

Audit Ready HIPAA Checklist: 6 Areas U.S. Practices Must Document
A defensible HIPAA compliance checklist covers six areas: applicability scope, a documented risk analysis, administrative and physical and technical safeguards, business associate governance, breach response, and audit-ready evidence. If you do nothing else this week, start a Security Risk Assessment and name a Security Officer and Privacy Officer in writing. Anchor both to the HHS/OCR guidance on risk analysis and the ONC SRA Tool.
TL;DR:
- A completed risk assessment, appointment of a Security Officer, and documented asset inventory are immediate priorities for demonstrating HIPAA compliance.
- Regularly updating the risk register, policies, and vendor management files are essential for maintaining audit readiness over the required six-year documentation retention period.
- Technical safeguards like multi-factor authentication, encryption, and log reviews are critical controls that must be evidenced through ongoing records to satisfy OCR expectations.
- Physical safeguards, including locked facilities, encrypted devices, and secure media disposal, form a crucial part of protecting ePHI and are scrutinized during audits.
- Adopting a disciplined approach to incident response and continuous monitoring, especially after breaches, supports compliance with evolving enforcement priorities emphasizing tangible evidence.
Table of Contents
Table of Contents
- Who Needs a HIPAA Compliance Checklist?
- What Does a Full HIPAA Checklist Look Like, Start to Finish?
- How Do You Conduct a Defensible Security Risk Assessment?
- What Administrative Safeguards Does HIPAA Require?
- What Physical Safeguards Protect PHI in Your Office?
- What Technical Safeguards Do Auditors Actually Check?
- What Happens in the First Hour After a Breach?
- How Do You Govern Business Associates Beyond a Signature?
- What Documents Do You Need for an OCR Audit?
- How Should You Prioritize Remediation?
- How tekrescue Helps SMBs Get Audit-Ready
- Perspective: Why Evidence Is the New Compliance Currency
- Need Help Turning This Checklist Into a Program?
- Sources
- FAQ
Who Needs a HIPAA Compliance Checklist?
Two categories of organizations owe HIPAA obligations: covered entities and business associates. A covered entity is a health plan, health care clearinghouse, or provider that transmits health information electronically in connection with a covered transaction. A business associate is any vendor or contractor that creates, receives, maintains, or transmits protected health information (PHI) on a covered entity’s behalf, from billing companies to IT support firms to cloud hosting providers.
Run this three-question test to find out where you stand:
- Do you create, receive, maintain, or transmit PHI as part of delivering care, processing claims, or supporting a provider?
- Do you store, process, or transmit electronic PHI (ePHI) on servers, laptops, cloud platforms, or third-party software?
- Do you perform services (billing, IT, legal, cleaning with facility access, answering services) for a covered entity that puts you in contact with PHI, even indirectly?
Answer yes to any of these and the checklist applies to you. If the answer is murky, the smart move is a scoped risk assessment rather than a guess. Attorneys often get this call wrong because HIPAA applicability turns on function, not job title. A billing vendor that never opens a chart still touches PHI the moment it processes a claim. Legal practices handling medical records for litigation face the same exposure, a topic covered in more detail in this breakdown of HIPAA compliance for legal practices. If you answer yes, move through the rest of this checklist in order. If you are unsure, get a scoped assessment or legal opinion before you assume you are exempt.
What Does a Full HIPAA Checklist Look Like, Start to Finish?
Think of this as the project plan you hand to whoever owns compliance at your organization. Each step below produces a specific deliverable, and knowing which ones are one-time setup versus ongoing maintenance changes how you staff it.
- Appoint a Privacy Officer and Security Officer. Deliverable: signed role descriptions with authority to enforce policy. One-time, reviewed annually.
- Build an asset inventory. Deliverable: spreadsheet or CMDB listing every system, device, and location touching ePHI. Ongoing, updated quarterly.
- Run a Security Risk Assessment. Deliverable: a documented risk register with scores and remediation owners. Annual minimum, more often after major IT changes.
- Draft or update policies. Deliverable: a policy library with version history and approval signatures. Reviewed at least yearly.
- Execute Business Associate Agreements. Deliverable: signed BAAs filed with renewal dates tracked. Ongoing as vendors change.
- Remediate technical gaps. Deliverable: closed tickets referencing the risk register (MFA rollout, encryption, patching). Continuous.
- Train the workforce. Deliverable: training rosters with signed acknowledgments. Onboarding plus annual refreshers.
- Build an incident response plan. Deliverable: a written IR plan with named roles and a tested notification process. Reviewed annually, tested after incidents.
