Free, editable starting points for every required document — plus a warning about what templates cannot do.
What we give away
Risk assessment workbook, full policy set, BAA, incident response plan, training deck, device and BYOD policies, remote work policy, encryption policy, access control policy, and the annual review checklist.
Each one maps to a specific obligation, which is the only sensible way to organise a document set. The risk assessment workbook implements §164.308(a)(1) — the register, the scales, the methodology skeleton. The policy set covers the administrative, physical, and technical safeguard standards plus the Privacy Rule items. The BAA template contains the §164.504(e) required provisions. The incident response plan carries the §164.308(a)(6) procedures, the four-factor worksheet, and the notification clocks. The training deck covers the awareness requirement with a completion record sheet. The BYOD, remote work, encryption, access control, and password policies fill the specific gaps modern distributed teams actually have. And the annual review checklist operationalises the evaluation standard at §164.308(a)(8). Every file is DOCX or spreadsheet, includes rule citations and fill-in guidance in the margins, and comes with a completed example.
Why free, and why templates at all
The honest economics: policy documents are commodity. The regulatory requirements they implement have been stable for years, every consultancy works from substantially similar bases, and charging hundreds of dollars for them mostly prices out the small organisations that need them most. The value in a compliance engagement was never the DOCX — it is the adaptation, the judgement, and the ongoing proof. So we give the commodity away and sell the other parts. Where do templates genuinely help? They encode the structure a reviewer expects, they cite the specifications so you know why each clause exists, and they turn “write twenty policies” from a blank-page month into an editing week.
How to use them
Read every paragraph and delete anything that describes an organisation you are not. A template with three untrue statements is worse than no template.
The working sequence that avoids the classic failures: start from your risk assessment, not from the policy folder, because policies are supposed to answer identified risks rather than decorate them. Then adapt each document — real role names, real systems, real procedures, with every aspirational clause either implemented or deleted. Then assign an owner and a next-review date per document. Then distribute and collect acknowledgements recorded against the version number. Then keep everything, including superseded versions, for six years under §164.316. An untrue policy is the emphasis worth repeating: in an investigation, your policies are read as the standard you set for yourself, and every clause you did not follow is a documented deviation. Deleting a control you lack is defensible; claiming it falsely is not.
What templates cannot do
They cannot conduct your risk analysis, they cannot record acknowledgements, and they cannot prove they were followed. Those three things are the program.
This is the section other template vendors skip, so here it is plainly. A downloaded risk assessment workbook contains no knowledge of your systems — the inventory and scoring are irreducibly your work. A policy in a folder generates no record of who agreed to it or when, and “everyone knows about it” is not an acknowledgement record. And nothing in a document proves the procedure ran — the access review happened, the backup restored, the training completed. Documents plus those three missing capabilities equal a programme; documents alone equal a very organised folder. Relatedly: no template, ours included, makes you “HIPAA certified”, because no such certification exists — HHS operates no programme and anyone selling one is selling a badge.
Licensing
Ours are free to use and modify commercially, no attribution required. We ask for an email address, which is the whole business model of this page.
No watermarks, no expiry, no locked sections, no upsell wall halfway through the document. Rebrand them, merge them into your handbook, use them across client engagements if you are a consultant. You will be on our mailing list until you unsubscribe, and we will occasionally mention the platform and services. That is the entire exchange. If you want to know which templates you actually need before downloading all of them, the free readiness assessment will point you at your specific gaps in about eight minutes.
Questions teams actually ask
Which template should we start with? The risk assessment workbook, almost always. Policies are supposed to answer identified risks, and adapting the policy set before you know your risks means doing the editing twice. The exception is a live commercial deadline — if a customer questionnaire is blocking a deal, start with whatever documents the questionnaire demands and backfill the assessment immediately after.
Are these suitable for a business associate, or only covered entities? Both, with different subsetting. A business associate without direct patient relationships will cut most of the patient-facing Privacy Rule procedures down to what its BAAs require, keep the entire Security Rule set, and lean harder on the subcontractor version of the BAA template. The margin guidance flags which sections are entity-type specific.
Do they cover state privacy laws? No, deliberately. State medical-records retention, breach notification variants, and consumer privacy statutes layer on top of HIPAA and change too often for a static template to track honestly. Treat these documents as your federal floor and have counsel confirm the state layer.
How do we keep the set current after adoption? Two mechanisms, both cheap: a next-review date on every document, audited annually by the review checklist, and a change trigger — any new system, vendor category, or workforce model prompts a check of the documents it touches. The failure mode is not bad templates; it is 2024 documents describing a 2026 organisation.
What order do acknowledgements happen in? Adapt, then approve internally, then distribute, then acknowledge against the version number — never distribute a document still marked draft, because half-acknowledged drafts poison the evidence trail you are trying to build.
How long does adaptation actually take? For a small organisation working honestly: the risk assessment workbook is about a week, mostly interviews; the policy set is an editing week spread across a month of owner reviews; the single-topic policies are an afternoon each. The completed examples in every download exist to compress this — calibrating against a filled-in version is faster than staring at blank margins. Budget the acknowledgement chase separately; collecting signatures from a distracted workforce reliably takes longer than writing the documents did. The one shortcut that never pays is skipping the read-through — every clause you did not read is a clause you may be audited against later, and finding out during the audit is the expensive way.
Where SuperHIPAA fits
Everything above is work. The platform does the parts that are mechanical — evidence collection, acknowledgement tracking, register maintenance, renewal reminders — and our team does the parts that need judgement. You keep the parts that need to be yours.
Start where you are
Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.