For nonprofits outside HIPAA
Privacy compliance for health nonprofits outside HIPAA
Pregnancy centers, free clinics and community health programs that never bill a health plan are often not covered by HIPAA. State privacy and breach laws still apply. Polestar GRC gives you the full program, written around your state's law instead of HIPAA.
14 days free. No card needed to start.
Does HIPAA apply to you?
HIPAA covers health plans, health care clearinghouses, and health care providers that send health information electronically to bill or check coverage with a health plan. A nonprofit that serves clients for free and never bills a health plan this way is often outside HIPAA.
When you set up your workspace, you choose "state privacy law only", and the whole app switches to privacy wording and your state's documents. You can change it later in Organization Settings. If you are not sure which applies, ask your attorney; this page is not legal advice.
State laws that still apply
Breach notice laws
Every state and DC has a data breach law, and many apply to any organization holding personal or health information, nonprofit or not. New York, for example, requires notice to the people affected within 30 days.
Consumer health data laws
Washington's My Health My Data Act was written to reach organizations outside HIPAA, and it covers nonprofits. Nevada has a similar law, and Connecticut's consumer health data rules also apply to nonprofits.
State medical records laws
Some states protect health information whether or not HIPAA applies. California's Confidentiality of Medical Information Act reaches organizations that offer medical services such as ultrasounds or pregnancy tests, even when they are not HIPAA covered. Texas, Maryland and Minnesota have their own records laws too.
Security program rules
Massachusetts requires a written information security program from any organization, nonprofit or not, that holds a resident's Social Security, driver's license or financial account number.
See what applies in your state on our state privacy law pages.
What you get
- Security and privacy risk assessment. Plain yes or no questions, measured against HIPAA-grade controls as a benchmark. A PDF report and a fix list at the end.
- Policies written for your state. Including a Consumer Health Data Privacy Notice and a State Privacy Law Addendum. HIPAA-only documents you do not owe, such as the Notice of Privacy Practices, stay out of your library.
- Vendor data protection agreements. Track the confidentiality and data protection agreement each vendor signs, in place of the HIPAA BAAs your vendors do not owe you.
- Staff and volunteer training. A 5-minute lesson by email each month, and a record of who finished it.
- Breach deadline clock. Log an incident and see your state's notice deadlines.
Nonprofit pricing
Verified 501(c)(3) nonprofits get 50% off every plan, with unlimited users. Until we verify your IRS letter, the regular price applies.
Essentials
$60 a month
Regular price $120 a month. Or $600 a year.
Full SRA, required-standard policies, vendor and BAA tracking
Professional
$125 a month
Regular price $250 a month. Or $1,250 a year.
Adds AI drafting, addressable policies, training courses and audit export
Advanced
$225 a month
Regular price $450 a month. Or $2,250 a year.
Adds the full policy library, AWS evidence checks, Audit Rooms and custom branding
How verification works is on the nonprofit pricing page.
What it does not do
- It does not decide whether HIPAA applies to you. You choose, and you can change it.
- It does not certify you, and it is not legal advice.
Start your privacy program today
Your answers save as you go, so you can stop and come back.
14 days free. No card needed to start.
