HIPAA compliance checklist
32 items, grouped in the order it makes sense to do them, each with the evidence that actually proves it. Written for a small practice, billing company or healthcare vendor with no compliance officer.
No email required, no download gate. Citations are to 45 CFR Part 164 so you can check anything against the regulation itself. Last reviewed .
Read the evidence column, not just the task column
Almost every organization that fails a client security review has done most of the tasks. What it cannot produce is dated proof that it did them. “We train our staff” invites a follow-up question; a list of certificates with names and dates ends the thread. Treat the right-hand column as the actual deliverable.
1. Establish what you are and what you hold
Half the confusion in small organizations comes from never settling this. Your obligations differ depending on whether you are a covered entity or a business associate, and you cannot protect information you have not located.
Determine whether you are a covered entity or a business associate
Evidence: A written note of the determination and the reasoning behind it
Inventory every system, device and vendor that touches patient information
Evidence: A dated list, including the tools nobody officially approved
Appoint someone accountable for security, and someone for privacy
Evidence: A named person in writing — it can be the same person in a small organization
164.308(a)(2), 164.530(a)
2. Conduct and document a risk analysis
This is the single most commonly cited failure in enforcement actions, usually because it was never done or was done once and never revisited. It is required, it is not optional, and the documentation is the deliverable.
Assess risks to the confidentiality, integrity and availability of the patient information you hold
Evidence: A dated risk analysis covering every system on your inventory
164.308(a)(1)(ii)(A)
Record decisions on addressable specifications you chose not to implement
Evidence: Written reasoning plus the alternative control you put in place instead
164.306(d)
Turn every gap into a task with an owner and a due date
Evidence: A remediation log showing what closed, when, and with what proof
164.308(a)(1)(ii)(B)
Repeat the analysis annually and whenever something material changes
Evidence: Consecutive dated analyses showing what changed year to year
3. Write policies people can actually follow
A hundred-page policy pack cloned from a hospital is worse than a short one your staff follow, because the gap between what you wrote and what you do is exactly what an investigator examines.
Adopt written security and privacy policies covering your real workflows
Evidence: Versioned policy documents with publication dates
164.316(a)
Have every workforce member read and acknowledge them
Evidence: Acknowledgement records naming the person, the version and the date
Write a sanction policy for workforce members who violate them
Evidence: The policy, plus records of any sanctions actually applied
164.308(a)(1)(ii)(C)
Retain documentation for six years from creation or last effective date
Evidence: A retention schedule you can demonstrate you follow
164.316(b)(2)(i)
4. Train the workforce, and prove it
Training is required, and the evidence that matters is per person and dated. A group session with no attendance record proves nothing a year later.
Train all workforce members on your policies and procedures
Evidence: A dated certificate per person, not a signed attendance sheet
164.530(b)
Train new starters before they get access to patient information
Evidence: Completion dates that precede their access grant dates
Refresh training periodically and after material changes
Evidence: A renewal schedule with completion dates against it
Run security reminders between formal sessions
Evidence: Records of the reminders sent
164.308(a)(5)(ii)(A)
5. Get agreements with everyone downstream
The gap here is rarely the obvious vendor. It is the storage account someone set up, the fax service, the scheduler on the website and the contractor who has admin access.
Sign a business associate agreement with every vendor that touches patient information
Evidence: Executed agreements, with dates, filed somewhere findable
164.502(e), 164.308(b)(1)
Confirm the vendor's agreement actually covers the products you use
Evidence: The vendor's own covered-services documentation alongside the agreement
If you are a business associate, get agreements with your own subcontractors
Evidence: Executed downstream agreements
164.502(e)(1)(ii)
Track expiry and review dates so none lapse quietly
Evidence: A register with owners and dates
6. Control access technically
This is the part most small organizations assume their IT provider handles. Ask them directly, because 'we use a good firewall' is not an answer to any of these.
