HIPAA Compliance Checklist
PHI, handled properly.HIPAA has no certificate — compliance is a defensible posture you can evidence when a customer, partner, or regulator asks. This checklist is scoped for health-tech companies acting as business associates.
01 Establish the foundation
- Determine your status: covered entity or business associate (most health-tech is the latter)
- Complete the Security Risk Analysis — the single most-cited gap in OCR enforcement
- Document where PHI lives, flows, and leaves: systems, vendors, endpoints
- Appoint a security official and a privacy official (can be one person, must be named)
- Write the HIPAA policy set: privacy, security, breach notification, sanctions
02 Contracts and people
- Execute Business Associate Agreements with every vendor touching PHI — no BAA, no PHI
- Sign BAAs upstream with covered-entity customers on terms you can actually meet
- Run HIPAA training at onboarding and annually, with completion records
- Enforce a sanction policy for violations — documented, not theoretical
03 Technical safeguards
- Encrypt PHI at rest and in transit, everywhere it exists
- Enforce unique accounts, MFA, and role-based access to PHI systems
- Enable audit logging on every system that stores or processes PHI
- Implement automatic session timeout and device encryption on endpoints
- Establish data backup and a tested disaster recovery capability
- De-identify or minimize PHI in non-production environments
04 Breach readiness
- Write the incident response plan with HIPAA's breach assessment built in
- Know the clocks: individual notification within 60 days; HHS reporting per breach size
- Run at least one tabletop exercise a year and record it
- Maintain six years of documentation retention — policies, risk analyses, training records
The enforcement pattern is remarkably consistent: OCR’s most common findings are a missing or stale Security Risk Analysis and missing BAAs. Those two items are also the cheapest on this list — do them first, and refresh the risk analysis whenever your architecture meaningfully changes, not just annually.
HIPAA Compliance Services
HIPAA compliance services for healthtech and covered entities: security risk analysis, safeguards implementation, BAA management, and breach-ready procedures.
Book a CallIs there an official HIPAA certification?
No. Vendors selling 'HIPAA certification' are selling attestations of their own design. What exists: your documented risk analysis, safeguards, and BAAs — the package OCR or an enterprise customer reviews.
Do we need HIPAA if we never see patient data directly?
If PHI transits or rests in your systems — even encrypted, even briefly — you're likely a business associate and HIPAA applies. The determining factor is data flow, not product category.
How does HIPAA overlap with SOC 2?
Heavily on technical safeguards: access control, encryption, logging, incident response. Teams commonly run SOC 2 plus a HIPAA mapping from one control set — the deltas are the risk analysis, BAAs, and breach-notification machinery.