HIPAA & privacy

What is on a HIPAA compliance checklist?

Short answer

A HIPAA checklist works through the three rules that bind a security program: the Security Rule (administrative, physical and technical safeguards for electronic PHI), the Privacy Rule (how PHI may be used and disclosed, and what you owe patients), and the Breach Notification Rule (who you tell, and by when). The items below are the duties the regulation names, with their section numbers. No checklist makes you compliant, because HIPAA has no certificate: what you show is a documented program.

Last updated

Step by step

  1. Settle your role and your scope. Decide whether you are a covered entity, a business associate, or both, and map every place ePHI flows. Everything after this depends on getting it right.
  2. Run the risk analysis and act on it. The risk analysis at §164.308(a)(1)(ii)(A) and risk management at §164.308(a)(1)(ii)(B) are the first two items in the Security Rule for a reason. Document both.
  3. Name a security official and a privacy official. §164.308(a)(2) requires an identified security official. The Privacy Rule requires a privacy official and a contact for complaints at §164.530(a).
  4. Work the administrative safeguards. Workforce security and termination procedures (§164.308(a)(3)), information access management (§164.308(a)(4)), awareness and training (§164.308(a)(5)), security incident procedures (§164.308(a)(6)), a contingency plan with backup, disaster recovery and emergency mode operation (§164.308(a)(7)), and periodic evaluation (§164.308(a)(8)).
  5. Work the physical and technical safeguards. Facility access, workstation use and security, and device and media controls including disposal and media re-use (§164.310). Access control with unique user identification and emergency access, audit controls, integrity, authentication and transmission security (§164.312).
  6. Get the contracts in place. A signed business associate agreement with every vendor that handles PHI for you, and with every subcontractor that handles it for them (§164.308(b), §164.314(a), §164.504(e)). Sign before any PHI moves, and keep a list of who holds one.
  7. Meet the Privacy Rule duties you cannot elect out of. Minimum necessary (§164.502(b), with the implementation specifications at §164.514(d)), a notice of privacy practices (§164.520), individual rights including access (§164.524), amendment (§164.526) and an accounting of disclosures (§164.528), and the administrative requirements at §164.530: training, safeguards, complaints, sanctions, no retaliation and no waiver of rights.
  8. Write the breach deadlines into your incident plan. Individuals: without unreasonable delay and no later than 60 calendar days after discovery (§164.404(b)). Media, for a breach affecting more than 500 residents of a State or jurisdiction: the same outer limit (§164.406). HHS: contemporaneously for 500 or more individuals, and within 60 days of year end for smaller breaches (§164.408). A business associate tells the covered entity within 60 days (§164.410). The burden of proof that no breach occurred is yours (§164.414(b)).
  9. Keep the paperwork for six years. Policies, procedures and the records of required actions, activities and assessments are retained for six years from creation or the date last in effect, whichever is later (§164.316(b)(2)(i) for the Security Rule, §164.530(j)(2) for the Privacy Rule).

Required and Addressable are not optional and mandatory

Inside the Security Rule each implementation specification is labelled Required or Addressable, and §164.306(d) is the only place those words are defined. A Required specification you implement. An Addressable one you assess: implement it, implement an equivalent alternative measure, or document why neither is reasonable and appropriate for your organization. Reading Addressable as "skip it" is the single most common error in a self-assessed HIPAA program, and the documentation of the decision is itself part of the duty.

The parts of HIPAA a checklist usually skips

Most checklists stop at the Security Rule because it reads like a control framework. The Privacy Rule carries duties that bind whether or not you ever make an optional disclosure, including minimum necessary, the notice of privacy practices, patient access, and the prohibitions on selling PHI and on using it for genetic-information underwriting. If you hold records for a provider, your product has to let that provider answer an access request (§164.524) and an amendment request (§164.526).

There is no HIPAA certification

No government body certifies HIPAA compliance, and any badge claiming otherwise is a vendor’s own. What you can produce is a risk analysis, a set of policies and procedures, training records, your BAAs, and evidence that your safeguards run. That package is what a customer’s security review and an OCR investigation both ask for.

Where Keel fits

Keel ships HIPAA as the regulation’s own sections rather than a vendor checklist, with every Required and Addressable specification in subpart C as a scored row, plus the Breach Notification Rule and the Privacy Rule provisions that impose duties. Controls you already run for SOC 2 or ISO 27001 carry across through the crosswalk, so the new work is the part nothing you run covers yet.

FAQ

Is there an official HIPAA compliance checklist?

No. HHS publishes guidance and a free Security Risk Assessment Tool, but there is no official checklist and no certificate. The regulation itself, 45 CFR Parts 160 and 164, is the only authoritative list of duties.

What are the HIPAA rules a security program has to meet?

The Privacy Rule, the Security Rule and the Breach Notification Rule. The Enforcement Rule governs how HHS investigates and penalizes, and the transaction, code set and identifier standards in 45 CFR Part 162 matter mainly to those who run covered transactions.

How long do we keep HIPAA records?

Six years from the date of creation or the date the document was last in effect, whichever is later. State law and your retention policy may require longer for medical records, which is a separate obligation from HIPAA documentation.

Do we need a BAA with our cloud provider?

If it stores, processes or transmits PHI for you, yes, even where it never accesses the data. Major cloud providers publish a BAA covering their in-scope services.

Does HIPAA require encryption?

It is addressable rather than required, so you either encrypt, use an equivalent measure, or document why neither is reasonable and appropriate. Encryption to HHS guidance also keeps a loss of data out of the breach notification rules, which is why most programs simply encrypt.

Next step

Get audit-ready with Keel

The AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.