WhatsApp Chat

HIPAA Compliance Checklist for Healthcare Organizations (2026)

By Olivia Dodd

HIPAA Compliance Checklist

OCR enforcement has never been more aggressive. In 2025 alone, the Office for Civil Rights issued 19 settlements and more than $8 million in fines against healthcare organizations for HIPAA violations. The common thread across nearly every case was not a sophisticated cyberattack — it was a documentation failure. Missing risk analyses, absent Business Associate Agreements, and undertrained staff were the recurring culprits.

A HIPAA compliance checklist is not a guarantee against enforcement action. But it is the most practical tool for identifying gaps before OCR does. This checklist covers every area the Privacy Rule, Security Rule, and Breach Notification Rule require healthcare organizations to address — organized by safeguard category so you can work through it systematically and prioritize where your exposure is greatest.

Whether you are starting a new HIPAA compliance program, preparing for an audit, or conducting an annual self-review, this checklist gives you a concrete starting point.

How to Use This HIPAA Compliance Checklist

HIPAA compliance requirements fall across three rules and three safeguard categories. Understanding the structure before working through the checklist makes the process significantly more efficient.

The three HIPAA rules:


Privacy Rule — governs how PHI can be used and disclosed, and what rights patients have over their information.

Security Rule — governs how electronic PHI (ePHI) must be protected through administrative, physical, and technical safeguards.

Breach Notification Rule — governs what must happen when PHI is exposed or potentially exposed.

The three safeguard categories under the Security Rule:


Administrative safeguards — policies, procedures, workforce training, and risk management.

Physical safeguards — controls over physical access to facilities and devices containing ePHI.

Technical safeguards — technology controls protecting ePHI in systems, networks, and transmissions.

This HIPAA compliance requirements checklist is organized by safeguard category, with additional sections for IT-specific controls, risk assessment, workforce training, and audit preparation.

Administrative Safeguards Checklist

Administrative safeguards are the policies and procedures that govern how your organization manages the selection, development, and implementation of security measures to protect ePHI. They also include your workforce training program and risk management process.

Security Management Process


Conducted and documented a formal security risk analysis covering all systems that create, receive, maintain, or transmit ePHI.

Implemented a risk management plan that addresses identified vulnerabilities and documents mitigation measures.

Established sanctions policies for workforce members who violate HIPAA policies.

Implemented regular review of information system activity including audit logs, access reports, and security incident reports.

Privacy and Security Officer


Designated a Privacy Officer responsible for HIPAA Privacy Rule compliance.

Designated a Security Officer responsible for HIPAA Security Rule compliance.

Both roles have defined responsibilities documented in writing.

Contact information for both officers is accessible to all workforce members.

Workforce Training and Access


All workforce members with PHI access have completed initial HIPAA training before accessing PHI.

Annual HIPAA refresher training is scheduled and documented for all applicable staff.

Training records are retained for a minimum of six years.

Role-based training content is differentiated for clinical staff, administrative staff, and IT personnel.

Business associate workforce HIPAA training obligations are verified.

For a complete breakdown of HIPAA workforce training requirements → HIPAA Training Requirements guide

For structured training delivery and automated tracking → HIPAA Compliance Training guide

Information Access Management


Access to ePHI is granted based on the minimum necessary standard.

Access authorization procedures are documented and applied consistently.

Access is terminated promptly when a workforce member changes roles or leaves the organization.

Policies, Procedures and Documentation


Written HIPAA privacy policies and procedures are in place and reflect current regulatory requirements.

Written security policies and procedures cover all Security Rule requirements.

HIPAA policy templates are updated whenever policies change and when new regulatory guidance is issued.

Documentation of all policies is retained for a minimum of six years.

A HIPAA compliance statement is maintained and accessible to patients upon request.

Business Associate Management


All business associates handling PHI have signed a Business Associate Agreement (BAA) before any PHI is shared.

BAAs are current and reflect each associate’s actual PHI handling activities.

Subcontractor agreements require HIPAA compliance from third parties downstream.

BAA inventory is maintained and reviewed annually.

Physical Safeguards Checklist

Physical safeguards govern how your organization controls physical access to facilities and equipment where ePHI is created, maintained, or transmitted.

Facility Access Controls


Physical access to areas containing ePHI systems is restricted to authorized personnel.

Access control policies document who has access to what areas and under what circumstances.

Access logs or monitoring systems are in place for areas housing ePHI.

Visitor access to restricted areas is managed and documented.

Workstation Security


Workstations are positioned to prevent unauthorized viewing of patient information (screen privacy).

Workstation use policies specify what activities are permitted on devices accessing ePHI.

Automatic screen lock is enabled on all workstations after a defined period of inactivity.

Workstations in shared or public areas have additional physical security measures.

Device and Media Controls


Policies govern the receipt and removal of hardware and electronic media containing ePHI.

ePHI is removed from hardware before disposal or reuse — data wiping or physical destruction.

Backup copies of ePHI are created and stored securely.

Movement of devices and media containing ePHI is tracked and documented.

Technical Safeguards Checklist

Technical safeguards are the technology and associated policies that protect ePHI and control access to it. This section forms the core of any HIPAA IT compliance checklist.

