Checklist · Compliance
HIPAA Security Rule Checklist
There’s no such thing as a “HIPAA certificate.” What a regulator wants is a documented risk analysis and safeguards that are actually running. Here are the three families of safeguards — and the paperwork that ties them together.
The checklist
It applies whether you’re a covered entity (a practice) or a business associate (a vendor that handles ePHI).
How to use it. Work down the list and mark each line honestly — in place, partly in place, or missing. Do not soften the partials. The Security Rule expects documented evidence, so a control that exists only in someone’s memory counts as missing when an investigator asks. Most practices we meet are strong on the technical items and thin on the administrative ones: the risk analysis, the sanction policy, the workforce clearance procedure. Those are the lines that come up first after an incident.
What it is not. This is a working checklist, not a risk analysis. HIPAA requires an actual risk analysis specific to your environment, and no printable list substitutes for one. Use this to find the gaps worth investigating, then document the analysis properly — or book the free 30-minute assessment and we will walk it with you.
Administrative safeguards
- A documented risk analysis of where ePHI lives and how it's exposed — the foundation of the whole program.
- Assigned security responsibility — a named person accountable.
- Workforce security-awareness training, refreshed regularly.
- A contingency plan: backup, disaster recovery, and emergency-mode operation.
Physical safeguards
- Facility access controls for where systems and ePHI live.
- Workstation and device use policies.
- Media controls for disposal and re-use of devices that held ePHI.
Technical safeguards
- Access control with unique user IDs and automatic logoff.
- Audit controls — logging of who accessed ePHI and when.
- Integrity controls so ePHI isn't improperly altered or destroyed.
- Transmission security — encryption of ePHI in transit.
- Encryption of ePHI at rest ("addressable," which in practice means required unless you can document why not).
The paperwork that ties it together
- A signed Business Associate Agreement (BAA) with every vendor that touches ePHI.
- Written policies and procedures you can produce for an OCR inquiry.
- Documentation kept current — an audit meets a binder, not a scramble.
This checklist is a summary, not legal advice — the Security Rule governs. We operate the technical and much of the administrative core, and sign the BAA. See how →