HIPAA Compliance Checklist: Protect PHI and Reduce Risk

HIPAA Compliance Checklist: Steps to Protect PHI and Reduce Risk
All U.S. organizations handling Protected Health Information (PHI) must ensure they are HIPAA compliant and protect this data in accordance with security guidelines. However, achieving HIPAA compliance isn’t a one-time review. It’s a continuous, rolling series of checks and measures.
In this guide, we offer practical, plain-language steps as part of a HIPAA compliance checklist to help your organization stay protected.
What is a HIPAA compliance checklist?
A HIPAA compliance checklist breaks down the requirements for protecting PHI under HIPAA. It helps you connect compliance requirements to your business processes, operations, and everyday data handling. It also serves as a tool to help you understand who's accountable for each obligation, what compliance evidence to keep, and how frequently you should conduct reviews.
A HIPAA compliance checklist applies to healthcare providers, covered entities, healthcare clearinghouses, business associates, and health plans. It should comprehensively cover all people, policies, vendors, documentation, safeguards, training, and monitoring steps required.
The HIPAA compliance checklist
The checklist below condenses each requirement covered in this guide into a single, repeatable reference. Use it to assign ownership, track evidence, and schedule reviews, and revisit it whenever your systems, vendors, or workflows change. Remember, no single item proves compliance on its own; it's the combination of documented, regularly reviewed measures that protect PHI and stands up to Office for Civil Rights (OCR) scrutiny.
- Designate a HIPAA compliance officer in writing: with documented authority over policies, training, and incident response.
- Map where PHI lives: inventory all systems, devices, vendors, and paper records that store or transmit PHI, and update after every change.
- Conduct and document risk assessments: at least annually, and after any system, policy, or vendor change.
- Implement all three safeguard categories: administrative, physical, and technical - and tie each control to risk assessment outcomes.
- Write policies staff can actually follow: covering access, appropriate use, storage, disposal, transmission, and incident response.
- Sign Business Associate Agreements (BAAs) before sharing PHI: and review vendor access whenever contracts change or end.
- Train staff on PHI handling: role-specific, repeated after changes, and fully documented.
- Document a breach response plan: including intake, triage, containment, investigation, and notification timelines.
- Keep compliance documentation audit ready: retained for at least six years.
- Schedule rolling reviews: of access controls, policies, and safeguards, especially after incidents, audits, or regulatory updates.
What each HIPAA rule requires
HIPAA sets out three core rules: Privacy, Security, and Breach Notification. When following a checklist, it’s vital to remember that complying with one rule does not mean you necessarily satisfy the others, and that there are separate penalties for breaching each.
- The Privacy Rule dictates how PHI should be used, handled, disclosed, and accessed.
- The Minimum Necessary Standard, within the Privacy Rule, expects covered entities to limit access and disclosure of PHI to intended purposes only.
- The Security Rule covers the physical, administrative, and technical safeguards required to protect electronic PHI.
- The Breach Notification Rule dictates how organizations should report breaches and violations, including timelines for informing the Department of Health and Human Services (HHS), affected individuals, and the media (if applicable).
- This rule also advises how business associates must inform covered entities about breaches.
Rule violations are enforceable via OCR, which determines whether an organization has breached its HIPAA obligations.
Appointing a HIPAA compliance officer
A HIPAA compliance officer ensures security policies and privacy standards are followed. This role forms the foundation of your compliance program. Without a named, responsible owner, your checklist is unenforceable, so you must designate an officer in writing.
Responsibilities include:
- Drafting security processes
- Designing privacy training modules
- Investigating incidents and breaches
- Carrying out risk assessments and reviews
- Analyzing safeguards
This is a role with considerable authority, as an officer can oversee compliance processes covering IT, operations, legal teams, HR, and even third-party vendor management. In some cases, you may need multiple officers depending on compliance scale.
Finding where PHI lives in your organization
Organizations need a clear PHI map to ensure all checklist steps are accurate and effective. Tracking down PHI across your organization also means building risk management around where data is located, how it is used, and what vulnerabilities may exist.