- Assemble documentation for audit readiness. Deliverable: an indexed evidence packet. Continuous upkeep, six-year retention.
How Do You Conduct a Defensible Security Risk Assessment?
The Security Rule treats risk analysis as a required, ongoing implementation specification, not a one-time form you file and forget. HHS guidance on risk analysis is explicit that assessments must be accurate, thorough, and continuously updated as systems and threats change. That framing matters because OCR investigators routinely find that organizations ran an SRA years ago, filed it, and never touched it again.
A defensible risk analysis needs these components documented, not just performed:
- Defined scope. List every location, system, application, and device that creates, receives, maintains, or transmits ePHI, including remote offices and cloud environments.
- Asset inventory with ownership. Each asset needs a named owner, a criticality rating, and a note on what ePHI it touches.
- Dataflow mapping. Trace how ePHI moves between your systems, your EHR vendor, billing clearinghouses, and any subcontractors.
- Threat and vulnerability identification. Catalog realistic threats (phishing, lost devices, unpatched servers) against each asset.
- Likelihood and impact scoring. Score each risk using a consistent methodology; many organizations map this against NIST SP 800-66 or the NIST Cybersecurity Framework crosswalk for consistency.
- A risk register. Every identified risk needs an owner, a remediation priority, a target date, and, where a risk is accepted rather than fixed, a documented rationale for that acceptance.
- Reviewer sign-off. Record who reviewed and approved the SRA, and when, so the document itself becomes evidence.
The ONC Security Risk Assessment Tool, currently at version 3.6.1, gives small and medium providers a structured, question-based way to produce this output without building a methodology from scratch. It uses branching logic aligned to NIST scoring and stores reports locally, which makes it a reasonable starting point for a practice with a few dozen employees. Larger organizations with complex vendor networks usually need a tailored assessment that maps more directly to NIST SP 800-66, since the SRA Tool is informational and does not by itself guarantee compliance.
Pro Tip: Rerun your risk analysis any time you change EHR vendors, add a new cloud application, or open a new location. A static risk register from two years ago is one of the fastest ways to fail an OCR review, because it signals the assessment stopped being “ongoing” the day it was filed.
What Administrative Safeguards Does HIPAA Require?
Administrative safeguards are the governance layer, and they are where most small practices lose points during a review because the policies exist but nobody can produce evidence they were followed.
Start with people. Designate a Privacy Officer and a Security Officer with written job descriptions that spell out their authority to enforce policy, approve exceptions, and sign off on the risk register. These can be the same person in a small organization, but the authority needs to be documented, not assumed.
Next comes your policy inventory. HIPAA does not hand you a template; it expects a defined set of policies covering access management, workforce sanctions, device use, breach response, and data retention, each with a documented review cadence, typically annual. A policy nobody has updated since 2019 is a liability, not a safeguard.
Workforce training follows close behind:
- Role-based curricula, so front-desk staff and IT admins get different training content matched to their access levels.
- Onboarding training completed before system access is granted, not weeks after.
- Annual refreshers, tracked with rosters and signed acknowledgments.
- A sanction policy that spells out consequences for violations, applied consistently.
Access governance closes the loop: periodic access reviews tied to HR’s joiner, mover, and leaver process, so a terminated employee’s credentials are revoked the same day, not the following month.
Vendor governance rounds out administrative safeguards. Maintain a business associate inventory, assign each vendor a risk tier based on what PHI they touch, define minimum security requirements per tier, and require BAA clauses that address breach notification timelines, subcontractor flow-down, and data return or destruction on termination. Monitor higher-tier vendors on a recurring attestation cycle rather than a signature you file once and never revisit.
What Physical Safeguards Protect PHI in Your Office?
Physical safeguards get overlooked because they feel less technical, but OCR treats a stolen laptop or an unattended server room exactly as seriously as a network breach.
- Controlled facility access. Server rooms and areas with PHI-bearing devices need locked access, with visitor logs and badge records kept as evidence.
- Workstation controls. Automatic screen locks after a short idle period, positioned screens away from public view, and secure storage for any portable media at the end of the day.
- Device inventory with encryption. Every laptop, tablet, and portable drive that could hold ePHI needs to be logged, and full-disk encryption should be the default, not the exception.
- Secure media disposal. Old hard drives and backup tapes need a documented chain of custody through destruction, with certificates of destruction filed as proof.
- Remote-work provisions. Home offices need the same baseline expectations: locked storage for any printed PHI, privacy screens, and a policy prohibiting personal devices from accessing ePHI without controls in place.
