Lindsay Hill

Psych NP Fellowship · Free Practice Tool

Free · No signup · Audit-ready

Build your HIPAA policies-and-procedures manual.

Federal law (HIPAA Security Rule, 45 CFR § 164.316) requires every covered entity — including a solo PMHNP practice — to maintain a written set of policies and procedures. Answer the questions below and this tool generates yours as a downloadable PDF. About 15–20 minutes.

Why it matters: Most solo practices have the patient-facing HIPAA notice and signed BAAs with vendors, but no internal manual. That internal manual is the document an OCR investigator asks for first. Not having one is a fineable gap even if nothing ever goes wrong.

What you'll need handy · before you start

Practice basics. Your LLC/PLLC name, NPI, practice address, designated officer name.
Vendor list. Your EHR, telehealth, e-prescribing, billing, AI scribe, secure messaging, and email provider names.
Tech inventory. Whether you have device encryption (FileVault/BitLocker), MFA, password manager, screen auto-lock.
1

Practice identification

The basics about your covered entity. These appear on the cover page and throughout the manual.

2

Designated HIPAA officers

HIPAA requires you to formally designate a Privacy Officer and a Security Officer. In a solo practice, you typically appoint yourself to both roles. The manual must name them.

3

ePHI inventory

Where does electronic protected health information live in your practice, and what types do you handle? Check all that apply.

4

Vendor inventory + BAA status

Every vendor that touches ePHI must have a signed Business Associate Agreement (BAA). Fill in the vendor name and confirm BAA status for each. Leave a row blank if you don't use that category.

Category
Vendor name
BAA signed?
5

Workforce

Anyone who can access ePHI counts as workforce, even if it's just you.

6

Physical safeguards

Even a telehealth-only practice has physical safeguards: the device, the workspace, paper documents.

7

Technical safeguards

These are the controls on the devices and accounts that touch ePHI. Be honest — gaps you flag here become your remediation list.

8

Breach response & risk analysis

Federal rules give you 60 days from discovery to notify affected individuals (HIPAA Breach Notification Rule, 45 CFR §§ 164.400–414). Document who does what.

Everything stays in your browser. Nothing is sent to any server.

Your manual is ready. Review below, then save to PDF.
Built by Lindsay Hill, DNP, PMHNP-BC · Psych NP Fellowship.
Educational reference only — not legal advice. The completed manual is a starting compliance document; review it against your state's privacy rules and your malpractice carrier's requirements before relying on it in an audit. Recommended: have a healthcare attorney review once, then update annually.