PHI can be found across:
- Electronic Health Records (EHRs) and systems
- Billing systems and claims tools
- Email servers and inboxes
- Cloud environments
- Patient access portals
- Collaboration tools
- Call recordings
- CRMs and communication flows
- Data warehouses
- Emergency backups
- Paper documents and files
- Vendor environments (e.g., apps and exchanges)
As part of your HIPAA compliance checklist, always review these inventories and environments after each workflow, system, or vendor change.
Risk assessments across these environments should carefully evaluate potential threats of data leakage, the likelihood of breaches taking place, and what the wider impact would be to parties involved.
These assessments should also account for any known vulnerabilities (e.g., through penetration testing) and record any safeguards.
Ultimately, these assessments help build toward documented remediation plans, should breaches occur. These plans should establish clear task ownership and remediation timelines.
Turning requirements into rules your staff can follow
Effectively managing HIPAA compliance means creating clear daily operating rules your staff can easily repeat. The policies laid out by your officer(s) are only effective if you attach them to real workflows and ensure personnel understand boundaries.
Create accessible policies that apply to HIPAA’s core principles, covering:
- Access management and expectations
- Appropriate use of PHI (and boundaries)
- Data backup and retention
- Expected PHI storage standards
- Incident response
- Safe data disposal
- Disclosure and transmission boundaries
Always ensure document versions are date stamped, keep approval records, and establish review schedules to keep policies up to date with business changes.
In addition, staff should be able to read and digest these documents so they can apply knowledge to both everyday work and unusual situations, so be specific.
Closing the gaps attackers look for
HIPAA sets three safeguard categories you must implement to stay compliant: administrative, physical, and technical. Each category applies to a different layer of PHI exposure.
- Administrative safeguards cover risk analysis, workforce security and training, contingency planning, access management, and response procedures.
- Physical safeguards establish controls that apply to physical spaces and access needs, covering workstations, systems, facilities, and individual devices.
- Technical safeguards cover access controls, authentication, audit controls, transmission security, and how data is encrypted at rest and in transit. In practice, meeting these standards also means deploying supporting defenses like phishing protection and anti-virus tools.
It’s vital to apply and tie safeguards in each category to risk assessment outcomes. During assessments, you’ll establish how effective your safeguards are, record vulnerabilities, and take steps to strengthen those protections.
These safeguard categories are also set to tighten. A proposed update to the HIPAA Security Rule, projected for final publication in July 2027, would make nearly all currently "addressable" safeguards mandatory, including encryption at rest and in transit, multi-factor authentication, and regular penetration testing. Treating these as baseline requirements now means no scramble if and when the rule is finalized.
Gaps in any of these categories can expose PHI, and even unauthorized access that happens innocently can trigger Breach Notification Rule obligations. We created a HIPAA Security Rule Compliance Checklist to help you identify those gaps now, while there is still time to address them effectively.
When a vendor breach becomes your problem
Before sharing PHI with a third-party vendor, you must obtain a signed BAA. Without one, sharing PHI with that vendor is itself a HIPAA violation, and any subsequent vendor breach lands squarely on the covered entity, raising auditing and enforcement risks.
A BAA should clearly define:
- How a vendor intends to use PHI
- Any safeguards the covered entity expects
- How and when a vendor will report breaches
- Responsibilities regarding contract and BAA termination
If contracts change or services end, always review vendor access to PHI and consult the relevant BAAs.
The staff behaviors that trigger most PHI incidents
Common staff behaviors that trigger PHI incidents include snooping on records (e.g., of people they know), mistakenly sending information to the wrong people, disposing of data improperly, and sharing access credentials. Therefore, it’s crucial to instill understanding of and respect for HIPAA standards before granting access to PHI.
HIPAA Journal’s 2025 Healthcare Data Breach Report shows that staff error and internal fraud continue to pose concerning PHI security risks:
“While there were small decreases in hacking/IT incidents, loss/theft incidents, and improper disposal incidents year-over-year, there was a 17.4% increase in unauthorized access/disclosure incidents. These incidents include data theft by malicious insiders and inadvertent data exposures due to carelessness by employees.”
HIPAA compliance training is most effective when it's designed to establish repeatable habits.
What’s more, compliance habits should be tied to individual roles and access levels, and all training activities should be fully documented. This helps to build auditable evidence to show staff have effectively received training.
