Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

HIPAA compliance checklist covering Privacy Rule, Security Rule, breach notification and BAAs

HIPAA Compliance Checklist for Vendors & Small Practices

A practical HIPAA compliance checklist turns a complex law into a clear set of actions. Whether you are a small practice, a growing vendor, or a business associate, working through a structured checklist is the surest way to cover every requirement. This guide gives you that checklist, organised by the HIPAA rules.

HIPAA compliance checklist covering Privacy Rule, Security Rule, breach notification and BAAs

For the wider context, see our complete HIPAA guide.

The HIPAA compliance checklist at a glance

At the highest level, HIPAA compliance means being able to evidence five things: a completed risk assessment, appropriate safeguards for protected health information, documented privacy and security policies, trained staff, and processes for breaches and business associates. Everything below expands these into concrete, checkable items.

Privacy Rule checklist

  • Documented privacy policies covering permitted uses and disclosures of PHI.
  • A Notice of Privacy Practices provided to individuals.
  • Procedures for patient rights — access, amendment, and accounting of disclosures.
  • The “minimum necessary” standard applied to PHI use.
  • A designated privacy official.

Security Rule checklist

  • A completed and current security risk assessment.
  • Administrative safeguards — risk management, workforce training, access management.
  • Physical safeguards — facility access, workstation and device controls.
  • Technical safeguards — access controls, encryption, audit logs, integrity controls.
  • A designated security official.
  • Contingency, backup, and disaster recovery plans.

Breach notification and business associates

  • A breach detection, assessment, and notification procedure that meets required timelines.
  • A breach log and records of any incidents.
  • Signed Business Associate Agreements with every vendor that handles PHI.
  • Ongoing oversight of business associates.
  • Retention of all HIPAA documentation for six years.

Common HIPAA compliance gaps

The most frequent shortfalls are a missing or outdated risk assessment, incomplete Business Associate Agreements, policies that exist but are not followed or trained, and no documented breach-response procedure. Closing these four areas addresses the majority of typical gaps and puts you on solid ground — and a mapped toolkit makes closing them quick.

Work through HIPAA with confidence.

Our HIPAA Toolkit gives you every policy, procedure, and template on this checklist — risk assessment, safeguards, breach response, and Business Associate Agreement — in Word and Excel.

Get the HIPAA Toolkit →

Frequently asked questions

What is on a HIPAA compliance checklist?

A completed risk assessment; administrative, physical, and technical safeguards; documented privacy and security policies; workforce training; breach-notification procedures; and signed Business Associate Agreements — all retained for six years.

How do small practices become HIPAA compliant?

By working through the same requirements proportionately — a risk assessment, safeguards, policies, training, breach procedures, and business associate agreements — scaled to their size.

What are the most common HIPAA compliance gaps?

A missing or outdated risk assessment, incomplete Business Associate Agreements, policies that are not followed or trained, and no documented breach-response procedure.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.