HIPAA Audit Checklist: What OCR Actually Asks You For
A data request letter from the HHS Office for Civil Rights does not ask whether you are compliant. It names documents, names a date, and expects PDFs. A HIPAA audit checklist is worth building for exactly one reason: when that letter lands, you either have the files or you spend three weeks manufacturing a paper trail that an investigator can date-check against your own systems.
This article walks the document list — administrative, physical, technical, and Privacy Rule — and assigns each item an owner, a refresh cadence, and a description of what acceptable evidence looks like. It is written for the person who signs vendor contracts and answers records requests, not for patients.
What Is on a HIPAA Audit Checklist?
A complete HIPAA audit checklist covers eight evidence categories:
- Security risk analysis — a current, written, ePHI-inventory-based assessment of threats and vulnerabilities.
- Risk management plan — the remediation decisions that followed the risk analysis, with dates and owners.
- Written policies and procedures — Privacy, Security, and Breach Notification, adopted and dated.
- Business Associate Agreements — one signed agreement per vendor that creates, receives, maintains, or transmits ePHI on your behalf.
- Workforce training records — names, dates, topics, and acknowledgments.
- Access management evidence — provisioning, periodic review, and termination records for every system holding ePHI.
- Breach and incident log — every incident, its risk assessment, and its notification outcome.
- Patient rights records — Notice of Privacy Practices, access request tracking, amendment and restriction requests, complaints.
Everything in that list must be retained for six years from creation or last effective date under 45 CFR 164.316(b)(2). That retention rule is what turns a checklist into a filing obligation.
The Risk Analysis Is Item One Because It Is Request One
OCR's audit findings and its enforcement pattern point the same direction. The agency's HIPAA Audits program reported widespread failure to conduct an accurate and thorough risk analysis, and the risk analysis enforcement initiative OCR announced in 2024 has produced a steady run of resolution agreements where the core cited failure is the same: no adequate risk analysis on file.
A gap analysis against a control list is not a risk analysis. Neither is a vendor's security questionnaire. Under 45 CFR 164.308(a)(1)(ii)(A), the analysis has to be specific to your environment and reach every place ePHI lives.
What an investigator checks inside your risk analysis
- Asset inventory. Every system, server, workstation, laptop, tablet, phone, imaging device, fax bridge, backup target, and cloud service holding ePHI. If your billing clearinghouse portal is not listed, the analysis is incomplete on its face.
- Threat and vulnerability pairing. Not "ransomware is a risk" — which assets, which vulnerability, which existing control.
- Likelihood and impact ratings with a stated method.
- A date and an author. An undated document is treated as no document.
NIST SP 800-66r2 is the free, non-binding companion HHS points to for implementing the Security Rule. Use its structure; it gives you defensible vocabulary when you explain your method.
The risk management plan is a separate document
The analysis identifies risks. Section 164.308(a)(1)(ii)(B) requires that you reduce them to a reasonable level. Practices lose here constantly: a thorough assessment with no evidence anything happened afterward.
Your remediation log needs the finding, the decision, the assigned owner, the target date, and the closing date. When you accept a risk instead of fixing it, write down why and who authorized it. "We decided the cost outweighed the exposure" is a legitimate position when documented and signed; it is a finding when it lives only in someone's memory.
Your Business Associate Agreement Binder Is the Cheapest Finding to Eliminate
Missing BAAs are the most common self-inflicted wound in a HIPAA audit checklist, because the fix costs nothing but attention. Under 164.308(b) and 164.502(e), you need a signed agreement with every entity that handles PHI on your behalf.
Build the vendor list from your accounts payable ledger, not from memory. Then classify each line:
- Business associate — BAA required: billing companies, transcription, IT managed services, cloud hosting and backup, e-fax, secure messaging, patient engagement and reminder platforms, answering services, shredding vendors, release-of-information processors, collection agencies, consultants who touch charts.
- Not a business associate: the cleaning crew with no PHI access, the utility company, a plumber under escort, couriers acting as mere conduits, other providers receiving PHI for their own treatment purposes.
- Ambiguous — decide and document: the marketing agency with CRM access, the answering service that takes symptom details, the analytics tool loaded on your patient portal pages.
For each executed BAA, keep the signed copy, the effective date, the counterparty's contact, and any subcontractor flow-down language. Note the last review date. A 2013-era agreement that never got refreshed still counts, but you should be able to say when you last read it.
If your binder has holes — and most do, usually the e-fax vendor and the IT contractor — you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX. It is a one-time purchase with no subscription, which matters when you need four agreements this month and none next month.
The reverse direction matters too
If your practice performs services for another covered entity — reading studies, supervising a lab, providing after-hours coverage — you are a business associate in that relationship, and you owe the same downstream diligence to your own subcontractors.
Privacy Rule Items Your Front Desk Actually Owns
Security Rule documentation lives with IT and the privacy officer. Privacy Rule evidence is generated at the front desk every single day, which is why it fails quietly.