Access Controls


Each workforce member has a unique username and password — shared credentials are prohibited.

Multi-factor authentication (MFA) is implemented for access to all systems containing ePHI.

Role-based access controls limit each user to the minimum necessary PHI access for their function.

Emergency access procedures exist for accessing ePHI during a system outage.

Automatic logoff is configured for sessions accessing ePHI.

Audit Controls


Hardware and software mechanisms record and examine access to ePHI.

Audit logs are reviewed regularly to detect unusual access patterns or potential breaches.

Audit log retention meets the six-year minimum documentation requirement.

Integrity Controls


Mechanisms exist to confirm that ePHI has not been altered or destroyed in an unauthorized manner.

Data integrity verification processes are documented and applied to critical ePHI systems.

Encryption and Transmission Security


ePHI is encrypted at rest using current encryption standards (AES-256 or equivalent).

ePHI is encrypted in transit — email, file transfers, and API communications.

Unencrypted transmission of ePHI is prohibited and enforced by technical controls where possible.

Remote access to ePHI systems requires VPN or equivalent secure connection.

HIPAA IT Compliance Checklist

The HIPAA IT compliance checklist extends technical safeguard requirements into specific IT environment controls frequently cited in OCR investigations. This section is particularly relevant for IT professionals managing healthcare environments.

Network Security


Firewalls are configured and regularly updated to protect the network perimeter.

Network segmentation separates clinical systems from general business systems.

Wireless networks transmitting ePHI use WPA3 or equivalent encryption.

Network access is logged and monitored for anomalous activity.

Email and Communication Security


Email encryption is implemented for any communication containing ePHI.

Secure messaging policies prohibit sending PHI through unencrypted channels including personal email or SMS.

Anti-phishing controls and user training address the most common vector for healthcare breaches.

Cloud and EMR/EHR Security


All cloud storage and SaaS applications that access or store ePHI have signed BAAs in place.

EMR/EHR systems have access controls, audit logging, and encryption configured per HIPAA requirements.

EMR HIPAA compliance checklist items are reviewed with your EHR vendor at least annually.

Cloud environments are configured with least-privilege access principles.

Vulnerability and Patch Management


Software and operating systems containing ePHI are patched on a documented schedule.

Vulnerability scanning is conducted regularly on systems housing ePHI.

Penetration testing is performed at least annually on systems that create, receive, maintain, or transmit ePHI.

Identified vulnerabilities are remediated with documented timelines and responsible owners.

Endpoint Security


Endpoint protection software is installed and current on all devices accessing ePHI.

Mobile device management (MDM) is in place for any mobile devices accessing ePHI.

Remote wipe capability exists for mobile devices that may contain or access ePHI.

Removable media (USB drives) use is restricted or encrypted on devices accessing ePHI.

HIPAA Risk Assessment Checklist

In 2025, one covered entity paid $1.19 million after failing to conduct a compliant risk analysis despite multiple prior OCR investigations. Security risk analysis failures are the single most commonly cited violation in recent OCR enforcement actions.

Risk Analysis


Scope of the risk analysis is defined — all systems, devices, and processes that create, receive, maintain, or transmit ePHI are in scope.

All ePHI within the defined scope is identified and catalogued.

Threats to ePHI confidentiality, integrity, and availability are identified.

Existing controls are documented and evaluated for effectiveness against identified threats.

Likelihood and impact of each identified threat are assessed.

Risk level of each identified threat is determined (high / medium / low).

The risk analysis is documented in writing and retained for a minimum of six years.

The risk analysis is reviewed and updated when significant operational or environmental changes occur.

Risk Management


A risk management plan is developed based on the findings of the risk analysis.

Risk management measures are implemented in priority order based on assessed risk level.

Implementation of risk management measures is documented.

Ongoing monitoring of the effectiveness of risk management measures is in place.

HIPAA Compliance Audit Checklist

The HIPAA compliance audit checklist helps organizations prepare for both internal self-audits and external OCR investigations. Organizations that can produce comprehensive, organized documentation consistently fare better in enforcement proceedings.

Documentation Readiness


All HIPAA policies and procedures are in writing and available for review.

Evidence of the most recent security risk analysis is accessible and complete.

Training records for all workforce members are organized and retrievable by individual and date.

BAA inventory is current and all agreements are accessible.

Breach incident logs are maintained — including incidents assessed and determined not to be reportable.

OCR correspondence files are organized and complete.

Documentation of all HIPAA-related activities is retained for a minimum of six years.

Self-Audit Process


Annual internal HIPAA audit is scheduled and conducted by designated compliance staff.

Audit scope covers Privacy Rule, Security Rule, and Breach Notification Rule compliance.

Identified gaps are documented with remediation timelines and responsible owners.

Results of prior audits and remediation actions are documented and retained.

Audit findings are reported to organizational leadership and used to update the HIPAA compliance plan.

Patient Rights Compliance


Patient access request procedures are implemented — patients receive copies of records within 30 days.

Procedures for handling patient requests to amend records are documented.

Accounting of disclosures is available to patients upon request.

