Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

HIPAA policies checklist including privacy, security, risk assessment and breach notification

HIPAA Required Policies & Documentation Checklist

Well-written HIPAA policies are the backbone of any compliance programme. The HIPAA rules require covered entities and business associates to adopt documented policies and procedures, and auditors and investigators will expect to see them. This guide explains which policies HIPAA requires, the supporting documentation you need, and how to produce it efficiently.

HIPAA policies checklist including privacy, security, risk assessment and breach notification

For the wider context, see our complete HIPAA guide.

Why HIPAA policies matter

Both the Privacy Rule and the Security Rule explicitly require documented policies and procedures, kept for a defined retention period. These policies translate HIPAA’s requirements into clear instructions your workforce can follow, and they are the primary evidence that you take compliance seriously. Without them, even strong technical safeguards leave you exposed — which is why building a complete, tailored policy set is a foundational step.

Essential HIPAA policies

Most organizations need policies covering:

  • Privacy policy — permitted uses and disclosures of PHI and patient rights.
  • Security policy — the administrative, physical, and technical safeguards for ePHI.
  • Risk assessment and risk management — identifying and treating risks to PHI.
  • Access control policy — who may access PHI and how access is managed.
  • Workforce training and sanctions — training staff and enforcing the rules.
  • Breach notification policy — detecting, assessing, and reporting breaches.
  • Business associate management — agreements and oversight of vendors.
  • Contingency and data backup — maintaining availability of ePHI.
  • Device, media, and disposal policies — handling PHI throughout its lifecycle.

Supporting documentation and records

Alongside policies, HIPAA expects records that evidence compliance in action — a completed risk assessment, training logs, access reviews, Business Associate Agreements, breach assessments, and audit trails. These records demonstrate that your policies are not just written but actually followed, which is exactly what an investigation examines. HIPAA generally requires such documentation to be retained for six years.

How to produce HIPAA documentation efficiently

Authoring a full HIPAA policy suite from scratch is slow and easy to get wrong, particularly across both the Privacy and Security Rules. Starting from a mapped set of templates gives you a complete, rule-aligned baseline you can tailor to your organization — ensuring coverage while letting you focus on the specifics of your environment. It is the fastest route to an audit-ready documentation set.

Every required policy, ready to adapt.

Our HIPAA Toolkit includes the privacy and security policies, risk assessment, training and breach procedures, and Business Associate Agreement — mapped to the HIPAA rules and editable in Word and Excel.

Get the HIPAA Toolkit →

Frequently asked questions

What policies are required for HIPAA?

Documented privacy and security policies, plus supporting policies for risk assessment, access control, workforce training, breach notification, business associate management, and contingency planning.

How long must HIPAA documentation be kept?

HIPAA generally requires policies, procedures, and related documentation to be retained for six years from the date of creation or last effective date.

Are HIPAA policy templates acceptable?

Yes. Using templates is standard practice, provided the policies are tailored to your organization and actually implemented and followed.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.