Give every user a unique identifier — no shared logins
Evidence: A user list with no generic accounts on it
164.312(a)(2)(i)
Enforce multi-factor authentication on systems holding patient information
Evidence: A configuration export showing enforcement, not a policy saying so
Remove access promptly when someone leaves
Evidence: Termination dates matched against access-revocation dates
164.308(a)(3)(ii)(C)
Enable audit logging and actually review it
Evidence: Logs plus a record that someone looked at them
164.312(b)
Encrypt patient information in transit and at rest where reasonable
Evidence: Configuration evidence, and written reasoning where you did not
164.312(a)(2)(iv), 164.312(e)(2)(ii)
Have tested backups you can actually restore from
Evidence: A restore test with a date on it
164.308(a)(7)
7. Be ready for the incident
Most incidents are small and never become reportable breaches. The record showing you assessed them properly is what turns an incident into a non-event rather than a finding.
Write an incident response procedure staff can follow at 4pm on a Friday
Evidence: The procedure, plus evidence staff know where it is
164.308(a)(6)
Log every security incident, including the ones that turned out fine
Evidence: An incident log with dates, assessments and outcomes
Run the four-factor risk assessment on any impermissible use or disclosure
Evidence: Written analysis of all four factors and the conclusion reached
164.402
Know your notification obligations before you need them
Evidence: Deadlines and recipients documented in the procedure
164.400–414
8. Keep it alive
Compliance decays. An organization that did everything on this list two years ago and nothing since is in a worse position than one that has been muddling along and documenting it.
Review the whole programme annually
Evidence: A dated review record
164.306(e)
Reassess when you adopt a new system or change how you work
Evidence: Assessment records tied to specific changes
Keep an evidence pack current enough to send on request
Evidence: A dated export you could hand over this week
The list is the easy part. The evidence is the work.
Our platform runs the assessment, turns each gap into a task with an owner and a date, holds the policies and certificates, tracks the agreements, and exports the whole thing as a dated pack when a client asks. 14 days free, no credit card.
Common questions
- What are HIPAA compliance requirements?
- In practice: conduct and document a security risk analysis, implement administrative, physical and technical safeguards, adopt written policies and train your workforce on them, sign business associate agreements with vendors that touch patient information, keep an incident log with breach notification procedures, and retain the documentation for six years. The checklist above breaks each into concrete items with the evidence that proves it. There is no official government checklist and no body that certifies completion.
- What are the 5 basic rules of HIPAA?
- The Privacy Rule, governing how protected health information may be used and disclosed; the Security Rule, requiring safeguards for electronic PHI; the Breach Notification Rule, saying who must be told when something goes wrong; the Enforcement Rule, covering investigations and penalties; and the Omnibus Rule, which extended direct liability to business associates.
- What are the top 10 HIPAA violations?
- The failures OCR cites most often: no documented risk analysis, missing business associate agreements, impermissible disclosures including staff snooping, lost or stolen unencrypted devices, denying patients timely access to their records, insufficient workforce training, late breach notification, improper disposal of records, weak access controls, and disclosures on social media. Most are documentation and process failures, not sophisticated attacks — which is why a worked checklist matters.
- What is the new HIPAA rule in 2026?
- The change to watch is the Security Rule update proposed in January 2025, which would make encryption, multi-factor authentication and asset inventories mandatory rather than 'addressable'. As of our last review it had not been finalized, so current obligations are unchanged — but building those controls now is the safe direction to err in.
Keep reading
- Vendor compliance checkerVerdicts on the tools small healthcare organizations actually run.
- HIPAA glossaryPlain-language definitions, each with its citation.
- HIPAA training requirementsWho must be trained, how often, and what proof to keep.
- HIPAA compliance auditsThe three different things called an audit, and what each asks for.
- Practice management softwareHow to evaluate what a vendor is actually offering you.
- How we researchSourcing, review cadence and corrections policy.
- About the teamThe compliance officers, clinicians and security people behind the research.
Looking for the software rather than the explanation? HIPAA risk assessment software.
Unfamiliar terms are defined in the glossary →
A practical interpretation of the requirements, not legal advice and not an official or exhaustive list. Citations are given so you can read the regulation yourself. What is reasonable and appropriate for your organization depends on its size, complexity and circumstances — take advice on anything you are unsure about.