hipaa.systems
Guide

HIPAA compliance

What HIPAA compliance actually means for a small practice or health tech company, what it consists of, and what it is not.

HIPAA compliance at a glance

HIPAA compliance means a covered entity or business associate meets the HIPAA Privacy, Security and Breach Notification Rules: it limits how protected health information is used and shared, honors patients' rights, protects electronic health information with a documented risk analysis and safeguards, has business associate agreements with vendors, trains its workforce, and can respond to breaches. It is an ongoing program, not a certificate — no government body certifies HIPAA compliance.

Who needs itCovered entities and business associates
Core piecesRisk analysis, policies, safeguards, BAAs, training, breach response, patient rights
Official certificationNone — compliance is shown through documentation
Most-missed itemA documented security risk analysis
Keep recordsSix years

HIPAA compliance is not a status you buy or a certificate on the wall. It is the state of actually meeting the rules — and being able to show it.

What it consists of

Area What it means in practice Rule
Scope Know whether you’re a covered entity or business associate, and where PHI lives Who must comply
Risk analysis A written assessment of risks to ePHI and a plan to reduce them Security risk analysis
Safeguards Access control, strong authentication (MFA where appropriate based on risk), encryption, audit logs, device security Security Rule
Policies Written policies and procedures, kept six years 45 CFR 164.316
Vendors A BAA with every vendor that is a business associate BAAs
People Workforce training and sanctions Training requirements
Patients Notice of Privacy Practices, access to records, valid authorizations Privacy Rule
Incidents A breach response process and the 60-day notification clock Breach Notification Rule

What it is not

Where to start

Use the HIPAA compliance checklist as a working list. If you are a small practice, the therapists scenario shows what to prioritize.

Next steps

Frequently asked questions

How do I become HIPAA compliant?

Confirm HIPAA applies to you, complete a security risk analysis, put policies and safeguards in place, sign BAAs with vendors, train your staff, set up a breach response process, and keep documentation. Our checklist walks through each step.

Can software make me HIPAA compliant?

No. Compliance software can organize policies, risk assessments and training, but compliance depends on what your organization actually does.

Is HIPAA compliance a one-time project?

No. The risk analysis, policies, vendor list and training must be kept current as your systems and staff change.