CompyMax

HIPAA compliance checklist

32 items, grouped in the order it makes sense to do them, each with the evidence that actually proves it. Written for a small practice, billing company or healthcare vendor with no compliance officer.

No email required, no download gate. Citations are to 45 CFR Part 164 so you can check anything against the regulation itself. Last reviewed .

Read the evidence column, not just the task column

Almost every organization that fails a client security review has done most of the tasks. What it cannot produce is dated proof that it did them. “We train our staff” invites a follow-up question; a list of certificates with names and dates ends the thread. Treat the right-hand column as the actual deliverable.

1. Establish what you are and what you hold

Half the confusion in small organizations comes from never settling this. Your obligations differ depending on whether you are a covered entity or a business associate, and you cannot protect information you have not located.

  • Determine whether you are a covered entity or a business associate

    Evidence: A written note of the determination and the reasoning behind it

  • Inventory every system, device and vendor that touches patient information

    Evidence: A dated list, including the tools nobody officially approved

  • Appoint someone accountable for security, and someone for privacy

    Evidence: A named person in writing — it can be the same person in a small organization

    164.308(a)(2), 164.530(a)

2. Conduct and document a risk analysis

This is the single most commonly cited failure in enforcement actions, usually because it was never done or was done once and never revisited. It is required, it is not optional, and the documentation is the deliverable.

  • Assess risks to the confidentiality, integrity and availability of the patient information you hold

    Evidence: A dated risk analysis covering every system on your inventory

    164.308(a)(1)(ii)(A)

  • Record decisions on addressable specifications you chose not to implement

    Evidence: Written reasoning plus the alternative control you put in place instead

    164.306(d)

  • Turn every gap into a task with an owner and a due date

    Evidence: A remediation log showing what closed, when, and with what proof

    164.308(a)(1)(ii)(B)

  • Repeat the analysis annually and whenever something material changes

    Evidence: Consecutive dated analyses showing what changed year to year

3. Write policies people can actually follow

A hundred-page policy pack cloned from a hospital is worse than a short one your staff follow, because the gap between what you wrote and what you do is exactly what an investigator examines.

  • Adopt written security and privacy policies covering your real workflows

    Evidence: Versioned policy documents with publication dates

    164.316(a)

  • Have every workforce member read and acknowledge them

    Evidence: Acknowledgement records naming the person, the version and the date

  • Write a sanction policy for workforce members who violate them

    Evidence: The policy, plus records of any sanctions actually applied

    164.308(a)(1)(ii)(C)

  • Retain documentation for six years from creation or last effective date

    Evidence: A retention schedule you can demonstrate you follow

    164.316(b)(2)(i)

4. Train the workforce, and prove it

Training is required, and the evidence that matters is per person and dated. A group session with no attendance record proves nothing a year later.

  • Train all workforce members on your policies and procedures

    Evidence: A dated certificate per person, not a signed attendance sheet

    164.530(b)

  • Train new starters before they get access to patient information

    Evidence: Completion dates that precede their access grant dates

  • Refresh training periodically and after material changes

    Evidence: A renewal schedule with completion dates against it

  • Run security reminders between formal sessions

    Evidence: Records of the reminders sent

    164.308(a)(5)(ii)(A)

5. Get agreements with everyone downstream

The gap here is rarely the obvious vendor. It is the storage account someone set up, the fax service, the scheduler on the website and the contractor who has admin access.

  • Sign a business associate agreement with every vendor that touches patient information

    Evidence: Executed agreements, with dates, filed somewhere findable

    164.502(e), 164.308(b)(1)

  • Confirm the vendor's agreement actually covers the products you use

    Evidence: The vendor's own covered-services documentation alongside the agreement

  • If you are a business associate, get agreements with your own subcontractors

    Evidence: Executed downstream agreements

    164.502(e)(1)(ii)

  • Track expiry and review dates so none lapse quietly

    Evidence: A register with owners and dates

6. Control access technically

This is the part most small organizations assume their IT provider handles. Ask them directly, because 'we use a good firewall' is not an answer to any of these.

