Free tools for compliance and privacy teams.
Twelve tools for health systems, provider networks, and health-tech teams, built from primary regulatory sources. Everything runs in your browser, and nothing you enter is transmitted or stored unless a card says otherwise.
Score real risk
Run a structured assessment and get back a scored, prioritized gap summary.
Breach Notification Risk Assessment
Three modules (HIPAA, CMIA/HSC §1280.15, Civil Code §1798.82) with rationale, citations, and draft notification letters, plus an HHS OCR Breach Portal worksheet and a 50-state reference table.
- Output
- Risk call + draft letters
- Data
- Stays in your browser
- Source
- HIPAA · CMIA · Civ. Code §1798.82
Seven Elements Self-Scoring
Score your program against the OIG's seven elements from the 2023 General Compliance Program Guidance. Feeds a color-banded scorecard and a gap summary you can copy or print.
- Output
- Maturity scorecard
- Data
- Stays in your browser
- Source
- OIG GCPG 2023, 7 elements
AI Risk Assessment
Assess ambient scribes, AI coding tools, and LLM products across BAA terms, de-identification, §1557 and Colorado AI Act nondiscrimination, clinical rules, AKS/Stark, research, and records.
- Output
- 81-item gap checklist
- Data
- Stays in your browser
- Source
- 45 CFR 164.514 · §1557 · AKS/Stark
Employment AI Risk Assessment
Resume screeners, video-interview scorers, and monitoring tools tested against Title VII, ADA, ADEA, EEOC vendor liability, NYC LL144, the Illinois AI Video Interview Act, and the Colorado AI Act.
- Output
- 24-item gap checklist
- Data
- Stays in your browser
- Source
- Title VII · ADA · NYC LL144 · CO AI Act
Work the regulation, section by section
Work through the regulation text item by item, check off what's in place, and copy a gap summary. Progress saves in your browser.
HIPAA Security Rule Checklist
Covers the current Security Rule (45 CFR §§164.308–316) alongside HHS's 2025 NPRM cybersecurity changes. Filter to today's obligations, the proposed rule, or both.
- Output
- 79-item gap checklist
- Data
- Stays in your browser
- Source
- 45 CFR §§164.308–316 + 2025 NPRM
HIPAA Privacy Rule Checklist
Uses and disclosures, individual rights, the Notice of Privacy Practices, business associates, and administrative requirements, with status flags for the 2024 reproductive-health amendments after Purl v. HHS.
- Output
- 78-item gap checklist
- Data
- Stays in your browser
- Source
- 45 CFR Part 164, Subpart E
Part 2 Alignment Checklist
Aligns substance use disorder record handling with the 2024 Part 2 final rule: consent, redisclosure, counseling notes, and breach notification, with separate program/recipient views.
- Output
- 50-item gap checklist
- Data
- Stays in your browser
- Source
- 42 CFR Part 2, 2024 final rule
California Health Privacy Checklist
Layers California on top of the HIPAA baseline: CMIA authorizations, the AB 352/AB 254 sensitive-services and digital-health rules, and state breach clocks that run faster than the federal one.
- Output
- 44-item gap checklist
- Data
- Stays in your browser
- Source
- CMIA + AB 352/254
Multi-State Consumer Health Data Checklist
The health privacy laws that reach past HIPAA: Washington's My Health My Data Act, Nevada SB 370, and the Connecticut Data Privacy Act. In all three the HIPAA exemption is data-level, not entity-level.
- Output
- 45-item gap checklist
- Data
- Stays in your browser
- Source
- WA MHMDA · NV SB 370 · CT DPA
Screen people, watch enforcement
Screen against exclusion lists or explore active enforcement settlements.
Exclusion & Sanctions Screening Tracker
Screen staff, clinicians, contractors, and vendors against the OIG exclusion list (LEIE) and the Medi-Cal Suspended and Ineligible list. Upload a roster or check one name, with recheck reminders on the OIG cadence.
- Output
- Screening results + reminders
- Data
- LEIE matched locally; Medi-Cal checked live via the CHHS API
- Source
- OIG LEIE data as of Jul 2026
Corporate Integrity Agreements Dashboard
Filter and explore active HHS OIG Corporate Integrity Agreements from 2023–2026: a violation summary, the material obligations each settlement imposes, and a plain read on what it means for your own program.
- Output
- Filterable CIA dashboard
- Data
- No personal data entered
- Source
- Verified against OIG, Aug 2026
Generate a policy library
One intake form, three cited policy libraries.
Compliance & Privacy Policy Builder
Complete one intake form and generate three customized policy libraries: Privacy (HIPAA Privacy, breach notification, California overlays), Security (Security Rule safeguards), and Compliance (OIG seven-elements policies), each cited with a currency status.
- Output
- 3 libraries, 37 print-ready policies
- Data
- Stays in your browser
- Source
- Reviewed per policy, dates on each
More tools on the way
More tools are in development and will appear here as they're ready.
Tools published here draw on publicly available regulatory sources and are provided for general compliance-learning purposes. They are not legal advice. Brandon Goulter is not an attorney, and using these tools creates no professional advisory relationship. Verify current requirements against primary sources and a licensed attorney before acting.