HIPAA Compliance Checklist
HIPAA compliance rests on three safeguard categories: administrative, physical, and technical. Here's what each one requires in practice.
Book a 20-min deal readiness callDetermine if you're a covered entity or business associate
Your HIPAA obligations differ depending on whether you handle PHI directly or process it on behalf of a covered entity.
Appoint a Privacy and Security Officer
HIPAA requires named individuals accountable for privacy policy and security controls, even at a small company.
Conduct a risk analysis
Identify where PHI lives, how it flows through your systems, and what could expose it. This is the foundation every other safeguard builds on.
Implement administrative safeguards
Workforce training, access management procedures, incident response plans, and a sanction policy for violations.
Implement physical safeguards
Facility access controls, workstation security, and device and media controls for anything that touches PHI.
Implement technical safeguards
Access controls, audit logs, encryption in transit and at rest, and automatic logoff for systems handling PHI.
Sign Business Associate Agreements
Any vendor that touches PHI on your behalf needs a signed BAA before they get access, no exceptions.
Build a breach notification process
Know your obligations and timelines for notifying affected individuals, HHS, and in some cases the media, if PHI is exposed.
Monitor and reassess continuously
HIPAA has no certification, but ongoing risk analysis and safeguard reviews are what an auditor or investigator expects to see.
What auditors actually ask for
- Can you produce a current, dated risk analysis?
- Do you have signed BAAs with every vendor touching PHI?
- Can you show audit logs of PHI access by user?
- Is workforce training documented with completion dates?
- Do you have a tested breach notification procedure?
Where teams most often trip up
- Treating the risk analysis as one-off rather than ongoing
- Vendors accessing PHI without a signed BAA in place first
- No documented sanction policy for workforce violations
- Assuming encryption alone satisfies HIPAA, the safeguards are broader
- Missing the 60-day individual breach notification deadline
Realistic timeline
HIPAA has no certification, so readiness is continuous. Most teams reach a defensible posture in 8-12 weeks.