Draft policy wording checks: free pre-scan and optional paid early-access report. Findings need review. Public uploads must contain no patient data or other restricted information.
Draft checks you can use today
Draft policy checks
HIPAA Security
63 checks · +$0.50 per page
US medical and dental covered-entity policies without patient data. Security Rule policy wording only; Privacy and Breach Notification checks are outside this preview.
US scope only. Applicability answers may exclude checks or leave them unresolved.
HIPAA security policyDraft wording checks available
Security policyDraft wording checks available
Risk analysisDraft wording checks available
Incident response planDraft wording checks available
Contingency planDraft wording checks available
Privacy policyResearch document type
Exposure control planResearch document type
Breach response planResearch document type
Scope questions
Industry alone does not establish legal applicability. Confirm location, activities, role, data and relevant thresholds.
Business associates handling ePHI
Does the covered entity use business associates that create, receive, maintain, or transmit ePHI on its behalf? Unknown answers leave vendor requirements unresolved.
Electronic protected health information
Does the organization create, receive, maintain, or transmit ePHI? Answer about the organization; do not upload patient data.
HIPAA covered entity
Is the document owner a HIPAA covered entity, such as a provider that transmits health information electronically in covered standard transactions? This preview supports US medical and dental covered entities; business-associate-only and health-plan scope are not implemented. Do not infer this from industry.
Unknown answers stay unresolved. Document detection does not answer these questions for you.
A fictional example to explore
These sample policies contain intentional gaps. Use them to try the quote and pre-scan flow; they are not adopted policies or complete compliance templates.
PDF pages are counted exactly. DOCX and TXT use the disclosed word-count estimate, so the same policy can have different billable page counts.
Regulations and frameworks to explore
These are research candidates for this profile. Confirm the exact organization and activity before concluding that a rule applies.
Draft policy checks available
HIPAA Security Rule
45 CFR Parts 160 and 164
US medical and dental covered-entity policies without patient data. Security Rule policy wording only; Privacy and Breach Notification checks are outside this preview.
Jurisdictions: US-FEDERAL
Research applicability questions
Does the covered entity use business associates that create, receive, maintain, or transmit ePHI on its behalf? Unknown answers leave vendor requirements unresolved.
Does the organization create, receive, maintain, or transmit ePHI? Answer about the organization; do not upload patient data.
Is the document owner a HIPAA covered entity, such as a provider that transmits health information electronically in covered standard transactions? This preview supports US medical and dental covered entities; business-associate-only and health-plan scope are not implemented. Do not infer this from industry.
An emergency action plan is required when another OSHA standard triggers 29 CFR 1910.38. Confirm the triggering standard and state-plan coverage. A plan must generally be written and available to employees; employers with ten or fewer employees may communicate it orally. Do not infer a written-plan violation solely from the industry label.
Jurisdictions: US-FEDERAL
Research applicability questions
Which OSHA standard requires an emergency action plan for this workplace?
How many employees does the employer have, and does the ten-or-fewer oral-plan exception apply?
Does an OSHA-approved state plan apply, and does it impose different workplace requirements?
What work activities, hazards and other OSHA standards trigger this workplace emergency-plan duty?