hipaa.systems
Guide

HIPAA compliance checklist

A practical HIPAA checklist for small practices and business associates, with each item linked to the rule behind it — not a list of things to buy.

HIPAA compliance checklist at a glance

A HIPAA compliance checklist for a small practice or business associate covers: confirming HIPAA applies, a documented security risk analysis and risk management plan, written policies and procedures, workforce training, BAAs with every vendor that handles PHI, access controls with MFA, encryption, audit logs, a Notice of Privacy Practices (covered entities), and a breach response plan — with all documentation kept for six years.

Start withConfirm whether you are a covered entity or business associate
Most-missed itemA documented security risk analysis
VendorsA signed BAA with every vendor that is a business associate
PatientsNotice of Privacy Practices; authorizations for non-routine disclosures
Keep recordsSix years from creation or last effective date

Use this as a working list. Each item links to the page that explains the requirement and what to check in your tools.

1. Scope

2. Security Rule

3. Vendors

4. Privacy Rule (covered entities)

5. Incidents

6. Keep it current

Next steps

Frequently asked questions

Is there an official HIPAA compliance checklist?

No. HHS does not publish a mandatory checklist. The requirements come from the Privacy, Security and Breach Notification Rules in 45 CFR Part 164; a checklist is a way to make sure you've addressed each one.

What is the most important item on a HIPAA checklist?

The security risk analysis. It is required, it drives most other Security Rule decisions, and it is one of the most common gaps found in HHS audits.

Do business associates need the same checklist?

Mostly. Business associates must meet the Security Rule, sign BAAs with their own subcontractors, and report breaches to the covered entity. They don't issue a Notice of Privacy Practices.