A practice that moved to hybrid work during the past few years and never updated its physical safeguards policy to cover home offices has a real gap, and it is one auditors ask about directly.
What Technical Safeguards Do Auditors Actually Check?
Technical safeguards are where the evidence trail matters most, because these controls generate logs and reports almost automatically, and auditors expect you to have kept them.
- Access controls. Unique user IDs for every person touching ePHI, multi factor authentication across email and remote access, and role-based permissions reviewed on a set schedule with the recertification results logged.
- Encryption. Document where encryption is applied, in transit and at rest. If you decide not to encrypt something, HIPAA allows that, but only with a documented risk-based rationale explaining why.
- Audit logging. Retain system access logs long enough to support an investigation, and review them on a defined cadence rather than only after something goes wrong.
- Vulnerability management. Scheduled vulnerability scans, patch service-level agreements tied to severity, and remediation tickets that get closed with a rescan, not just a status change.
- Backup and restore. A documented backup schedule, encrypted backups, and periodic restore tests with dates and outcomes recorded. A backup nobody has test-restored is not a backup, it is a hope.
One dynamic worth naming directly: OCR’s enforcement posture and its proposed Security Rule updates increasingly emphasize demonstrable evidence over stated policy. An organization that says it patches promptly but cannot produce a ticket history is treated skeptically. The tekrescue 5 cybersecurity controls every small business needs outlines the baseline most SMBs are missing, MFA, patching, backups, endpoint protection, and monitoring, each of which maps directly to a technical safeguard here.
What Happens in the First Hour After a Breach?
Breach response is not the time to improvise, and OCR expects a written plan that names roles before an incident, not during one.
- Contain and preserve evidence. Isolate affected systems, but avoid wiping devices before forensic evidence is captured. Assign one person as incident commander.
- Assess whether PHI was compromised. Determine what data was accessed, whether it was encrypted, and how many individuals are affected. This assessment determines your reporting obligations.
- Apply the breach threshold test. Most unauthorized PHI disclosures are presumed breaches unless you can demonstrate a low probability that the information was compromised, using a documented risk assessment of the incident itself.
- Report to OCR on the required timeline. Breaches affecting 500 or more individuals require notification without unreasonable delay; smaller breaches can be reported annually. File through the OCR breach reporting portal, which specifies the required fields for each submission.
- Notify affected individuals and, where required, the media. Have patient notification and media statement templates drafted in advance so a crisis does not turn into a drafting exercise. A ready-made structure like this incident response plan template saves critical hours.
- Conduct a post-incident review. Document lessons learned, update the risk register with new findings, and retain every artifact from the incident, since these records become part of your audit-readiness packet.
How Do You Govern Business Associates Beyond a Signature?
A signed BAA is the floor, not the finish line. Real BA governance means tracking exposure over time.
- Maintain a BA inventory listing every vendor, the exposure tier they represent, and current contract and renewal dates.
- Define minimum security controls per tier and request evidence to back them up: SOC 2 reports, signed security attestations, or completed vendor security questionnaires for higher-risk vendors like EHR hosts or billing processors.
- Keep a BAA clause checklist covering breach notification timelines, subcontractor flow-down requirements, and PHI return or destruction obligations at contract end.
- Have a defined escalation path for when a BA fails to meet expectations, ranging from a corrective action plan to contract termination.
- Build an offboarding checklist for departing vendors and employees alike: revoke system access same-day, confirm PHI return or destruction in writing, and log the date credentials were disabled.
Radiology groups working with outside imaging or teleradiology vendors face a version of this same exposure, since those partners routinely handle PHI-laden studies across systems, which makes vendor tiering especially important for that specialty.
What Documents Do You Need for an OCR Audit?
HHS guidance sets a six-year retention requirement for HIPAA-related documentation, measured from the date of creation or the date it was last in effect. That single number should shape your entire filing system.
Retain, at minimum: current and prior risk analyses, your risk management plan, all policies with version history, training logs with signed acknowledgments, signed BAAs, incident and breach logs, vulnerability scan and patch reports, and backup restore-test results.
- Every document needs version control: a date, an approver name, and a signature, digital or otherwise.
- Training records need individual acknowledgments, not just a headcount summary.
- Remediation tickets should link back to the specific risk register entry they closed, so an auditor can trace a fix to the risk that prompted it.
Build what amounts to an OCR defensibility packet: an indexed folder or shared drive containing the risk analysis, asset inventory and dataflow map, policy library, access governance records, vulnerability management artifacts, incident logs with post-incident reviews, backup and restore evidence, and BA governance files. Assign one person to keep it current and sign off on quarterly updates.
