HIPAA BinderGet my forms

HIPAA binder template: exactly what goes in it (2026)

A HIPAA binder is a private practice’s complete set of required compliance documents: a covered-entity determination, Notice of Privacy Practices with patient acknowledgment, Business Associate Agreements with a vendor register, a Security Risk Analysis, written privacy and security policies with training and sanctions records, breach notification procedures with a log, and patient-rights and authorization forms.

Researched and written by Larry Osakwe · Last verified July 15, 2026

Checked against the current 45 CFR text. Not a lawyer, not a certified compliance professional, and not affiliated with HHS.

How we research thisReport an error

What goes in a HIPAA binder?

Nine documents. This is the annotated table of contents of the binder we actually build and deliver, each entry mapped to the rule that requires it, so you can verify any of it against the regulation.

#DocumentWhat it doesGoverning rule
01Covered-entity determination memoWalks the electronic-transactions test for your billing setup and records the conclusion, so you can show why HIPAA applies (or doesn't) to your practice.45 CFR § 160.103
02Notice of Privacy Practices (print-ready)The notice you must give patients, post in your office, and publish on your website, describing their rights and how you use their information.45 CFR § 164.520
03NPP plain-language summary + acknowledgment of receiptThe form documenting your good-faith effort to obtain each patient's written acknowledgment that they received the notice.45 CFR § 164.520(c)(2)
04Privacy Official & Security Official designationNames the person responsible for your privacy policies and the person responsible for security, in writing; in a small practice both are usually the owner.45 CFR § 164.530(a); § 164.308(a)(2)
05Business Associate Agreement template + vendor registerThe contract every vendor that touches patient data must sign (EHR, billing, email, cloud, AI notetaker), plus a register tracking which BAAs are on file.45 CFR § 164.502(e); § 164.504(e)
06Security Risk Analysis workbookThe documented, accurate and thorough assessment of risks to your electronic patient data: the single most-cited deficiency in OCR enforcement.45 CFR § 164.308(a)(1)(ii)(A)
07Privacy & security policies and proceduresYour written rulebook for access, minimum-necessary use, safeguards, workforce training (with a training log), and a sanctions policy for violations.45 CFR § 164.530(b), (e); § 164.308(a)(5); § 164.316
08Breach notification procedure + breach logWhat to do when something goes wrong: the federal deadlines (notification without unreasonable delay, at most 60 days), plus your state's breach statute answered specifically.45 CFR §§ 164.400–414
09Patient-rights & authorization forms (print-ready)Request forms for access, amendment, accounting of disclosures, and restrictions, plus the authorization form for uses that require written permission.45 CFR §§ 164.508, 164.522, 164.524, 164.526, 164.528

Want to see the finished documents rather than a list? See a sample of the actual binder →

The HIPAA binder checklist

Print this section and check items off as your binder comes together. If every box is checked, you have the document set an auditor, a payer, or a nervous patient would ask for.

  • Covered-entity determination for your billing setup, in writing
  • Notice of Privacy Practices: given to patients, posted in the office, published on your site
  • Patient acknowledgment-of-receipt forms, filed
  • Privacy Official and Security Official designated in writing
  • Signed BAA on file for every vendor touching patient data, tracked in a vendor register
  • Security Risk Analysis completed, documented, and reviewed at least annually
  • Written privacy and security policies adopted and dated
  • Workforce training completed and logged; sanctions policy adopted
  • Breach notification procedure (federal + your state statute) and an empty breach log, ready
  • Patient-rights request forms and authorization forms, print-ready
  • Everything above retained for six years from creation or last effective date

Prefer the therapist-specific walkthrough? See the private-practice compliance checklist or take the free 2-minute gap check.

Do you need a binder or compliance software?

For a practice under roughly ten employees, a maintained document set plus an annual review is the proportionate answer. Every requirement in the table above is satisfied by a written document you adopt, follow, and keep current; nothing in the Privacy Rule, Security Rule, or Breach Notification Rule requires a software subscription. What the rules require is documentation that exists, matches what you actually do, and can be produced on request.