  • Give every user a unique identifier — no shared logins

    Evidence: A user list with no generic accounts on it

    164.312(a)(2)(i)

  • Enforce multi-factor authentication on systems holding patient information

    Evidence: A configuration export showing enforcement, not a policy saying so

  • Remove access promptly when someone leaves

    Evidence: Termination dates matched against access-revocation dates

    164.308(a)(3)(ii)(C)

  • Enable audit logging and actually review it

    Evidence: Logs plus a record that someone looked at them

    164.312(b)

  • Encrypt patient information in transit and at rest where reasonable

    Evidence: Configuration evidence, and written reasoning where you did not

    164.312(a)(2)(iv), 164.312(e)(2)(ii)

  • Have tested backups you can actually restore from

    Evidence: A restore test with a date on it

    164.308(a)(7)

7. Be ready for the incident

Most incidents are small and never become reportable breaches. The record showing you assessed them properly is what turns an incident into a non-event rather than a finding.

  • Write an incident response procedure staff can follow at 4pm on a Friday

    Evidence: The procedure, plus evidence staff know where it is

    164.308(a)(6)

  • Log every security incident, including the ones that turned out fine

    Evidence: An incident log with dates, assessments and outcomes

  • Run the four-factor risk assessment on any impermissible use or disclosure

    Evidence: Written analysis of all four factors and the conclusion reached

    164.402

  • Know your notification obligations before you need them

    Evidence: Deadlines and recipients documented in the procedure

    164.400–414

8. Keep it alive

Compliance decays. An organization that did everything on this list two years ago and nothing since is in a worse position than one that has been muddling along and documenting it.

  • Review the whole programme annually

    Evidence: A dated review record

    164.306(e)

  • Reassess when you adopt a new system or change how you work

    Evidence: Assessment records tied to specific changes

  • Keep an evidence pack current enough to send on request

    Evidence: A dated export you could hand over this week

The list is the easy part. The evidence is the work.

Our platform runs the assessment, turns each gap into a task with an owner and a date, holds the policies and certificates, tracks the agreements, and exports the whole thing as a dated pack when a client asks. 14 days free, no credit card.

Common questions

What are HIPAA compliance requirements?
In practice: conduct and document a security risk analysis, implement administrative, physical and technical safeguards, adopt written policies and train your workforce on them, sign business associate agreements with vendors that touch patient information, keep an incident log with breach notification procedures, and retain the documentation for six years. The checklist above breaks each into concrete items with the evidence that proves it. There is no official government checklist and no body that certifies completion.
What are the 5 basic rules of HIPAA?
The Privacy Rule, governing how protected health information may be used and disclosed; the Security Rule, requiring safeguards for electronic PHI; the Breach Notification Rule, saying who must be told when something goes wrong; the Enforcement Rule, covering investigations and penalties; and the Omnibus Rule, which extended direct liability to business associates.
What are the top 10 HIPAA violations?
The failures OCR cites most often: no documented risk analysis, missing business associate agreements, impermissible disclosures including staff snooping, lost or stolen unencrypted devices, denying patients timely access to their records, insufficient workforce training, late breach notification, improper disposal of records, weak access controls, and disclosures on social media. Most are documentation and process failures, not sophisticated attacks — which is why a worked checklist matters.
What is the new HIPAA rule in 2026?
The change to watch is the Security Rule update proposed in January 2025, which would make encryption, multi-factor authentication and asset inventories mandatory rather than 'addressable'. As of our last review it had not been finalized, so current obligations are unchanged — but building those controls now is the safe direction to err in.

Unfamiliar terms are defined in the glossary →

A practical interpretation of the requirements, not legal advice and not an official or exhaustive list. Citations are given so you can read the regulation yourself. What is reasonable and appropriate for your organization depends on its size, complexity and circumstances — take advice on anything you are unsure about.