HIPAA implementation has no certificate at the end and no auditor booked in the
diary. That is exactly why it drifts: the work has no forcing function until a breach or a complaint
creates one. This is a ten-step plan that produces the evidence OCR actually asks for when that day
comes.
Before step one of HIPAA implementation: establish what you are
Everything in a HIPAA implementation follows from this. A covered entity is a health plan, a health care
clearinghouse, or a provider who transmits health information electronically in connection with a
covered transaction. A business associate creates, receives, maintains or transmits
protected health information on behalf of one. Many organisations are business associates without
realising it — and business associates have been directly liable under the Security Rule since
the 2013 Omnibus Rule, not merely contractually liable.
The ten steps of HIPAA implementation
- Determine your status and scope (1–2 weeks). The first move in any HIPAA implementation. Covered entity, business
associate, or hybrid entity. If you are a hybrid, designate the health care components formally. - Appoint a Privacy Official and a Security Official (1 week). Both are required
by rule. They can be the same person in a small organisation, but the appointment must be
documented. - Inventory ePHI (3–5 weeks). Every system, device, backup, vendor and cloud
service that touches it. The first pass always misses something. - Security risk analysis (4–8 weeks). The required implementation
specification at 45 CFR §164.308(a)(1)(ii)(A), and the foundation of any defensible position.
See our guide to the HIPAA risk assessment template. - Risk management (ongoing from week 8). Reduce the risks you found to a
reasonable and appropriate level, with owners and dates. Identifying risks and doing nothing is the
most cited failing in OCR settlements. - Policies and procedures (6–10 weeks). Administrative, physical and
technical safeguards, plus the Privacy Rule policies. See HIPAA policies. - Business associate agreements (3–6 weeks). Identify every business
associate, execute agreements, and do proportionate due diligence. See the
HIPAA business associate agreement guide. - Notice of Privacy Practices and individual rights (2–4 weeks). Publish the
notice and build the workflow for access, amendment, accounting of disclosures and restriction
requests. See our guide to the
notice of privacy practices. - Workforce training and sanctions (2–4 weeks, then ongoing). Training is
required, and so is a sanction policy that is actually applied. - Incident and breach response (2–3 weeks, then exercised). A four-factor
risk assessment to decide whether an impermissible use or disclosure is a reportable breach, and the
notification workflow behind it.
160+ templates and the risk analysis workbook.
The HIPAA Toolkit covers the security risk analysis, the full policy set across administrative, physical and technical safeguards, business associate agreements, the notice of privacy practices and the breach response pack — with a regulatory currency statement in every document.
The three steps HIPAA implementation always underestimate
Step 4, the risk analysis. Treated as a questionnaire, and it is the single most
examined artefact in any OCR investigation. A checklist is not a risk analysis, and OCR has said so
consistently for more than a decade.
Step 7, business associate agreements. Organisations sign the agreements and stop
there. The obligation includes knowing who your business associates are — which means an
inventory that tracks new vendors — and taking action if you become aware of a pattern of
breach.
Step 10, breach response. Written once, never rehearsed. The four-factor
assessment is a judgement call made under time pressure, and the individual notification deadline is
60 days from discovery. Run a tabletop before you need it.
What HIPAA implementation does not require
There is no HIPAA certification. No body accredits HIPAA compliance, and any vendor selling you a
“HIPAA certified” badge is selling a marketing artefact rather than a regulatory status. What exists
is evidence: a current risk analysis, applied policies, executed agreements, trained staff and a
documented history of acting on what you found. Retain it all for six years, which
is the documentation requirement at §164.316(b).
Nor does HIPAA prescribe specific technologies today. The Security Rule is deliberately
technology-neutral and risk-based — though the proposed overhaul would change that
substantially. See our HIPAA Security Rule update.
A realistic total for HIPAA implementation
Four to nine months to a defensible position for a mid-sized provider or a
business associate with an existing security function, and longer where ePHI is spread across many
systems or the organisation has grown by acquisition. If you already hold ISO 27001, steps 3 to 6
largely transfer — the security work is done, and what remains is the Privacy Rule content,
business associate management and the HIPAA-specific documentation. But HIPAA implementation does not
finish: the risk analysis has to track the business, and one that has not moved in three years is
itself the finding. Start with the HIPAA compliance checklist or the
free HIPAA templates.
References
- HHS: HIPAA Security Rule — the Security Rule guidance on hhs.gov.
- HHS: Notice of Privacy Practices — what the notice must contain.
More on HIPAA
- HIPAA implementation guide — you are here
- notice of privacy practices
- HIPAA risk assessment template
- HIPAA Security Rule update
- HIPAA risk assessment
- HIPAA compliance checklist
- HIPAA policies
- HIPAA business associate agreement
- Security Rule vs Privacy Rule
- HIPAA compliance explained
All of these are covered by the HIPAA Toolkit, or start with the free HIPAA templates.
Implementation guides for the other standards
- ISO 27001 implementation
- ISO 9001 implementation
- ISO 13485 implementation
- ISO 14001 implementation
- ISO 45001 implementation
- ISO 22301 implementation
- GDPR implementation
- ISO 42001 implementation
- ISO 20000 implementation
- HIPAA implementation — you are here