HIPAAmart

HIPAA guide map

HIPAA Risk and Security Guide

Connect risk analysis, resilience, access, systems, and evidence prompts into a repeatable starting point.

Reviewed August 2026

Available guidance

  • HIPAA Risk Assessment

    Build a defensible risk analysis by connecting assets, threats, vulnerabilities, likelihood, impact, and remediation evidence.

  • Administrative Safeguards

    The governance, risk, workforce, incident, and contingency practices that organize Security Rule protection.

  • Physical Safeguards

    Facility, workstation, device, and media controls that help protect ePHI from physical threats.

  • Technical Safeguards

    Access, audit, integrity, authentication, and transmission controls for systems handling ePHI.

  • HIPAA Access Controls

    Designing unique identification, emergency access, automatic logoff, and least-privilege practices around ePHI.

  • Encryption and HIPAA

    How to evaluate encryption for ePHI without reducing a broader risk decision to a yes-or-no checkbox.

  • HIPAA Audit Controls

    Create useful, reviewable records of activity in systems that contain or use ePHI.

  • HIPAA Disaster Recovery

    Make contingency planning and recovery evidence useful for the availability of ePHI and the continuity of critical work.

  • Ransomware and HIPAA

    A grounded response framework for ransomware risk, availability, evidence, and breach analysis.