Notice of Privacy Practices (NPP) is current, accessible, and provided to patients at first service.

Workforce Training Checklist

Workforce training is the most direct control an organization has over human-factor HIPAA risks — and it is one of the first areas OCR reviews during an investigation.

Training Program Requirements


HIPAA Privacy Rule training covers PHI handling, patient rights, minimum necessary standard, and reporting procedures.

HIPAA Security Rule training covers password management, phishing recognition, device security, and incident response.

Training content is role-specific — clinical, administrative, and IT staff receive content relevant to their PHI exposure.

New employee training is completed before PHI access is granted — within the first week of employment.

Annual refresher training is scheduled and completed by all applicable workforce members.

Training is updated and redistributed whenever policies change significantly.

Training Documentation


Completion records exist for every workforce member — name, date, course content, and policy version.

Certificates of completion are stored in a retrievable format.

Training records are retained for a minimum of six years.

Training delivery is managed through a system that generates audit-ready records automatically.

Business Associate Training Verification


BAAs require business associates to maintain an active HIPAA training program for their own workforce.

Evidence of business associate training compliance is requested as part of periodic vendor reviews.

2026 HIPAA Updates: What Your Checklist Must Reflect

Reproductive Health Care Privacy Rule Amendment (Effective 2024)

In 2024, HHS amended the HIPAA Privacy Rule to add new protections for PHI related to reproductive health care. Covered entities and business associates are now prohibited from disclosing reproductive health care PHI in certain law enforcement circumstances involving the provision of lawful reproductive health care.


Policies updated to reflect the 2024 reproductive health care amendment.

Workforce training updated to cover the new disclosure restrictions.

Attestation procedures implemented for PHI requests that may relate to reproductive health care.

HIPAA Security Rule Proposed Updates

HHS has proposed significant updates to the HIPAA Security Rule that would raise the baseline for technical safeguards — elevating addressable implementation specifications to required status and mandating specific controls including MFA, network segmentation, and encryption.


MFA implemented for all access to ePHI systems.

Network segmentation between clinical and administrative systems documented.

Encryption of ePHI at rest and in transit implemented as a baseline, not an option.

Annual penetration testing documented and completed.

FAQs

Common questions about HIPAA compliance checklists.

What is a HIPAA compliance checklist?

A HIPAA compliance checklist is a structured tool that helps covered entities and business associates identify whether they have implemented all the required administrative, physical, and technical safeguards under the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule. It is used for internal compliance reviews, audit preparation, and gap assessment.

What is the key to HIPAA compliance?

The key to HIPAA compliance is documentation. Organizations that consistently produce written evidence of their compliance activities — risk analyses, training records, policies and procedures, Business Associate Agreements, and audit logs — are significantly better positioned during OCR investigations than those with stronger technical controls but weaker documentation. OCR investigators can only assess what is documented.

Is there a HIPAA compliance checklist PDF available?

Yes — many regulatory bodies, compliance firms, and healthcare technology providers publish HIPAA compliance checklist PDFs. HHS itself publishes guidance documents that function as reference checklists. This page covers the full scope of HIPAA requirements in checklist format. A printable or downloadable version can be requested through the contact form.

How often should a HIPAA compliance checklist be reviewed?

At a minimum, your HIPAA compliance checklist should be reviewed annually as part of a formal internal audit. It should also be reviewed whenever significant changes occur — a new EHR system, a change in business associates, new regulatory guidance, or a security incident. The 2024 reproductive health care amendment and the proposed Security Rule updates are both reasons to review your checklist in 2026.

What does an EMR HIPAA compliance checklist include?

An EMR HIPAA compliance checklist covers the specific requirements that apply to electronic medical record systems — including access controls, audit logging, user authentication, data encryption, backup and recovery, business associate agreements with the EHR vendor, and regular security assessments of the system.

What is a HIPAA compliance audit checklist?

A HIPAA compliance audit checklist is a tool used to assess whether an organization’s compliance program meets regulatory standards. It covers documentation readiness, policy completeness, training records, breach incident logs, BAA inventory, and patient rights procedures. Organizations that maintain a current audit checklist are significantly better prepared when OCR requests documentation.

Do business associates need their own HIPAA compliance checklist?

Yes. Business associates are directly liable under HIPAA and must independently implement administrative, physical, and technical safeguards. A business associate’s HIPAA compliance checklist includes the same categories as a covered entity’s checklist, plus specific items related to their BAA obligations and subcontractor management.

Build and Maintain Your HIPAA Compliance Program

A HIPAA compliance checklist identifies gaps. A HIPAA compliance program fills them and maintains that compliance over time as regulations change, systems evolve, and staff turn over.

The organizations that consistently pass OCR scrutiny share two characteristics: they document everything, and they train their workforce consistently. Both require systems that work in the operational reality of a healthcare environment rather than relying on manual processes that break down under pressure.

For workforce training specifically the item most directly within the control of compliance and HR teams a structured HIPAA training program with automated tracking, role-based content, and six-year record retention is both a compliance requirement and a demonstrable risk reduction measure.

Do NOT follow this link or you will be banned from the site!