Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect
Product & Platform

The HIPAA Foundation: 15+ Free Tools for Independent Practices

The HIPAA Foundation is Patient Protect's free layer for independent healthcare — 15+ tools, an open breach dataset, an iOS app, a Chrome extension, and research. No paid subscription. No sales call. No credit card. No paywall.

Patient ProtectPatient Protect Editorial Team·November 5, 2025·7 min read

Written and reviewed by the Patient Protect team — Joseph A. Perrin, CTO (federal infrastructure background, platform security architect), Angie Perrin, CSO (Certified HIPAA Consultant, 10+ years clinical practice), and Alexander Perrin, CEO (20 years enterprise SaaS, primary author of the Secure Care Research Institute research program). See editorial standards.

Share
Dashboard view of the HIPAA Foundation free tools for independent healthcare practices

The HIPAA Foundation: 15+ Free Tools for Independent Practices

Same rules, a fraction of the resources

A solo dental practice with 1,200 patient records answers to the same federal HIPAA framework as Mayo Clinic. Federal responsibilities do not diminish with headcount. Budgets do.

That gap is not new — but it has been quietly widening. IBM's 2024 Cost of a Data Breach Report puts the average healthcare breach at $9.77 million, the highest of any industry for the fourteenth consecutive year. Attacks on independent providers have risen roughly six times since 2021. And most of the tools that would help those practices see the problem clearly have been priced into subscription tiers and behind sales calls.

After eleven years building compliance and security tools for independent healthcare, Patient Protect made the foundation public. We call it the HIPAA Foundation. No paid subscription. No sales call. No credit card. No paywall.

Explore the full collection at patient-protect.com/free-tools.

What "the foundation" actually means

The HIPAA Foundation is a working collection of 15+ tools, datasets, references, an iOS app, a Chrome extension, and research — deliberately built so an independent practice can arrive with no context, take a first-order action within five minutes, and walk out with a keepable artifact.

Each free tool is a standalone web resource. None of them manage or store your ePHI. They draw on the same research, threat modeling, and compliance framework that inform the paid Patient Protect platform, but they are intentionally separated from platform infrastructure — so they stay simple, fast, and safe as a starting point.

The collection is organized around the six capabilities that actually raise the security standard.

1. Assess risk

Where do you stand? Start here.

  • Risk Assessment — The flagship. A comprehensive HIPAA risk analysis combining compliance readiness, entity classification, practice profile, and ePHI data flow into a single Patient Protect Score. Five minutes, no login. Free · proprietary.
  • Ask PIPAA — An AI HIPAA assistant that answers questions about the Security Rule, Privacy Rule, breach response, and risk analysis — with citations. Free · proprietary.
  • HIPAA Readiness Scan — See what an OCR investigator sees when they look at your practice website: tracking pixels, security gaps, email vulnerabilities, missing HIPAA documents. Thirty seconds. Free · proprietary.
  • HIPAA Self-Assessment — A seven-question readiness check with action-oriented guidance. Free · proprietary.
  • Entity Determination Tool — Determine whether you operate as a Covered Entity, Business Associate, Hybrid Entity, or Vendor under HIPAA. Free · proprietary.

2. Map exposure

Trace how patient data actually moves before something leaks.

  • ePHI Data Flow Mapper — Map how patient data moves through employees, devices, vendors, and systems. Export as SVG or JSON. Free · proprietary.
  • HIPAA Compliance Roadmap — Fifty-eight sequenced tasks across five phases (Foundation, Safeguards, Operations, Response, Continuous) with owners and CFR anchors. Free · proprietary.
  • Secure Infrastructure Checklist — Twenty-two technical controls with severity-weighted scoring and 2026 NPRM readiness signal. Free · proprietary.

3. Quantify consequences

Put a number on what a breach would actually cost.

4. Train the workforce

Reference and training material the workforce can actually use.

  • Free HIPAA Training — Four complete modules on the Privacy Rule, Security Rule, and compliance fundamentals. Part of an 80-module curriculum. Free · proprietary.
  • HIPAA Glossary — 203 Terms — Definitions, regulatory citations, and cross-references with Schema.org DefinedTermSet markup for AI extraction. Data is CC BY 4.0.
  • hipaa-toolkit on GitHub — Open reference data: 203-term glossary (CSV + JSON), 40+ acronyms, the 18 PHI Safe Harbor identifiers, 50-state breach-notification quick reference, plus four operational templates (BAA, NPP, IRP, Risk Analysis) released under CC0 for unrestricted use. Repository is CC BY 4.0.

5. Track the threat landscape

Situational awareness at the industry level.

  • Breach Dashboard — Every reported HHS OCR breach, mapped by state, filterable by entity type and vector, cross-referenced against six additional community sources across twelve analytical views. Free · proprietary.
  • Healthcare Breach Dataset — A citable dataset of U.S. healthcare breaches sourced from the HHS OCR Breach Portal. CSV + JSON. License and attribution metadata included inside the download body. CC BY 4.0.
  • HIPAA Response — Verified compliance and security developments for independent practices, checked against the source of record. Free · proprietary.
  • Patient Protect Signal — The mobile pillar of the HIPAA Foundation. Push notifications the moment HHS publishes a breach, compliance scoring you check between patients, and every reported breach mapped by state. Free iOS app, no account required. Free · proprietary.