The 30-day access clock
Under 164.524, you have 30 calendar days from receipt of a patient's access request to produce the records, with one 30-day extension available if you notify the patient in writing of the reason and the new date. OCR's Right of Access Initiative has produced dozens of settlements, and the pattern is consistent: the request came in, nobody logged it, weeks passed.
Your evidence is a request log: date received, patient, records requested, format requested, date fulfilled, fee charged, and who handled it. Fees must be reasonable and cost-based — labor for copying, supplies, postage. No search fees, no retrieval fees. HHS's access guidance is explicit on this.
Notice of Privacy Practices
Current version posted in the waiting area, current version on your website, and a good-faith effort to obtain written acknowledgment of receipt from each patient. If you cannot get the acknowledgment, document the attempt. Check that your NPP reflects the 2024 reproductive health care privacy provisions if you have not revised it since then.
Training rosters that survive scrutiny
Training is required at hire and periodically thereafter, plus whenever a material policy changes. Your roster needs employee name, date, module or topic, and a signed or timestamped acknowledgment. A calendar invite is not a roster. Annual cadence for everyone, same-week onboarding for new hires, and a documented refresher after any incident.
Technical Safeguards: The Evidence Is Log Output, Not Policy Text
A policy stating that you review system activity satisfies nothing. Section 164.308(a)(1)(ii)(D) requires you to actually review records of information system activity, and 164.312(b) requires audit controls that record and examine activity in systems containing ePHI.
Assemble these artifacts:
- Unique user IDs with no shared logins. Pull a current user list from every ePHI system and reconcile it against your active roster.
- Termination records. For each departure in the past year, show the date access was revoked in each system. Same-day is the standard you want; the gap between last day worked and access revoked is a number an investigator will compute.
- Access review evidence. Quarterly is defensible. Keep the exported user list, the reviewer's name, the date, and any changes made.
- Encryption status. Full-disk encryption on every laptop and workstation, encryption in transit for email and portals, encrypted backups. Encryption is "addressable," not optional — if you do not implement it, you must document the equivalent alternative and why.
- Backup and recovery testing. A backup you have never restored is a hypothesis. Test at least annually, log the date, the scope, and the result.
- Device and media disposal. Certificates of destruction for retired hard drives, copiers, and imaging workstations.
- Contingency plan. Data backup plan, disaster recovery plan, emergency mode operation plan, and a record that you exercised it.
HHS keeps its Security Rule guidance materials current, and the January 2025 proposed Security Rule update — still a proposal as of today — would tighten several of these into explicit requirements, including asset inventories, network mapping, and annual compliance audits. Building the evidence now costs less than retrofitting it later.
The Breach Log and the 60-Day Clock
Every incident goes in the log, even the ones that turn out to be nothing. A misdirected fax, a lost thumb drive, an email to the wrong patient, a phishing click — log it, run the four-factor risk assessment under 164.402, and record the conclusion.
Deadlines, from discovery:
- Affected individuals: without unreasonable delay, no later than 60 calendar days.
- HHS, 500 or more individuals: no later than 60 calendar days, plus notice to prominent media in the affected state or jurisdiction.
- HHS, fewer than 500: annually, within 60 days after the end of the calendar year in which the breach was discovered. Your 2025 small breaches are due by March 1, 2026.
The documented determination that an incident was not a reportable breach is as important as the notification itself. That is the file that answers "why didn't you report this?" Two years later, the public breach portal is worth ten minutes of your time — read what happened to practices your size and check whether the same failure mode exists in your shop.
Turning the Checklist Into a Calendar
A HIPAA audit checklist that lives in a drawer generates nothing. Assign cadence and owners:
- Annually: risk analysis refresh, policy review and re-adoption, workforce training, backup restore test, contingency plan exercise, BAA inventory reconciliation against AP.
- Quarterly: user access review across all ePHI systems, incident log review, patch and vulnerability status.
- Monthly: access request log review for aging items approaching day 30, new-vendor BAA check.
- On event: risk analysis update whenever you add a system, open a location, or change a major vendor; access revocation on termination; incident logging within 24 hours of discovery.
Name a single accountable person per line — not a department. "IT" does not sign anything.
A 30-day sprint if you are starting cold
Week 1: build the ePHI asset inventory and the vendor list from accounts payable. Week 2: reconcile BAAs against that vendor list and send agreements for every gap. Week 3: pull user lists from every system, reconcile against active staff, revoke what is stale, and document the review. Week 4: complete or update the risk analysis, open a remediation log with dates and owners, and schedule training.
Thirty days gets you from nothing to a defensible starting position. It does not get you to finished, because the obligation is continuous.
Where to Start This Week
Pull your vendor list and count the BAAs you can actually produce as signed PDFs. If the number is smaller than the number of vendors touching PHI, close that gap first — it is the fastest, cheapest finding to eliminate, and you can build and export a signature-ready BAA in six steps without signing up for another subscription.
If the risk analysis and policy set are also missing or years stale, automated risk analysis reports and the full compliance document set will get you to a dated, coherent baseline faster than a blank template will. Either way, the standard is the same: documents that exist, carry dates, name owners, and match what your systems would show.