Confirm scope first. Open with the §164.502 scope question: is the reader's organization a Covered Entity (health plan, health-care clearinghouse, or a health-care provider that transmits health information electronically) or a Business Associate (a vendor creating, receiving, maintaining, or transmitting PHI on a CE's behalf)? If neither, the Privacy, Security, and Breach Notification Rules do not directly apply. Confirming "we are neither, so HIPAA stops here" early is the cheapest document on the page.
Inventory every system that touches PHI. Per the §164.308(a)(1)(ii)(A) Risk Analysis, the inventory must list every system that creates, receives, maintains, or transmits ePHI, the threats against it, the vulnerabilities those threats exploit, the likelihood of materialization, the impact if it does, and the current controls in place. This document is the most-cited OCR artifact and the first one an inquiry letter or a vendor BAA review opens with.
Run the §164.308(a)(1)(ii)(A) Risk Analysis. The OCR inquiry letter opens here. Document the methodology, the assets in scope, the threats catalogued, the vulnerabilities, the likelihood-and-impact scoring, and the current-control set. A Risk Analysis without a paired Risk Management plan is the single most common OCR resolution-agreement trigger.
Pair the §164.308(a)(1)(ii)(B) Risk Management plan to each finding. For every Risk Analysis finding, name a security measure, an owner, a remediation date, and a verification step. The Risk Management plan is what turns the analysis from a finding list into a remediation commitment the AO can sign against.
Confirm every BA has an executed §164.308(b)(1) BAA, and that any subcontractor touching PHI has a downstream BAA. The BAA inventory is itself the second artifact an inquiry letter and a vendor due-diligence review will ask for. A vendor whose contract has no BAA but whose service touches PHI is the single most common §164.308(b)(1) finding.
Rehearse the §164.402 four-factor breach assessment on a tabletop scenario so the §164.404 individual-notice clock (60 days) and the §164.408 HHS-notice clock (60 days, with the 500-or-more trigger earmarked for the HHS Wall of Shame) are wired before a real incident hits. The four-factor worksheet, the notice templates, and the contact lists for HHS, the media, and the affected individuals are the artifacts a tabletop produces.
Two beginner briefs anchor the entry path: Atlas Health Partners (regional integrated delivery network, post-merger HITRUST foundation and an OCR inquiry letter in the next two quarters) runs the annual risk-assessment walkthrough — re-runs the §164.308(a)(1)(ii)(A) Risk Analysis against the post-merger systems inventory, pairs the §164.308(a)(1)(ii)(B) Risk Management plan to each finding, and confirms the BAA inventory. WovenCart (D2C apparel on Shopify Plus, no direct PHI scope, evaluating a benefits-administration SaaS for its own employees' health-plan enrollment) handles a vendor BAA review — walks the §164.308(b)(1) BAA clauses, flags the vendor's carve-outs, and returns a redline that closes the §164.308(b)(1) gap before the pilot starts.
The laminate for HIPAA reads the same way every primer reads: name the rule, name the CFR citation, name the next concrete artifact. The Privacy, Security, and Breach Notification Rules are the three pillars; the CFR citations point to the subpart; the next concrete artifact is the document that proves the rule has been read.