most compliance vendors do not — risk remediation, compliance scoring, workforce governance, vendor oversight, BAA tracking, training enforcement, security monitoring, audit evidence, and incident-response documentation.
That work never finishes, which is why it is the product.
| Free Foundation | Basic $39/mo | Pro $99/mo | |
|---|---|---|---|
| What it is | Diagnostic and educational — one-shot tools, no account | Fourteen modules — active compliance operations | Twenty modules — full operational visibility |
| Risk assessment | Free five-minute self-assessment; keepable Exposure Report | Full SRA with saved history and remediation tracking | NIST-aligned SRA across locations with audit exports |
| Breach intelligence | Public breach dashboard + citable dataset (CC BY 4.0) | Alerts on incidents that affect your vendor surface | Predictive breach modeling and peer comparison |
| Vendor & BAA oversight | Manual via data-flow mapper | Vendor Risk Scanner with BAA tracking | Continuous monitoring with alerts on risky pathways |
| Workforce training | Five free modules on HIPAA fundamentals, Privacy Rule, Security Rule | Foundational modules with completion tracking | 19 HIPAA Foundations modules today; advanced Pro series in development |
| Documentation & audit | Downloadable templates + open toolkit | Version-controlled policies in dashboard | ePHI audit trails, exportable for OCR or insurer review |
| Support | Blog, FAQs, resource center | Standard email support | Priority support and dedicated compliance advisor |
Both paid plans include a 14-day trial. A credit card is required for identity verification; there is no charge before the trial ends. The free Foundation tools stay free — no account needed.
Free is not open source
Free and open are not the same thing, and Patient Protect draws the line deliberately.
- CC BY 4.0 on the Healthcare Breach Dataset and the reference data in hipaa-toolkit — free to reproduce, redistribute, remix, and build upon (including commercially) with attribution to Patient Protect.
- CC0 on the four operational templates (BAA, Notice of Privacy Practices, Incident Response Plan, Risk Analysis Questionnaire) — dedicated to the public domain for unrestricted use.
- MIT on HIPAA Shield's source code — permits use, modification, distribution, sublicensing, and sale.
- Free · proprietary on everything else — the tools are free to use, but the underlying scoring methodology, dashboard UX, editorial content, and analytical frameworks belong to Patient Protect.
- Free to read · Proprietary on the SCRI research papers — free to read and cite; commercial reuse, adaptation, or derivative analytical products require written authorization.
Where a license is expressly stated, that license governs — including the CC BY 4.0 permission to use the dataset commercially. That distinction is written into our Terms of Use §6.6.
Why the foundation exists
Independent practices — dental offices, medical practices, behavioral health clinics, chiropractic offices, physical therapy centers, optometry practices — carry hospital-grade HIPAA obligations without dedicated legal, compliance, or cybersecurity teams. The compliance-vendor market has responded by gating basic tools behind $2,000–$5,000 consultant engagements and hiding reference material behind sales calls. The result: the segment most exposed to breach is the segment least able to see the exposure.
The consequences do not require a sophisticated attack. In 2016, Raleigh Orthopaedic Clinic paid $750,000 after releasing X-ray films and protected health information for 17,300 patients to a vendor without a Business Associate Agreement. No ransomware. No zero-day. A routine vendor workflow and a missing agreement.
The HIPAA Foundation is our answer to that gap. Every practice deserves a credible place to begin — free, immediate, no account required.
Start with the Risk Assessment →
The free tools and resources provided by Patient Protect are intended solely for educational and informational purposes. Use of these tools does not constitute legal advice, create an attorney-client or consultant relationship, or guarantee HIPAA compliance. While Patient Protect strives for accuracy and reliability, results, interpretations, and recommendations derived from these tools are provided without warranty or liability. Users remain solely responsible for verifying all compliance requirements applicable to their organization and for implementing appropriate safeguards consistent with federal and state law.
Corrections & Updates
Healthcare security data changes as investigations progress, vendors update systems, and laws and guidance evolve. If you see something outdated, incomplete, or incorrect — or have newer source material — we’d appreciate hearing from you.
