HIPAA guide map
HIPAA Risk and Security Guide
Connect risk analysis, resilience, access, systems, and evidence prompts into a repeatable starting point.
Reviewed August 2026
Available guidance
- HIPAA Risk Assessment
Build a defensible risk analysis by connecting assets, threats, vulnerabilities, likelihood, impact, and remediation evidence.
- Administrative Safeguards
The governance, risk, workforce, incident, and contingency practices that organize Security Rule protection.
- Physical Safeguards
Facility, workstation, device, and media controls that help protect ePHI from physical threats.
- Technical Safeguards
Access, audit, integrity, authentication, and transmission controls for systems handling ePHI.
- HIPAA Access Controls
Designing unique identification, emergency access, automatic logoff, and least-privilege practices around ePHI.
- Encryption and HIPAA
How to evaluate encryption for ePHI without reducing a broader risk decision to a yes-or-no checkbox.
- HIPAA Audit Controls
Create useful, reviewable records of activity in systems that contain or use ePHI.
- HIPAA Disaster Recovery
Make contingency planning and recovery evidence useful for the availability of ePHI and the continuity of critical work.
- Ransomware and HIPAA
A grounded response framework for ransomware risk, availability, evidence, and breach analysis.