For clinics and healthcare practices

Security documentation for a practice without an IT department

HIPAA applies differently depending on whether you treat patients or handle records for someone who does. Documents that say which one you are, carry the 60-day breach timetable, and are honest about what is still outstanding.

Usually a cyber insurance renewal, a hospital or payer asking for your policies, or the realisation that the practice has never actually written any of this down.

5
documents
83
clauses
5
gaps flagged

What the engine actually produced for one real business of this kind — including the gaps, which it states with a remediation clause rather than leaving out.

What tends to be true of firms like yours.

Covered entity or business associate — they differ

The obligations are not the same, and neither role is excused by not having checked. If you provide care and bill insurance electronically you are almost certainly a covered entity; if you handle patient information on behalf of another healthcare organisation you are a business associate, directly subject to the Security Rule rather than only to your contract. Your documents state which, or state plainly that it is unconfirmed.

The 60-day clock, written down before you need it

Breaches of unsecured protected health information carry their own notification timetable, separate from and in addition to state law. Your incident response plan carries it, along with the four-factor assessment that decides whether an incident is notifiable at all — documented either way, because an undocumented decision not to notify is the one an investigator asks about.

Two things a document cannot do for you

HIPAA separately requires a written security risk analysis, reviewed at least annually, and a signed business associate agreement with every vendor that handles protected health information on your behalf. Your program names both as owner actions rather than pretending a policy covers them.

Honest about gaps, which matters more here

Where multi-factor authentication or endpoint protection is not in place yet, the documents say so with a remediation commitment. For a practice, a policy claiming controls you do not have is not just an insurance problem — it is a written record pointing the wrong way.

Where this stops

Whether you are a covered entity or a business associate is a determination for you and your counsel. Coverwright produces documentation; it does not make anyone HIPAA compliant, and no patient information is ever entered into it.

Start

See your own set before you pay.

Answer 21 plain-English questions — about ten minutes — and read the first section of your real generated program before deciding. From $199, one time, renewed for $99 a year.