6. Prevent disclosure

Protection at the moment of the decision.

  • HIPAA Shield — Browser Extension — A Chrome extension that warns when PHI is typed or pasted into a browser form — especially consumer AI chat tools like ChatGPT, Claude, and Gemini. Detection runs inside the browser. Zero network requests, no telemetry. MIT licensed.

Plus the research behind the work

  • Patient Protect Research — Two SSRN working papers from the Secure Care Research InstituteThe Cyber-Economic Stack and The Economics of ePHI Exposure — plus quarterly state-of-compliance reports. Free to read and cite. Papers are proprietary; commercial reuse or derivative analytical products require written authorization.

The Platform: turning awareness into automation

The free layer helps you see the problem clearly. The Patient Protect platform runs the continuous work most compliance vendors do not — risk remediation, compliance scoring, workforce governance, vendor oversight, BAA tracking, training enforcement, security monitoring, audit evidence, and incident-response documentation.

That work never finishes, which is why it is the product.

Free Foundation Basic   $39/mo Pro   $99/mo
What it is Diagnostic and educational — one-shot tools, no account Fourteen modules — active compliance operations Twenty modules — full operational visibility
Risk assessment Free five-minute self-assessment; keepable Exposure Report Full SRA with saved history and remediation tracking NIST-aligned SRA across locations with audit exports
Breach intelligence Public breach dashboard + citable dataset (CC BY 4.0) Alerts on incidents that affect your vendor surface Predictive breach modeling and peer comparison
Vendor & BAA oversight Manual via data-flow mapper Vendor Risk Scanner with BAA tracking Continuous monitoring with alerts on risky pathways
Workforce training Five free modules on HIPAA fundamentals, Privacy Rule, Security Rule Foundational modules with completion tracking 19 HIPAA Foundations modules today; advanced Pro series in development
Documentation & audit Downloadable templates + open toolkit Version-controlled policies in dashboard ePHI audit trails, exportable for OCR or insurer review
Support Blog, FAQs, resource center Standard email support Priority support and dedicated compliance advisor

Both paid plans include a 14-day trial. A credit card is required for identity verification; there is no charge before the trial ends. The free Foundation tools stay free — no account needed.

Free is not open source

Free and open are not the same thing, and Patient Protect draws the line deliberately.

  • CC BY 4.0 on the Healthcare Breach Dataset and the reference data in hipaa-toolkit — free to reproduce, redistribute, remix, and build upon (including commercially) with attribution to Patient Protect.
  • CC0 on the four operational templates (BAA, Notice of Privacy Practices, Incident Response Plan, Risk Analysis Questionnaire) — dedicated to the public domain for unrestricted use.
  • MIT on HIPAA Shield's source code — permits use, modification, distribution, sublicensing, and sale.
  • Free · proprietary on everything else — the tools are free to use, but the underlying scoring methodology, dashboard UX, editorial content, and analytical frameworks belong to Patient Protect.
  • Free to read · Proprietary on the SCRI research papers — free to read and cite; commercial reuse, adaptation, or derivative analytical products require written authorization.

Where a license is expressly stated, that license governs — including the CC BY 4.0 permission to use the dataset commercially. That distinction is written into our Terms of Use §6.6.

Why the foundation exists

Independent practices — dental offices, medical practices, behavioral health clinics, chiropractic offices, physical therapy centers, optometry practices — carry hospital-grade HIPAA obligations without dedicated legal, compliance, or cybersecurity teams. The compliance-vendor market has responded by gating basic tools behind $2,000–$5,000 consultant engagements and hiding reference material behind sales calls. The result: the segment most exposed to breach is the segment least able to see the exposure.

The consequences do not require a sophisticated attack. In 2016, Raleigh Orthopaedic Clinic paid $750,000 after releasing X-ray films and protected health information for 17,300 patients to a vendor without a Business Associate Agreement. No ransomware. No zero-day. A routine vendor workflow and a missing agreement.

The HIPAA Foundation is our answer to that gap. Every practice deserves a credible place to begin — free, immediate, no account required.

Start with the Risk Assessment →

The free tools and resources provided by Patient Protect are intended solely for educational and informational purposes. Use of these tools does not constitute legal advice, create an attorney-client or consultant relationship, or guarantee HIPAA compliance. While Patient Protect strives for accuracy and reliability, results, interpretations, and recommendations derived from these tools are provided without warranty or liability. Users remain solely responsible for verifying all compliance requirements applicable to their organization and for implementing appropriate safeguards consistent with federal and state law.

Was this useful? Share it.

Share

Corrections & Updates

Healthcare security data changes as investigations progress, vendors update systems, and laws and guidance evolve. If you see something outdated, incomplete, or incorrect — or have newer source material — we’d appreciate hearing from you.

Submit a correction →

Next step

What would an OCR investigator find on your website?

Free 30-second scan — tracking pixels, security gaps, missing policies. See what’s visible before they do.

Stay informed

Subscribe to HIPAA Pulse.

Breach alerts, enforcement updates, and compliance intelligence — every two weeks.

© 2026 Patient Protect LLC. All rights reserved. Content may not be reproduced, scraped, or used to train AI models without written permission. Terms · DMCA