Using HIPAAList
See how HIPAAList turns readiness questions into organized work.
These product guides show the practical path smaller healthcare teams use: save organization details, add staff, then follow recommended work for documents, vendors, training, evidence, reviews, and exports.
Start here
Set up Profile, add Staff, then follow recommendations
Start with the records HIPAAList needs to make the workspace useful. Those basics turn a blank account into tailored next steps for documents, training, vendors, evidence, and review work.
- 1Save the basic organization details that shape recommendations.
- 2Add staff records for training, acknowledgements, and officer assignments.
- 3Use Dashboard recommendations to choose the next record.
Organization
Organization Profile
Basic organization details that tailor readiness guidance and document placeholders.
How complex is your organization to support?
This helps HIPAAList choose a practical starting path.
Small
SelectedA focused practice or team with simpler operations.
Medium
Several teams or locations with recurring IT work.
Large
Multiple locations, systems, and broader IT ownership.
Services
Staff Roles
Featured product guides
Organization
Organization Profile
Basic organization details that tailor readiness guidance and document placeholders.
How complex is your organization to support?
This helps HIPAAList choose a practical starting path.
Small
SelectedA focused practice or team with simpler operations.
Medium
Several teams or locations with recurring IT work.
Large
Multiple locations, systems, and broader IT ownership.
Services
Staff Roles
Quickstart
6 min readGetting Started with HIPAAList
Start with Organization Profile and Staff, then use Dashboard recommendations to choose the next documents, training, vendors, and evidence work.
Read product guide
Readiness
Dashboard
Current readiness progress, work status, and the next useful records to complete.
Readiness Score
742
+38 this quarter
Work Status
| Readiness Path | Type | Status |
|---|---|---|
Complete Organization Profile Captures facts that tailor next steps and placeholders. | Setup | Complete |
Review EHR / Clinical System Access Confirm access, MFA, roles, and audit routines. | Work | Next Step |
Enable HIPAA Basics Training Prepare structured staff training records. | Training | Recommended |
Workspace
5 min readUsing the Dashboard
Dashboard gives your team a calm, intuitive view of current readiness, recent progress, and the next useful HIPAAList work to complete.
Read product guide
Organization
Documents
Create, edit, approve, and review policies, notices, procedures, and plans.
| Document | Purpose | Status |
|---|---|---|
Access Control Policy Defines how access is requested, approved, reviewed, and removed. | Policy | Approved |
Access & Authentication Policy Defines account, password, MFA, and sign-in expectations. | Policy | Approved |
Security Incident Response Procedure Provides first steps for reporting and assessing incidents. | SOP | Draft |
Documents
6 min readManaging Documents
Documents helps teams start faster with useful drafts, then keep approved versions, acknowledgements, review cadence, and history organized.
Read product guide

Courses
Structured training, sends, schedules, and completion records.
Open Courses

Reminders
Reminder Schedule, awareness topics, sends, and acknowledgement records.
Open Reminders
HIPAA Basics Training
Course schedule and staff completion status.
| Staff | Status | Last Activity |
|---|---|---|
| Morgan Lee | Complete | May 20, 2026 |
| Jamie Patel | Sent | May 24, 2026 |
| Riley Morgan | Not sent | - |
Training
5 min readManaging Training
Training separates structured courses from ongoing reminders so staff education, sends, and acknowledgements stay easy to manage.
Read product guide
Start Here
The first workspace path: add organization details, add staff, then follow recommended work.
Workspace Basics
Core pages for seeing progress, finding the next step, and getting help in context.
Readiness
Dashboard
Current readiness progress, work status, and the next useful records to complete.
Readiness Score
742
+38 this quarter
Work Status
| Readiness Path | Type | Status |
|---|---|---|
Complete Organization Profile Captures facts that tailor next steps and placeholders. | Setup | Complete |
Review EHR / Clinical System Access Confirm access, MFA, roles, and audit routines. | Work | Next Step |
Enable HIPAA Basics Training Prepare structured staff training records. | Training | Recommended |
Workspace
5 min readUsing the Dashboard
Dashboard gives your team a calm, intuitive view of current readiness, recent progress, and the next useful HIPAAList work to complete.
Read product guide
Assistant
HIPAAList Assistant
Workspace-aware help for product questions and practical next steps. Do not enter PHI.
Assistant
5 min readUsing the Assistant
Assistant helps users understand saved organization context, find the next useful step, and navigate HIPAAList without losing momentum.
Read product guide
Organization Records
Organization facts, staff, documents, vendors, and recommended work that make next steps feel specific and actionable.
Organization
Organization Profile
Basic organization details that tailor readiness guidance and document placeholders.
How complex is your organization to support?
This helps HIPAAList choose a practical starting path.
Small
SelectedA focused practice or team with simpler operations.
Medium
Several teams or locations with recurring IT work.
Large
Multiple locations, systems, and broader IT ownership.
Services
Staff Roles
Organization
5 min readSetting Up Your Organization Profile
Organization Profile is where HIPAAList learns and keeps current the facts that shape documents, staff roles, officer assignments, and recommendations.
Read product guide
Staff
Staff
Manage workforce members, roles, permissions, and invitation status.
| Name | Staff Roles | Invitation | Permissions |
|---|---|---|---|
| Morgan Lee | Provider, Privacy Officer | Joined | Admin |
| Taylor Chen | IT Support, Security Officer | Joined | Admin |
| Jamie Patel | Front Desk | Invited | Member |
| Riley Morgan | Billing | Not invited | Member |
Organization
5 min readManaging Staff Records
Staff records make invitations, roles, acknowledgements, training, officer assignments, and audit history easier to manage from one place.
Read product guide
Organization
Recommended Work
Review work recommended from your Organization Profile.

EHR / Clinical System Access
Accounts, permissions, authentication, and review routines for clinical systems.

Workforce Access
Access approvals, role changes, removals, and staff security practices.

Vendors & Business Associates
Outside services, BAA follow-up, and vendor review records.
Confirm MFA is enabled: configuration proof collected
May 27, 2026
Confirm unique user accounts are used: active shared-login risk remains
May 27, 2026
Recommended Work
7 min readWorking with Recommended Work and Actions
Recommended work turns broad HIPAA readiness needs into concrete Actions, Documents, and Vendor follow-up tied to the systems your organization actually uses.
Read product guide
Organization
Documents
Create, edit, approve, and review policies, notices, procedures, and plans.
| Document | Purpose | Status |
|---|---|---|
Access Control Policy Defines how access is requested, approved, reviewed, and removed. | Policy | Approved |
Access & Authentication Policy Defines account, password, MFA, and sign-in expectations. | Policy | Approved |
Security Incident Response Procedure Provides first steps for reporting and assessing incidents. | SOP | Draft |
Documents
6 min readManaging Documents
Documents helps teams start faster with useful drafts, then keep approved versions, acknowledgements, review cadence, and history organized.
Read product guide
Organization
Vendors
Track outside services, PHI access, BAA status, and follow-up.
| Vendor | Service | BAA Status | Review |
|---|---|---|---|
| Cloud EHR Vendor | EHR hosting and support | BAA on file | May 2027 |
| Billing Service | Claims and payment processing | BAA on file | Review due |
| Secure Email Provider | Encrypted email | In progress | July 2026 |
Vendors
5 min readManaging Vendors and BAAs
Vendors keeps outside services, business associate status, BAA records, notes, and reviews simple to track.
Read product guide
Follow-through
Evidence, risk follow-up, training, SRA, and export workflows that turn everyday work into durable readiness progress.
Confirm unique user accounts are used
Needs WorkVerify that every workforce member who can reach patient information signs in with an individual account, not a shared login.

Complete
Evidence is in place and no active risks remain.
Needs Work
Track active risk and follow-up plan.
Not Applicable
Document why this action does not apply.
Confirmation note: confirming
May 27, 2026, 11:59 AM
Critical Shared or generic login is still in use: One or more workforce members may be using a shared account, making activity harder to trace and access harder to remove when roles change.
Actions
6 min readAdding Evidence and Risks
Action evidence and risks help HIPAAList clearly separate documented progress from follow-up that still needs attention.
Read product guide

Security Risk Assessment
Built from the HHS/OCR Security Risk Assessment Tool. HIPAAList helps organize answers, related work, and risk follow-up.
Autosaved May 27, 2026, 3:54 PM
Questions Answered
2 / 126
2% answered
Current Risks
1
Open follow-up
Resolved Risks
1
Risk history
Questions
Has your practice completed a security risk assessment (SRA) before?
Suggested Suggested because no saved SRA version exists yet.
Do you review and update your SRA?
Suggested Suggested because SRA review is part of this HIPAAList workflow.
Do you include all information systems containing, processing, and/or transmitting ePHI in your SRA?
SRA
7 min readCompleting the Security Risk Assessment
The SRA page turns the HHS/OCR SRA workbook into a guided questionnaire that becomes easier to complete as HIPAAList records improve.
Read product guide

Courses
Structured training, sends, schedules, and completion records.
Open Courses

Reminders
Reminder Schedule, awareness topics, sends, and acknowledgement records.
Open Reminders
HIPAA Basics Training
Course schedule and staff completion status.
| Staff | Status | Last Activity |
|---|---|---|
| Morgan Lee | Complete | May 20, 2026 |
| Jamie Patel | Sent | May 24, 2026 |
| Riley Morgan | Not sent | - |
Training
5 min readManaging Training
Training separates structured courses from ongoing reminders so staff education, sends, and acknowledgements stay easy to manage.
Read product guide

Export
Audit-support export
Download a ZIP package with records, reports, documents, clean evidence files, and risk history.
Recent exports
| Export | Status | Created |
|---|---|---|
| May readiness package | Ready | May 27, 2026 |
| April review package | Ready | Apr 30, 2026 |
Export
4 min readDownloading an Export
Export turns connected HIPAAList records into one organized ZIP package for review, portability, and audit-support preparation.
Read product guide
Updates
What's New
Recent product updates and improvements that make HIPAAList easier, clearer, and more useful over time.
Read product updates
