An OCR data request rarely opens with a question. It opens with a list: your policies and procedures, your most recent security risk analysis and risk management plan, your business associate agreements, your workforce training records, and your log of the last six years of security incidents. If those five artifacts are not sitting in one folder with dates on them, the investigation gets longer and more expensive.

This is a working hipaa compliance checklist for the person who actually has to produce that folder — the practice owner, the privacy officer, the compliance lead. Each item names who owns it, when it is due, and what the documented evidence looks like. No item on this list is satisfied by a certificate on the wall.

What Is on a HIPAA Compliance Checklist?

A complete HIPAA compliance checklist for a covered entity covers ten items:

  1. Named Privacy Officer and Security Officer, in writing, with the date of appointment.
  2. A current security risk analysis covering every system that touches ePHI, plus a written risk management plan.
  3. Written policies and procedures for the Privacy Rule, Security Rule, and Breach Notification Rule.
  4. A business associate inventory with an executed, current BAA for every vendor on it.
  5. Workforce training records — who was trained, on what, on what date.
  6. A sanctions policy and evidence you have applied it.
  7. Notice of Privacy Practices, posted, distributed, and acknowledged.
  8. Patient rights workflows for access, amendment, accounting of disclosures, and restrictions.
  9. Breach response procedure with a risk-assessment worksheet and notification templates.
  10. Six years of retained documentation, per 45 CFR 164.316(b)(2).

Everything below is the operational detail behind those ten lines.

The Risk Analysis Line Item That Fails Most Often

More resolution agreements cite an inadequate or missing risk analysis than any other single failure. The usual pattern: a practice ran a vendor's automated scan of the network in 2021, filed the PDF, and never touched it again. That is not a risk analysis under 45 CFR 164.308(a)(1)(ii)(A).

A defensible risk analysis starts with an inventory of every place ePHI lives or moves: the EHR, the practice management system, the imaging archive, the billing clearinghouse connection, the fax server, the front-desk workstations, the two laptops the physicians take home, the phones with email on them, the cloud storage folder someone created for referral letters. If it is not on the inventory, it was not assessed.

For each asset, you document threats, vulnerabilities, existing controls, likelihood, impact, and the resulting risk level. Then the risk management plan assigns each unacceptable risk an owner and a target date. HHS publishes guidance on risk analysis requirements that spells out the elements, and ONC's Security Risk Assessment Tool is free if you want a structured starting point.

Owner: Security Officer. Cadence: full analysis annually, plus an update whenever you add a system, change locations, or absorb a practice. Evidence: a dated report, an asset inventory, and a risk register showing items closed with dates.

The 2025 wrinkle: a proposed Security Rule overhaul

In January 2025, OCR published a proposed rule to strengthen the Security Rule — it would tighten asset inventory and network mapping requirements, push toward mandatory encryption and multi-factor authentication, and require regular verification that business associates have deployed technical safeguards. It is still a proposal as of this month, not law. But the direction of travel is clear enough that building your asset inventory and MFA coverage now is time well spent rather than compliance theater.

Your Vendor List Is Half the HIPAA Compliance Checklist

Pull your accounts payable ledger for the last twelve months and read every line. Circle anyone who creates, receives, maintains, or transmits PHI on your behalf: the billing company, the answering service, the transcription service, the shredding company, the IT support firm with remote access, the cloud backup provider, the release-of-information vendor, the collections agency, the marketing agency that manages your patient recall texts.

Every circled name needs a signed business associate agreement on file before PHI moves. The agreement has to include the required elements at 45 CFR 164.504(e): permitted uses, safeguard obligations, subcontractor flow-down, breach reporting timelines to you, return or destruction of PHI at termination, and your right to terminate for material breach.

Two failure modes show up constantly in practices. First, the BAA that exists but predates a major change — the vendor was acquired, or moved to a new cloud platform, or started using an offshore subcontractor. Second, the BAA that was never signed because a clinician set up the vendor relationship directly and nobody in the business office knew. Both are discoverable in an audit, and both are unforced errors.

If you are staring at four unpapered vendors and no template you trust, you can generate a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX. It is a one-time purchase, not a subscription, which matters when you need three agreements this week and none next quarter.

Owner: Privacy Officer, with the office manager supplying the vendor list. Cadence: reconcile the vendor list against the BAA binder every quarter and at every new vendor onboarding. Evidence: a spreadsheet with vendor name, service, PHI touched, BAA execution date, and renewal or review date.

Policies, Training Logs, and the Six-Year Retention Rule

Policies are not decoration. Investigators compare what your policy says to what your staff actually did, and the gap is where penalties live. If your policy says workstations lock after five minutes and your workstations never lock, the policy is now evidence against you.

Your minimum policy set: uses and disclosures, minimum necessary, patient rights (access, amendment, accounting, restriction, confidential communications), Notice of Privacy Practices distribution, safeguards, workforce sanctions, security incident response, breach notification, contingency planning, device and media controls, access management, audit controls, and business associate management. Each one needs a version number, an effective date, and an approval signature.

Retention is six years from creation or from the date it was last in effect, whichever is later. That includes superseded policies, old training rosters, completed risk analyses, patient authorizations, accounting-of-disclosure logs, and incident write-ups. Deleting the 2020 policy because you wrote a 2024 one is a documentation violation.

