The full Security, Privacy, and Breach Notification policy set — 28 editable documents with the rule citation on every section.
What is in the download
- Format: DOCX (28 files)
- Length: 28 page(s) / file(s)
- Includes: rule citations, fill-in guidance in the margin, and a completed example
- Licence: free to modify and use commercially
What is in the set
Twenty-eight focused documents rather than one omnibus binder, because separate policies can have separate owners, separate review dates, and separate acknowledgement cycles — updating one paragraph should not re-trigger sign-off on ninety pages. The set maps to the rule, and every section carries its citation:
- Administrative safeguards (§164.308): risk management, sanctions, Security Officer designation, workforce security (joiner–mover–leaver), information access management, security awareness and training, security incident procedures, contingency planning and backup, evaluation, and vendor/BAA management.
- Physical safeguards (§164.310): facility security, workstation use and security, and device and media disposal.
- Technical safeguards (§164.312): access control, audit logging and review, integrity, authentication, and transmission security.
- Privacy Rule (§164.5xx): uses and disclosures, minimum necessary, patient rights procedures (access, amendment, restriction, accounting), Notice of Privacy Practices, authorisations, and complaints.
- Breach Notification (§§164.400–414): the assessment and notification procedure, plus the documentation standard itself — versioning, six-year retention, availability.
Each document includes the fill-in margin guidance and a completed example, so you can always see what a finished, honest version looks like at a fictional small organisation.
How to use it
- Read it end to end before filling anything in.
- Delete every clause describing a control you do not have. An untrue policy is evidence against you.
- Assign an owner and a review date to each section.
- Publish it, collect acknowledgements against the version number, and retain both for six years.
Sequence matters with a full set: adapt the risk management and access documents first, because their decisions (roles, systems, review cadences) cascade into most of the others. And resist adopting all 28 in one ceremonial afternoon — a realistic rollout is a handful per week, each read by its actual owner.
How to customise it
Do a find-and-replace pass last, not first — renaming the organisation is cosmetic, and doing it early creates the illusion of progress. The real adaptation is per-document: put real system names into the technical policies, real role names into the access and workforce documents, and your real entity type into the Privacy Rule set — a business associate without direct patient relationships should cut the patient-facing procedures down to what its BAAs actually require of it. Delete whole documents that do not apply rather than keeping them “just in case”; an unfollowed policy is a standard you set and ignored. Where a policy describes a control you want but lack, move the claim into a dated remediation plan instead of the policy. Expect the honest first pass to shrink the set — a 30-person company typically lands nearer twenty documents than twenty-eight, and that is a feature.
Common mistakes
- Adopting without reading. The most damaging artefact in a gap assessment is a policy set with another company’s role titles still in it — it proves the documents were purchased, not implemented.
- The omnibus merge. Combining everything into one handbook chapter destroys per-document ownership and makes every small update a full re-acknowledgement event.
- No acknowledgement trail. Twenty-eight adapted policies with no record of who agreed to which version is a library, not a programme. Record person, document, version, and date.
- Set-and-forget. Policies decay at the speed of your organisation; the review dates in step three are what the annual review checklist audits.
- Writing policy before assessing risk. Policies are supposed to answer identified risks. Run the risk assessment first, or at least in parallel.
Related templates
The set deliberately overlaps with the standalone deep-dive templates — access control, passwords, encryption, remote work, and the incident response plan — which contain fuller versions of the corresponding documents here; use whichever depth fits each area. The reasoning behind the whole structure is in the policies guide, and the free readiness assessment will tell you which documents to adapt first.
The honest limitation
A template is a starting point, not a program. It cannot record who acknowledged it, prove it was followed, or update itself when your environment changes. Those three things are what the platform does, and they are the difference between having documents and having compliance.
Start where you are
Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.