Pro Tip: Index the defensibility packet by safeguard category (administrative, physical, technical) rather than by date. An auditor asking “show me your access control evidence” wants a folder, not a timeline you have to reconstruct on the spot.
How Should You Prioritize Remediation?
Not every gap deserves the same urgency, and trying to fix everything at once is how remediation projects stall.
- First 90 days: quick wins. Roll out MFA everywhere it is missing, tighten encryption settings on portable devices, and clear any critical unpatched vulnerabilities. These are cheap, fast, and close the highest-likelihood risks first.
- Days 91 to 180: medium projects. Segment networks to isolate ePHI systems, reassess higher-risk business associates, and formalize access recertification schedules.
- Days 181 to 365: long-term projects. Address architecture-level changes, such as EHR platform migrations or a full identity management overhaul, that need budget cycles and vendor coordination.
Assign a named owner and clear acceptance criteria to every item, and require evidence before marking anything closed, a patch ticket, a rescan result, an updated policy with a signature. Bring in outside specialists for items requiring expertise you do not have in house, such as a formal penetration test or a NIST-mapped assessment for a multi-location organization, and have your asset inventory and current policies ready before that engagement starts so the specialist is not rebuilding groundwork you already have.
How tekrescue Helps SMBs Get Audit-Ready
Services exist to help small and medium healthcare practices, CPA firms, and other regulated businesses implement this checklist, including risk assessments, managed IT support, and technical remediation projects. Our 8-step risk assessment methodology and the five essential cybersecurity controls framework map directly to the administrative and technical safeguards covered above.
Before reaching out, pull together what you already have: an asset inventory if one exists, your current business associate list, and whatever policies are already written down, even outdated ones. That head start shortens the scoping conversation considerably.

Perspective: Why Evidence Is the New Compliance Currency
OCR’s enforcement posture and its proposed Security Rule updates point in one direction: auditable evidence over stated intent. A policy that says you patch systems monthly means little without ticket histories to back it up. That shift rewards organizations that treat asset inventories, MFA logs, and patch tickets as living records, not paperwork produced once and filed away. For a small practice with limited staff, the resource-light move is starting there, not with an expensive audit, since evidence generation is mostly a discipline problem, not a budget problem.
— Randy Bryan
Need Help Turning This Checklist Into a Program?
Reading a checklist and running one under deadline pressure are different problems, and most SMBs hit resource limits somewhere between the risk analysis and the technical remediation. Managed IT and cybersecurity teams can handle the parts that consume the most staff time: running Security Risk Assessments, closing technical safeguard gaps, and building business associate governance programs that support audit readiness. If you already have SRA output from the ONC tool or an internal review, we can start remediation immediately instead of repeating discovery work.

The fastest way to see where you stand is a scoping conversation about your current environment, your BA relationships, and what documentation already exists. Start with our cybersecurity risk assessment checklist to see the exact steps involved, or explore managed IT services for small business if ongoing monitoring and patch management are the bigger gap. Either page gets you to a real conversation about your specific environment, not a generic sales pitch.
Sources
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
FAQ
What Is a HIPAA Compliance Checklist?
A HIPAA compliance checklist is a structured list of the safeguards, policies, and documentation an organization needs to meet HIPAA’s Privacy and Security Rule requirements, covering risk analysis, administrative and physical and technical safeguards, business associate governance, and breach response.
What Are the HIPAA Compliance Requirements?
The core requirements are conducting an ongoing risk analysis, implementing administrative, physical, and technical safeguards, signing business associate agreements, maintaining breach notification procedures, and retaining supporting documentation for at least six years, per HHS guidance.
Are There New HIPAA Requirements Coming?
HHS has proposed updates to the Security Rule that would tighten expectations around documented, auditable cybersecurity evidence, including asset inventories and multi factor authentication, though organizations should track final rulemaking through HHS.gov rather than assuming any date-specific change is final.
Is There a Free HIPAA Compliance Checklist Tool Available?
Yes. The ONC Security Risk Assessment Tool is a free, government-provided tool that helps small and medium providers document a security risk assessment, though it does not guarantee compliance on its own.
Do Business Associates Need Their Own HIPAA Checklist?
Yes. Business associates carry direct HIPAA obligations for the PHI they handle, including safeguards, breach notification, and BAA compliance, separate from the covered entities they serve.
Recommended
Table of Contents











