HIPAA binder template: exactly what goes in it (2026)
A HIPAA binder is a private practice’s complete set of required compliance documents: a covered-entity determination, Notice of Privacy Practices with patient acknowledgment, Business Associate Agreements with a vendor register, a Security Risk Analysis, written privacy and security policies with training and sanctions records, breach notification procedures with a log, and patient-rights and authorization forms.
Researched and written by Larry Osakwe · Last verified July 15, 2026
Checked against the current 45 CFR text. Not a lawyer, not a certified compliance professional, and not affiliated with HHS.
What goes in a HIPAA binder?
Nine documents. This is the annotated table of contents of the binder we actually build and deliver, each entry mapped to the rule that requires it, so you can verify any of it against the regulation.
| # | Document | What it does | Governing rule |
|---|---|---|---|
| 01 | Covered-entity determination memo | Walks the electronic-transactions test for your billing setup and records the conclusion, so you can show why HIPAA applies (or doesn't) to your practice. | 45 CFR § 160.103 |
| 02 | Notice of Privacy Practices (print-ready) | The notice you must give patients, post in your office, and publish on your website, describing their rights and how you use their information. | 45 CFR § 164.520 |
| 03 | NPP plain-language summary + acknowledgment of receipt | The form documenting your good-faith effort to obtain each patient's written acknowledgment that they received the notice. | 45 CFR § 164.520(c)(2) |
| 04 | Privacy Official & Security Official designation | Names the person responsible for your privacy policies and the person responsible for security, in writing; in a small practice both are usually the owner. | 45 CFR § 164.530(a); § 164.308(a)(2) |
| 05 | Business Associate Agreement template + vendor register | The contract every vendor that touches patient data must sign (EHR, billing, email, cloud, AI notetaker), plus a register tracking which BAAs are on file. | 45 CFR § 164.502(e); § 164.504(e) |
| 06 | Security Risk Analysis workbook | The documented, accurate and thorough assessment of risks to your electronic patient data: the single most-cited deficiency in OCR enforcement. | 45 CFR § 164.308(a)(1)(ii)(A) |
| 07 | Privacy & security policies and procedures | Your written rulebook for access, minimum-necessary use, safeguards, workforce training (with a training log), and a sanctions policy for violations. | 45 CFR § 164.530(b), (e); § 164.308(a)(5); § 164.316 |
| 08 | Breach notification procedure + breach log | What to do when something goes wrong: the federal deadlines (notification without unreasonable delay, at most 60 days), plus your state's breach statute answered specifically. | 45 CFR §§ 164.400–414 |
| 09 | Patient-rights & authorization forms (print-ready) | Request forms for access, amendment, accounting of disclosures, and restrictions, plus the authorization form for uses that require written permission. | 45 CFR §§ 164.508, 164.522, 164.524, 164.526, 164.528 |
Want to see the finished documents rather than a list? See a sample of the actual binder →
The HIPAA binder checklist
Print this section and check items off as your binder comes together. If every box is checked, you have the document set an auditor, a payer, or a nervous patient would ask for.
- Covered-entity determination for your billing setup, in writing
- Notice of Privacy Practices: given to patients, posted in the office, published on your site
- Patient acknowledgment-of-receipt forms, filed
- Privacy Official and Security Official designated in writing
- Signed BAA on file for every vendor touching patient data, tracked in a vendor register
- Security Risk Analysis completed, documented, and reviewed at least annually
- Written privacy and security policies adopted and dated
- Workforce training completed and logged; sanctions policy adopted
- Breach notification procedure (federal + your state statute) and an empty breach log, ready
- Patient-rights request forms and authorization forms, print-ready
- Everything above retained for six years from creation or last effective date
Prefer the therapist-specific walkthrough? See the private-practice compliance checklist or take the free 2-minute gap check.
Do you need a binder or compliance software?
For a practice under roughly ten employees, a maintained document set plus an annual review is the proportionate answer. Every requirement in the table above is satisfied by a written document you adopt, follow, and keep current; nothing in the Privacy Rule, Security Rule, or Breach Notification Rule requires a software subscription. What the rules require is documentation that exists, matches what you actually do, and can be produced on request.
Compliance software earns its subscription by solving coordination problems: pushing policies to dozens of employees, chasing training completions across departments, tracking hundreds of vendor agreements, producing audit dashboards for a compliance officer. Those are real problems, at enterprise scale. A solo therapist or a three-person dental office doesn’t have them, and paying a recurring fee doesn’t change which documents you need or who is responsible for them (you, either way).
The honest tradeoff: a binder is cheaper and simpler but only as current as its last review, so put the annual review on your calendar and update documents when a cited rule or your practice changes. If you grow past the point where one owner can know every vendor and train every hire personally, that’s the signal to consider software. Until then, the subscription mostly buys you a login for problems you don’t have yet.
The longer version, with a row-by-row comparison and a defensible recommendation, is on the HIPAA compliance software alternative page. Only need the notice? See the NPP Generator alternative. New to the terms? Start with the HIPAA glossary.
Three ways to get the binder done
The Complete Binder
All nine documents, built to order for your practice, state, and vendor stack. Editable Word + annotated PDF.
Just the NPP
Generate your Notice of Privacy Practices now and see the finished notice before you pay.
See a sample first
Real excerpts from a delivered binder, citations included, so you know exactly what you’re buying.
Lock in founding pricing
Every document is made to order at locked-in founding pricing, built from your practice details and delivered within 30 days, with a full refund anytime before then. Each binder is built by hand, so founding pricing is limited to the first 25 practices; after that the Complete Binder is $249. Preview any document free before you decide.
Opening a dental office? HIPAA + OSHA Binder Bundle: $299 $328 separately
Add the OSHA binder: exposure control plan, hazard communication, sharps and training documentation, every policy citing the regulation that requires it.
Founding price · $449 after the first 25 practices
Your documents are built to order and delivered within 30 days, with a full refund anytime before delivery. The subscription then keeps every document current as HIPAA rules change and reminds you when your annual risk assessment is due. Cancel anytime.
HIPAA binder FAQ
The binder, organized for your profession
The same nine documents, prepared around your field’s records, vendors, and covered-entity nuances. Not sure HIPAA even applies to you? Start with the covered-entity test by profession.
Prefer the question answered directly? Do I need HIPAA forms for a dental office, a physical therapy clinic, an eye care practice, or a chiropractic clinic?
Sources
- www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164
- www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160
- www.hhs.gov/hipaa/for-professionals/covered-entities/index.html
Last verified July 15, 2026. Educational self-help information about HIPAA documentation, not legal advice. A binder is a document layer; it never handles patient information (PHI) and does not by itself make a practice HIPAA compliant. Whether HIPAA applies to your practice depends on the covered-entity test; confirm your status with HHS/CMS resources and, where appropriate, a qualified attorney. State law may add stronger requirements.