Training: the roster is the deliverable

Privacy Rule training is required for all workforce members, including volunteers and students, within a reasonable time after they join and again when policies change materially. Security awareness training under 164.308(a)(5) is ongoing — periodic reminders about phishing, malicious software, login monitoring, and password practices.

The evidence is a roster: name, role, training topic, date completed, and how you know they completed it. Add a signed attestation acknowledging your policies and sanctions. When a new medical assistant starts on a Monday, that packet should be signed before they touch the EHR, and the date should be on it.

Sanctions: apply the policy at least once

A sanctions policy nobody has ever used reads as unenforced. When someone looks up a coworker's chart out of curiosity, document the investigation, the finding, the sanction applied, and the retraining. That record is what turns an isolated snooping incident into evidence of a functioning program instead of evidence of willful neglect.

The 30-Day Clock That Starts When a Patient Asks for Their Chart

You have 30 calendar days from receipt of a request to provide access, with one 30-day extension available if you notify the individual in writing of the reason and the new date. There is no second extension. Records held by an offsite storage vendor or a prior EHR do not stop the clock.

Practical controls that keep you inside the window:

  • Log every request the day it arrives — date received, requester, records sought, format requested, delivery method, date fulfilled. One log, one owner.
  • Train the front desk not to gatekeep. A verbal request at the window is a valid request. Staff should not demand a specific form, refuse an emailed request, or ask why the patient wants their chart.
  • Honor the requested format if it is readily producible, including unencrypted email when the patient asks for it after being warned of the risk.
  • Keep fees cost-based — labor for copying, supplies, postage, and preparation of an explanation if requested. No search-and-retrieval fees.

OCR has resolved dozens of right-of-access cases, and most involved small practices that simply took too long. This is the cheapest item on the checklist to fix and one of the most frequently enforced.

Notice of Privacy Practices: check your deadline

If your practice creates or receives substance use disorder records covered by 42 CFR Part 2, your NPP has to be updated to reflect the aligned Part 2 requirements by February 16, 2026. That is roughly ten weeks out. Separately, a federal court in 2025 vacated most of the 2024 reproductive health privacy provisions, so coordinate with counsel before you rewrite NPP language on that subject — the landscape shifted mid-year and state law still applies.

Breach Notification: 60 Days, and a March 1 Deadline You Will Forget

Two clocks, and operators mix them up constantly.

Breaches affecting 500 or more individuals: notify affected individuals, HHS, and prominent media in the state or jurisdiction without unreasonable delay and no later than 60 calendar days from discovery.

Breaches affecting fewer than 500 individuals: notify individuals within 60 days of discovery, but report to HHS annually — within 60 days after the end of the calendar year. Every small breach your practice discovered during 2025 must be submitted through the HHS portal by March 1, 2026. Pull your incident log now, while the details are still recoverable.

Discovery means the first day the incident is known, or reasonably should have been known, to anyone in your workforce other than the person who caused it. A misdirected fax reported to a supervisor on December 8 starts the clock on December 8, not when the privacy officer returns from vacation.

Every incident needs a four-factor risk assessment documented in writing: the nature and extent of the PHI, who received it, whether it was actually acquired or viewed, and the extent to which risk has been mitigated. If you conclude there is a low probability of compromise and no notification is required, that conclusion must be written down and retained. HHS maintains both the breach notification rule guidance and the public breach reporting portal.

Technical Safeguards Worth Verifying Every Quarter

Sit with your IT vendor for one hour a quarter and confirm these in the actual system, not in the contract:

  • Unique user IDs and no shared logins — including the front-desk workstation and the scanner account.
  • Termination procedures that disable EHR, email, VPN, and building access the day someone leaves. Pull a list of active accounts and compare it to your current payroll roster.
  • Encryption at rest on every laptop, tablet, phone, and external drive, with a report proving it.
  • Audit log review — someone actually looks, on a schedule, and initials the review.
  • Backups tested by restore, not just by a green status icon. Document the date and result of the last restore test.
  • Multi-factor authentication on email, remote access, and the EHR admin accounts.
  • Patch status and an inventory of anything running unsupported software.

Also write and test the contingency plan: data backup plan, disaster recovery plan, emergency mode operation procedures, and a criticality analysis of which applications you need running first. A tabletop exercise with a two-page memo is acceptable evidence. Nothing is not.

A 90-Day Sequence If You Are Starting From Zero

Days 1–30: Appoint and document the Privacy and Security Officers. Build the ePHI asset inventory. Pull twelve months of AP and build the vendor list. Start a single incident log.

Days 31–60: Complete the risk analysis and write the risk management plan with owners and dates. Chase every missing BAA. Adopt the core policy set with effective dates and signatures.

Days 61–90: Train the entire workforce and file the roster. Stand up the access-request log and train the front desk on the 30-day rule. Run one tabletop breach exercise. Update the NPP ahead of the February 2026 Part 2 deadline. Calendar the March 1 small-breach submission.

Track all of it in one place with a named owner and a due date per line. A hipaa compliance checklist without owners and dates is a wish list, and it will not survive a document request.

Next Step

Start with the two items that generate the most enforcement exposure per hour invested: the risk analysis and the BAA inventory. If you have vendors moving PHI without a signed agreement, build the BAA today and get it signed this week — one-time purchase, PDF and DOCX export, no subscription to manage. If the broader document set is what is missing, automated risk analysis reports and policy generation will get you to a dated, defensible file faster than a blank Word document will. Neither is a government credential; both produce the evidence an investigator asks for first.