Looks good so far and I understand how painful HIPPA can be. I would add:
Technical considerations
Physical Security
Data at Rest
Data in Motion
Detection
+ Loss Prevention
+ Data Accountability
+ Data Classification
Keep up the good work and thanks for sharing your project template.
Slimjim100