Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

HIPAA Implementation — guide from Governance Docs

How to Implement HIPAA: A Ten-Step Plan

HIPAA implementation has no certificate at the end and no auditor booked in the
diary. That is exactly why it drifts: the work has no forcing function until a breach or a complaint
creates one. This is a ten-step plan that produces the evidence OCR actually asks for when that day
comes.

Before step one of HIPAA implementation: establish what you are

Everything in a HIPAA implementation follows from this. A covered entity is a health plan, a health care
clearinghouse, or a provider who transmits health information electronically in connection with a
covered transaction. A business associate creates, receives, maintains or transmits
protected health information on behalf of one. Many organisations are business associates without
realising it — and business associates have been directly liable under the Security Rule since
the 2013 Omnibus Rule, not merely contractually liable.

The ten steps of HIPAA implementation

  1. Determine your status and scope (1–2 weeks). The first move in any HIPAA implementation. Covered entity, business
    associate, or hybrid entity. If you are a hybrid, designate the health care components formally.
  2. Appoint a Privacy Official and a Security Official (1 week). Both are required
    by rule. They can be the same person in a small organisation, but the appointment must be
    documented.
  3. Inventory ePHI (3–5 weeks). Every system, device, backup, vendor and cloud
    service that touches it. The first pass always misses something.
  4. Security risk analysis (4–8 weeks). The required implementation
    specification at 45 CFR §164.308(a)(1)(ii)(A), and the foundation of any defensible position.
    See our guide to the HIPAA risk assessment template.
  5. Risk management (ongoing from week 8). Reduce the risks you found to a
    reasonable and appropriate level, with owners and dates. Identifying risks and doing nothing is the
    most cited failing in OCR settlements.
  6. Policies and procedures (6–10 weeks). Administrative, physical and
    technical safeguards, plus the Privacy Rule policies. See HIPAA policies.
  7. Business associate agreements (3–6 weeks). Identify every business
    associate, execute agreements, and do proportionate due diligence. See the
    HIPAA business associate agreement guide.
  8. Notice of Privacy Practices and individual rights (2–4 weeks). Publish the
    notice and build the workflow for access, amendment, accounting of disclosures and restriction
    requests. See our guide to the
    notice of privacy practices.
  9. Workforce training and sanctions (2–4 weeks, then ongoing). Training is
    required, and so is a sanction policy that is actually applied.
  10. Incident and breach response (2–3 weeks, then exercised). A four-factor
    risk assessment to decide whether an impermissible use or disclosure is a reportable breach, and the
    notification workflow behind it.

160+ templates and the risk analysis workbook.

The HIPAA Toolkit covers the security risk analysis, the full policy set across administrative, physical and technical safeguards, business associate agreements, the notice of privacy practices and the breach response pack — with a regulatory currency statement in every document.

Explore the HIPAA Toolkit →

The three steps HIPAA implementation always underestimate

Step 4, the risk analysis. Treated as a questionnaire, and it is the single most
examined artefact in any OCR investigation. A checklist is not a risk analysis, and OCR has said so
consistently for more than a decade.

Step 7, business associate agreements. Organisations sign the agreements and stop
there. The obligation includes knowing who your business associates are — which means an
inventory that tracks new vendors — and taking action if you become aware of a pattern of
breach.

Step 10, breach response. Written once, never rehearsed. The four-factor
assessment is a judgement call made under time pressure, and the individual notification deadline is
60 days from discovery. Run a tabletop before you need it.

What HIPAA implementation does not require

There is no HIPAA certification. No body accredits HIPAA compliance, and any vendor selling you a
“HIPAA certified” badge is selling a marketing artefact rather than a regulatory status. What exists
is evidence: a current risk analysis, applied policies, executed agreements, trained staff and a
documented history of acting on what you found. Retain it all for six years, which
is the documentation requirement at §164.316(b).

Nor does HIPAA prescribe specific technologies today. The Security Rule is deliberately
technology-neutral and risk-based — though the proposed overhaul would change that
substantially. See our HIPAA Security Rule update.

A realistic total for HIPAA implementation

Four to nine months to a defensible position for a mid-sized provider or a
business associate with an existing security function, and longer where ePHI is spread across many
systems or the organisation has grown by acquisition. If you already hold ISO 27001, steps 3 to 6
largely transfer — the security work is done, and what remains is the Privacy Rule content,
business associate management and the HIPAA-specific documentation. But HIPAA implementation does not
finish: the risk analysis has to track the business, and one that has not moved in three years is
itself the finding. Start with the HIPAA compliance checklist or the
free HIPAA templates.

References

More on HIPAA

All of these are covered by the HIPAA Toolkit, or start with the free HIPAA templates.

Implementation guides for the other standards

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.