Compliance software earns its subscription by solving coordination problems: pushing policies to dozens of employees, chasing training completions across departments, tracking hundreds of vendor agreements, producing audit dashboards for a compliance officer. Those are real problems, at enterprise scale. A solo therapist or a three-person dental office doesn’t have them, and paying a recurring fee doesn’t change which documents you need or who is responsible for them (you, either way).

The honest tradeoff: a binder is cheaper and simpler but only as current as its last review, so put the annual review on your calendar and update documents when a cited rule or your practice changes. If you grow past the point where one owner can know every vendor and train every hire personally, that’s the signal to consider software. Until then, the subscription mostly buys you a login for problems you don’t have yet.

The longer version, with a row-by-row comparison and a defensible recommendation, is on the HIPAA compliance software alternative page. Only need the notice? See the NPP Generator alternative. New to the terms? Start with the HIPAA glossary.

Made to order · Founding pricing: first 25 practices

Lock in founding pricing

Every document is made to order at locked-in founding pricing, built from your practice details and delivered within 30 days, with a full refund anytime before then. Each binder is built by hand, so founding pricing is limited to the first 25 practices; after that the Complete Binder is $249. Preview any document free before you decide.

Single document
$49one-time

Founding price · $79 after the first 25 practices

Just the one document you need, built for your practice.
Choose your document

Instant: answer a short wizard, watch your document fill in live, and unlock the files for the same $49.

  • Built for your practice: profession, state, and billing setup shape every clause
  • Every policy cites the regulation that requires it
  • Editable Word + annotated PDF
  • See your finished notice before you pay
  • Instant download after checkout
The Complete Binder
Most complete
$129one-time

Founding price · $249 after the first 25 practices

Every HIPAA document a private practice needs, in one place.
  • Notice of Privacy Practices (current rules)
  • Covered-entity determination for your billing setup
  • BAA template + filled vendor table for your actual stack
  • Security Risk Analysis workbook + full policy set
  • Breach procedure: federal + your state's statute
  • Print-ready patient forms, annotated PDF, editable Word
  • Free revisions for 30 days after delivery
Binder + Always-Current
Stays current
$129+ $99/yr after 30 days

Founding price · $249 after the first 25 practices

The full binder, plus an annual refresh that keeps it current.
  • Everything in the Complete Binder
  • When a cited rule changes, we update the affected documents and send them to you
  • Every update comes with a note: what changed, why, and the citation
  • Annual refresh: every citation in your binder re-verified
  • Annual risk-assessment and training reminders
  • BAA tracker for your vendors
  • First year of updates starts 30 days after your order
  • Cancel anytime, the binder is yours

Opening a dental office? HIPAA + OSHA Binder Bundle: $299 $328 separately

Add the OSHA binder: exposure control plan, hazard communication, sharps and training documentation, every policy citing the regulation that requires it.

Founding price · $449 after the first 25 practices

Order both binders

Your documents are built to order and delivered within 30 days, with a full refund anytime before delivery. The subscription then keeps every document current as HIPAA rules change and reminds you when your annual risk assessment is due. Cancel anytime.

HIPAA binder FAQ

The binder, organized for your profession

The same nine documents, prepared around your field’s records, vendors, and covered-entity nuances. Not sure HIPAA even applies to you? Start with the covered-entity test by profession.

Prefer the question answered directly? Do I need HIPAA forms for a dental office, a physical therapy clinic, an eye care practice, or a chiropractic clinic?

Sources

Last verified July 15, 2026. Educational self-help information about HIPAA documentation, not legal advice. A binder is a document layer; it never handles patient information (PHI) and does not by itself make a practice HIPAA compliant. Whether HIPAA applies to your practice depends on the covered-entity test; confirm your status with HHS/CMS resources and, where appropriate, a qualified attorney. State law may add stronger requirements.