Basic PHI handling and HIPAA compliance training should cover:
- Individual security responsibilities
- Secure device handling (physical and administrative)
- Data privacy standards
- How to escalate breaches and report vulnerabilities
After each policy, system, or regulatory change, staff must receive refresher training, and you should ideally schedule regular training and scenarios throughout the year.
When documenting training records, you should clearly state when training started and was completed, the modules and topics that were covered, and which employees took part.
Why breach response must exist before the breach
Having a documented breach response plan in place ensures faster incident recovery and damage minimization. Documenting a clear action plan with notification timelines and investigation workflows also reduces damage scope, downtime, and panic in the event of a breach.
All documented incident response plans should cover:
- Intake
- Triage
- Containment
- Investigation
- Notification decisions
They must also clearly identify what happened, what PHI was affected (and to what extent), who was specifically responsible, and what remediation actions took place.
Establish your notification strategy before a breach occurs. You will need to inform any individuals affected by breaches within 60 days of an event being discovered, and if a breach affects more than 500 residents of a single state or jurisdiction, the media must also be informed.
Keeping compliance documentation ready for audits
OCR investigators treat undocumented controls and measures as absent. Therefore, it's crucial to fully and clearly document all proof of compliance in case of an audit.
Create and retain documentation covering:
- All security policies and procedures
- Any risk assessments you have carried out
- Breach response and remediation plans
- Employee training and assessment
- Internal auditing logs
- Existing BAAs and amendments made
- Security officer details
Keeping the program running after the initial setup
Becoming HIPAA compliant requires regular management. Instead of ticking annual checkboxes, organizations must establish rolling policy and safeguard reviews to prevent compliance from degrading, and potentially causing breaches.
With a rolling schedule, it's easier to account for potential control gaps, configuration issues, and access concerns before incidents occur. A key area to review, for example, is access control: do employees and vendors still have an acceptable level of access to PHI based on their current roles?
All security policies must also undergo review after significant changes. This covers alterations to systems, updates to regulations, and changes in vendor partnerships and roles.
You're also expected to review all policies after security incidents and breaches occur, and after each internal audit or OCR audit.
Where most HIPAA programs break down
Many HIPAA programs break down due to missing or unsigned BAAs, unrepeated risk assessments, and poorly tested incident response plans. It’s therefore important for your HIPAA compliance checklist to target each of these areas.
Beyond this, failing to review access controls for employees and vendors after onboarding means companies leave inactive accounts with access to live PHI, a common error that leaves sensitive information wide open unless remedied.
These are all common failures that OCR auditors pick up on which are avoidable with a proactive, checklist-driven approach.
FAQs
Q1 Who needs to follow a HIPAA compliance checklist?
All organizations operating within U.S. healthcare should use a HIPAA compliance checklist to ensure they are protecting PHI effectively. Covered entities, such as clinics and individual practitioners, and business associates, such as third-party billers and healthcare lawyers, must comply.
Q2 How often should a HIPAA risk assessment be conducted?
HIPAA risk assessments should be conducted continuously, whenever there are changes made to policies, operations, company structure, or vendor relationships. Otherwise, enterprise-wide assessments should be conducted at least annually.
Q3 What happens if a business associate causes a breach?
A business associate must take immediate steps to remedy a data breach and inform a covered entity within 60 days of identifying it. The covered entity must then inform affected individuals, HHS, and potentially the media. Such breaches may impact the BAA between the associate and covered entity.
Q4 Does completing a checklist prove HIPAA compliance?
No, completing a checklist does not prove you are HIPAA compliant, but it helps guide you toward what is needed to assess, safeguard, and record any security steps taken.
Q5 How long must HIPAA documentation be retained?
HIPAA documentation must be retained for at least six years from the date of its creation or the date when it was last in effect. Some state retention laws and guidelines, however, may extend this.
Conclusion
Achieving and maintaining HIPAA compliance requires significant effort and attention, but failure to meet standards can result in serious legal and reputational consequences.
If you need guidance with risk assessments and vulnerability investigation, it’s important to ask for help from seasoned experts. Take the next step toward continuous compliance with support from VikingCloud HIPAA compliance services.
Related Blogs
Stay up-to-date on the latest happenings in Cybersecurity and PCI Compliance.
Third-Party Vendors Already Have Access to Your Stores. Are You Managing the Risk?


.png)