HIPAA compliance checklist
A practical HIPAA checklist for small practices and business associates, with each item linked to the rule behind it — not a list of things to buy.
HIPAA compliance checklist at a glance
A HIPAA compliance checklist for a small practice or business associate covers: confirming HIPAA applies, a documented security risk analysis and risk management plan, written policies and procedures, workforce training, BAAs with every vendor that handles PHI, access controls with MFA, encryption, audit logs, a Notice of Privacy Practices (covered entities), and a breach response plan — with all documentation kept for six years.
| Start with | Confirm whether you are a covered entity or business associate |
|---|---|
| Most-missed item | A documented security risk analysis |
| Vendors | A signed BAA with every vendor that is a business associate |
| Patients | Notice of Privacy Practices; authorizations for non-routine disclosures |
| Keep records | Six years from creation or last effective date |
Use this as a working list. Each item links to the page that explains the requirement and what to check in your tools.
1. Scope
- Confirm whether you are a covered entity, a business associate, or neither (45 CFR 160.103).
- List every place patient information lives: EHR, email, telehealth, file storage, phones, laptops, paper, vendors.
2. Security Rule
- Complete and document a security risk analysis and a risk management plan — see Security risk analysis.
- One account per person on every system with PHI (required), and strong authentication such as MFA where your risk analysis calls for it (recommended) — see Access control.
- Encrypt ePHI at rest and in transit, or document why not — see Encryption.
- Turn on and review audit logs — see Audit controls.
- Write security policies and procedures and keep them for six years (164.316).
- Run security awareness training for your workforce (164.308(a)(5)) and keep records.
3. Vendors
- Sign a BAA with every vendor that is a business associate — one that creates, receives, maintains or transmits PHI on your behalf — see Business associate agreements.
- Check which plan and which services each BAA covers.
- Business associates: sign BAAs with your own subcontractors.
4. Privacy Rule (covered entities)
- Publish and hand out a Notice of Privacy Practices — see Notice of Privacy Practices.
- Use a valid authorization form for non-routine disclosures — see HIPAA authorization.
- Have a process for patients’ requests for their own records.
- Decide how you email patients and record their preferences — see Emailing patients.
5. Incidents
- Write a short breach response plan: who decides, the four-factor assessment, the 60-day clock — see Notifying patients of a breach.
- Keep a log of incidents and of breaches affecting fewer than 500 people for the annual HHS report.
6. Keep it current
- Review the risk analysis, policies and vendor list periodically and whenever something changes (HIPAA sets no fixed interval; we recommend at least yearly).
- Keep all HIPAA documentation for six years.
Next steps
- HIPAA for therapists in private practice →Scenario
- Security risk analysis →Requirement
- Business associate agreements (BAAs) →Requirement
- Access control and sign-in →Requirement
- Encryption of ePHI →Requirement
- Audit controls and activity logs →Requirement
- Notice of Privacy Practices →Requirement
- HIPAA authorization →Requirement
- Notifying patients of a breach →Requirement
Frequently asked questions
Is there an official HIPAA compliance checklist?
No. HHS does not publish a mandatory checklist. The requirements come from the Privacy, Security and Breach Notification Rules in 45 CFR Part 164; a checklist is a way to make sure you've addressed each one.
What is the most important item on a HIPAA checklist?
The security risk analysis. It is required, it drives most other Security Rule decisions, and it is one of the most common gaps found in HHS audits.
Do business associates need the same checklist?
Mostly. Business associates must meet the Security Rule, sign BAAs with their own subcontractors, and report breaches to the covered entity. They don't issue a Notice of Privacy Practices.