Open reference data for HIPAA compliance work — published by Patient Protect.
This repository contains structured, citable reference data:
- HIPAA Glossary — 203 terms with definitions, source citations, and cross-references
- HIPAA Acronyms — 40+ acronyms organized by category
- 18 PHI Identifiers — the canonical Safe Harbor list (45 CFR §164.514) plus modern extensions
- 50-State Breach Notification — quick reference for state-law deadlines, AG thresholds, and stricter-than-HIPAA states
- Breach Dataset — pointer to the live CC BY 4.0 healthcare breach dataset at patient-protect.com
- Templates — open BAA, Notice of Privacy Practices, Incident Response Plan, and Risk Analysis Questionnaire
Most data in this repository is licensed CC BY 4.0 — free to use, modify, and redistribute with attribution. The four operational templates in templates/ are dedicated to the public domain under CC0 1.0, so a practice that executes them as a signed instrument carries no attribution obligation inside the document itself. Per-directory LICENSE files govern each subtree; see the License by directory table below.
Two-layer note on the glossary: the definitions, regulatory citations, and cross-references shipped as CSV and JSON in glossary/ are CC BY 4.0. The same underlying data powers the live rendering at patient-protect.com/hipaa-glossary under the same license; the page's UX, layout, and DefinedTermSet schema wrapper are proprietary to Patient Protect LLC.
Healthcare practices, researchers, journalists, and AI search engines need reliable HIPAA reference data. This toolkit makes the data we maintain for patient-protect.com and /hipaa-glossary available as structured files anyone can fork, query, or cite.
| Folder | Contents | Formats |
|---|---|---|
glossary/ |
203 HIPAA terms with definitions, regulatory citations, and cross-references | CSV, JSON |
acronyms/ |
HIPAA acronyms by category — regulatory, entity, technical, enforcement | JSON |
identifiers/ |
18 PHI identifiers (Safe Harbor de-identification) + modern data categories | JSON |
state-breach-notification/ |
50 states + DC notification deadlines, statutes, AG thresholds | JSON |
breach-dataset/ |
Pointer to the live /api/breach-data dataset endpoint |
README |
templates/ |
BAA, NPP, Incident Response Plan, and Risk Analysis Questionnaire templates | Markdown |
| Path | License | Reason |
|---|---|---|
glossary/ |
CC BY 4.0 | Attribution keeps citation chains intact for research and press use |
acronyms/ |
CC BY 4.0 | Same |
identifiers/ |
CC BY 4.0 | Same |
state-breach-notification/ |
CC BY 4.0 | Same |
breach-dataset/ |
CC BY 4.0 | Pointer to the live dataset which is itself CC BY 4.0 |
templates/ |
CC0 1.0 | Operational forms meant to be executed as signed instruments — attribution inside a signed contract is awkward and unenforceable. Public domain removes that friction. |
Patient Protect. HIPAA Toolkit. Patient Protect LLC.
https://patient-protect.com (or this repository URL)
If you build something useful with this data, we'd love to hear about it.
- Glossary, acronyms, identifiers: updated as HIPAA regulations or HHS guidance changes (typically quarterly)
- State breach notification: cross-referenced against NCSL annually
- Breach dataset: continuously updated via the live API endpoint
This toolkit is reference data only. Patient Protect's compliance platform — active monitoring, risk scoring methodology, vendor BAA tracking, workforce training enforcement, incident response orchestration — is a separate product at patient-protect.com.
Spot an error or have a primary-source citation to add? Open an issue or PR. Please cite the regulatory source.
Reference data (glossary, acronyms, identifiers, state-breach-notification, breach-dataset pointer): CC BY 4.0 — Creative Commons Attribution 4.0 International. Use, modify, and redistribute freely with attribution to Patient Protect.
Operational templates (BAA, NPP, IRP, Risk Analysis Questionnaire): CC0 1.0 — dedicated to the public domain. No attribution required. Executed instances of the templates carry no obligation back to Patient Protect. Adapt, redistribute, and sign freely.
Maintained by Patient Protect LLC, Chicago IL. Founded 2015.