Skip to main content

Free resource

HIPAA Security Policy Starter Pack (WISP, SRA & BAA)

The documents covered entities are required to maintain but rarely have: a Written Information Security Plan, a Security Risk Analysis worksheet, and a Business Associate Agreement checklist. Practitioner-grade starter templates you can adapt for your practice.

Why this matters

Cyber-insurance applications and OCR inquiries increasingly ask: do you have a written security plan, a current Security Risk Analysis, and signed BAAs? Most small practices do not. This starter pack gives you a practitioner-grade foundation to build on, and we will help you complete it.

What is inside the pack

Three documents, mapped to the HIPAA Security Rule.

WISP template

A Written Information Security Plan covering the required administrative, physical, and technical safeguards, with fill-in sections for your practice.

Security Risk Analysis worksheet

A structured worksheet to document assets, threats, and gaps, the assessment the Security Rule requires and OCR asks for first.

BAA checklist

A checklist to make sure every vendor that touches PHI has a signed Business Associate Agreement, with the key clauses to confirm.

These are starter templates for education, not legal advice. Have your own counsel review and adapt them before relying on them.

Get the starter pack and a free gap review.

Book a free 30-minute HIPAA assessment. We will send the WISP, SRA, and BAA starter templates and walk you through the gaps specific to your practice. No obligation.

Book a Free HIPAA Assessment

Remote-first · nationwide · healthcare-focused · 30-day money-back guarantee

Request a Quote

Fill out the form below and our team will get back to you within one business day.

Free IT & HIPAA security assessment