Checklist · 19 items · Updated July 2026

HIPAA Compliance Checklist

PHI, handled properly.

HIPAA has no certificate — compliance is a defensible posture you can evidence when a customer, partner, or regulator asks. This checklist is scoped for health-tech companies acting as business associates.

01 Establish the foundation

  • Determine your status: covered entity or business associate (most health-tech is the latter)
  • Complete the Security Risk Analysis — the single most-cited gap in OCR enforcement
  • Document where PHI lives, flows, and leaves: systems, vendors, endpoints
  • Appoint a security official and a privacy official (can be one person, must be named)
  • Write the HIPAA policy set: privacy, security, breach notification, sanctions

02 Contracts and people

  • Execute Business Associate Agreements with every vendor touching PHI — no BAA, no PHI
  • Sign BAAs upstream with covered-entity customers on terms you can actually meet
  • Run HIPAA training at onboarding and annually, with completion records
  • Enforce a sanction policy for violations — documented, not theoretical

03 Technical safeguards

  • Encrypt PHI at rest and in transit, everywhere it exists
  • Enforce unique accounts, MFA, and role-based access to PHI systems
  • Enable audit logging on every system that stores or processes PHI
  • Implement automatic session timeout and device encryption on endpoints
  • Establish data backup and a tested disaster recovery capability
  • De-identify or minimize PHI in non-production environments

04 Breach readiness

  • Write the incident response plan with HIPAA's breach assessment built in
  • Know the clocks: individual notification within 60 days; HHS reporting per breach size
  • Run at least one tabletop exercise a year and record it
  • Maintain six years of documentation retention — policies, risk analyses, training records

The enforcement pattern is remarkably consistent: OCR’s most common findings are a missing or stale Security Risk Analysis and missing BAAs. Those two items are also the cheapest on this list — do them first, and refresh the risk analysis whenever your architecture meaningfully changes, not just annually.

Don't Want to Run This Yourself?

HIPAA Compliance Services

HIPAA compliance services for healthtech and covered entities: security risk analysis, safeguards implementation, BAA management, and breach-ready procedures.

Book a Call
Frequently Asked
Is there an official HIPAA certification?

No. Vendors selling 'HIPAA certification' are selling attestations of their own design. What exists: your documented risk analysis, safeguards, and BAAs — the package OCR or an enterprise customer reviews.

Do we need HIPAA if we never see patient data directly?

If PHI transits or rests in your systems — even encrypted, even briefly — you're likely a business associate and HIPAA applies. The determining factor is data flow, not product category.

How does HIPAA overlap with SOC 2?

Heavily on technical safeguards: access control, encryption, logging, incident response. Teams commonly run SOC 2 plus a HIPAA mapping from one control set — the deltas are the risk analysis, BAAs, and breach-notification machinery.