A practical HIPAA compliance checklist turns a complex law into a clear set of actions. Whether you are a small practice, a growing vendor, or a business associate, working through a structured checklist is the surest way to cover every requirement. This guide gives you that checklist, organised by the HIPAA rules.

For the wider context, see our complete HIPAA guide.
The HIPAA compliance checklist at a glance
At the highest level, HIPAA compliance means being able to evidence five things: a completed risk assessment, appropriate safeguards for protected health information, documented privacy and security policies, trained staff, and processes for breaches and business associates. Everything below expands these into concrete, checkable items.
Privacy Rule checklist
- Documented privacy policies covering permitted uses and disclosures of PHI.
- A Notice of Privacy Practices provided to individuals.
- Procedures for patient rights — access, amendment, and accounting of disclosures.
- The “minimum necessary” standard applied to PHI use.
- A designated privacy official.
Security Rule checklist
- A completed and current security risk assessment.
- Administrative safeguards — risk management, workforce training, access management.
- Physical safeguards — facility access, workstation and device controls.
- Technical safeguards — access controls, encryption, audit logs, integrity controls.
- A designated security official.
- Contingency, backup, and disaster recovery plans.
Breach notification and business associates
- A breach detection, assessment, and notification procedure that meets required timelines.
- A breach log and records of any incidents.
- Signed Business Associate Agreements with every vendor that handles PHI.
- Ongoing oversight of business associates.
- Retention of all HIPAA documentation for six years.
Common HIPAA compliance gaps
The most frequent shortfalls are a missing or outdated risk assessment, incomplete Business Associate Agreements, policies that exist but are not followed or trained, and no documented breach-response procedure. Closing these four areas addresses the majority of typical gaps and puts you on solid ground — and a mapped toolkit makes closing them quick.
Work through HIPAA with confidence.
Our HIPAA Toolkit gives you every policy, procedure, and template on this checklist — risk assessment, safeguards, breach response, and Business Associate Agreement — in Word and Excel.
Frequently asked questions
What is on a HIPAA compliance checklist?
A completed risk assessment; administrative, physical, and technical safeguards; documented privacy and security policies; workforce training; breach-notification procedures; and signed Business Associate Agreements — all retained for six years.
How do small practices become HIPAA compliant?
By working through the same requirements proportionately — a risk assessment, safeguards, policies, training, breach procedures, and business associate agreements — scaled to their size.
What are the most common HIPAA compliance gaps?
A missing or outdated risk assessment, incomplete Business Associate Agreements, policies that are not followed or trained, and no documented breach-response procedure.