Skip to content

Repository files navigation

hipaa-toolkit

Open reference data for HIPAA compliance work — published by Patient Protect.

This repository contains structured, citable reference data:

  • HIPAA Glossary — 203 terms with definitions, source citations, and cross-references
  • HIPAA Acronyms — 40+ acronyms organized by category
  • 18 PHI Identifiers — the canonical Safe Harbor list (45 CFR §164.514) plus modern extensions
  • 50-State Breach Notification — quick reference for state-law deadlines, AG thresholds, and stricter-than-HIPAA states
  • Breach Dataset — pointer to the live CC BY 4.0 healthcare breach dataset at patient-protect.com
  • Templates — open BAA, Notice of Privacy Practices, Incident Response Plan, and Risk Analysis Questionnaire

Most data in this repository is licensed CC BY 4.0 — free to use, modify, and redistribute with attribution. The four operational templates in templates/ are dedicated to the public domain under CC0 1.0, so a practice that executes them as a signed instrument carries no attribution obligation inside the document itself. Per-directory LICENSE files govern each subtree; see the License by directory table below.

Two-layer note on the glossary: the definitions, regulatory citations, and cross-references shipped as CSV and JSON in glossary/ are CC BY 4.0. The same underlying data powers the live rendering at patient-protect.com/hipaa-glossary under the same license; the page's UX, layout, and DefinedTermSet schema wrapper are proprietary to Patient Protect LLC.

Why this exists

Healthcare practices, researchers, journalists, and AI search engines need reliable HIPAA reference data. This toolkit makes the data we maintain for patient-protect.com and /hipaa-glossary available as structured files anyone can fork, query, or cite.

What's here

Folder Contents Formats
glossary/ 203 HIPAA terms with definitions, regulatory citations, and cross-references CSV, JSON
acronyms/ HIPAA acronyms by category — regulatory, entity, technical, enforcement JSON
identifiers/ 18 PHI identifiers (Safe Harbor de-identification) + modern data categories JSON
state-breach-notification/ 50 states + DC notification deadlines, statutes, AG thresholds JSON
breach-dataset/ Pointer to the live /api/breach-data dataset endpoint README
templates/ BAA, NPP, Incident Response Plan, and Risk Analysis Questionnaire templates Markdown

License by directory

Path License Reason
glossary/ CC BY 4.0 Attribution keeps citation chains intact for research and press use
acronyms/ CC BY 4.0 Same
identifiers/ CC BY 4.0 Same
state-breach-notification/ CC BY 4.0 Same
breach-dataset/ CC BY 4.0 Pointer to the live dataset which is itself CC BY 4.0
templates/ CC0 1.0 Operational forms meant to be executed as signed instruments — attribution inside a signed contract is awkward and unenforceable. Public domain removes that friction.

How to cite

Patient Protect. HIPAA Toolkit. Patient Protect LLC.
https://patient-protect.com  (or this repository URL)

If you build something useful with this data, we'd love to hear about it.

Update cadence

  • Glossary, acronyms, identifiers: updated as HIPAA regulations or HHS guidance changes (typically quarterly)
  • State breach notification: cross-referenced against NCSL annually
  • Breach dataset: continuously updated via the live API endpoint

What's NOT in this repo

This toolkit is reference data only. Patient Protect's compliance platform — active monitoring, risk scoring methodology, vendor BAA tracking, workforce training enforcement, incident response orchestration — is a separate product at patient-protect.com.

Contributing

Spot an error or have a primary-source citation to add? Open an issue or PR. Please cite the regulatory source.

License

Reference data (glossary, acronyms, identifiers, state-breach-notification, breach-dataset pointer): CC BY 4.0 — Creative Commons Attribution 4.0 International. Use, modify, and redistribute freely with attribution to Patient Protect.

Operational templates (BAA, NPP, IRP, Risk Analysis Questionnaire): CC0 1.0 — dedicated to the public domain. No attribution required. Executed instances of the templates carry no obligation back to Patient Protect. Adapt, redistribute, and sign freely.


Maintained by Patient Protect LLC, Chicago IL. Founded 2015.

About

Open HIPAA reference data — 203-term glossary, 40+ acronyms, 18 PHI identifiers, 50-state breach notification quick reference, and healthcare breach dataset. CC BY 4.0.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors