← HomeNot Legal Advice
HIPAA Policy Engine is software that generates HIPAA policy templates from a practice profile you provide. We are not a law firm. We do not provide legal advice. Using our service does not create an attorney-client relationship between you and the company, its founders, employees, or contractors.
What this means
- The policies we generate are starting points reflecting current federal regulations and common practice. They are not guaranteed to satisfy every applicable law or every enforcement interpretation.
- State laws (and, where applicable, 42 CFR Part 2 for SUD providers) may impose additional requirements not addressed in the generated policies. We surface common state and Part 2 considerations but we do not provide jurisdiction-specific legal analysis.
- Before you adopt any policy, we strongly recommend you have a healthcare attorney licensed in your state review the policy set. We do not represent you and cannot give you that review.
- If you receive a subpoena, breach inquiry, OCR complaint, or any other legal process, do not rely on this software in lieu of qualified counsel. Engage a healthcare attorney.
What we do
- We generate policy templates tailored to the profile you provide.
- We track template versions and notify you when a template changes.
- We record your adoption (attestation, signature, IP, timestamp) for your records.
- We preserve superseded versions so you have a continuous audit trail.
What we don't do
- We don't store any PHI. We don't ingest patient records of any kind.
- We don't submit anything to OCR, HHS, or any state regulator on your behalf.
- We don't perform your risk analysis for you, although our Risk Analysis Policy describes how to perform one.
- We don't represent you in any legal matter.