HIPAA Evidence of Compliance: What OCR Asks You For
A data request from the HHS Office for Civil Rights typically gives you somewhere between ten and thirty days to respond, and it asks for documents — not narratives. Your HIPAA evidence of compliance is whatever you can pull out of a folder and hand over with a date, an author, and a signature on it. Everything else is a story. This article walks through the specific artifacts a practice needs on file, who inside your organization produces each one, how long you keep them, and what makes evidence fall apart under review. If you are the privacy officer, this is your inventory checklist.
The Request That Assumes You Already Have the File
OCR does not open an investigation and then wait while you write policies. A complaint gets filed, a breach report crosses a threshold, and the request letter lands. It asks for your risk analysis, your policies as they existed on a specific date, your training records for named employees, and your business associate agreement with a named vendor.
The same thing happens outside enforcement. A hospital system onboarding your group as a referral partner sends a security questionnaire. A payer's delegated-credentialing audit asks for your workforce sanction policy. A malpractice carrier asks for proof of annual security evaluation before renewing cyber coverage. Different requesters, identical need: dated, attributable documents.
Practices that fail these requests rarely fail because they were reckless. They fail because the work happened and nobody wrote it down.
What Counts as HIPAA Evidence of Compliance?
HIPAA evidence of compliance is written documentation — paper or electronic — showing that a required policy, procedure, action, activity, or assessment actually occurred. Under 45 CFR 164.316, covered entities and business associates must maintain their Security Rule policies and procedures in writing and must document any action, activity, or assessment the rule requires. Qualifying evidence has four attributes:
- Dated — a creation date and, where relevant, an effective date and last-review date.
- Attributable — a named author, approver, or participant, not "management."
- Specific — references your actual systems, vendors, and locations rather than generic template language.
- Retained — held six years from creation or from the date it was last in effect, whichever is later.
A policy binder alone is not evidence of compliance. It is evidence that you bought a policy binder. The evidence is the signed acknowledgment, the training roster, the completed risk analysis, the log entry showing someone reviewed something on a Tuesday in March.
The Eleven Artifacts a Defensible File Contains
1. Security risk analysis
Required by 164.308(a)(1)(ii)(A). This is the single most requested document in OCR enforcement and the single most common deficiency. It must cover all ePHI your practice creates, receives, maintains, or transmits — including the laptop in the billing manager's home office, the imaging modality with a hard drive, and the ePHI sitting in your cloud vendors' systems.
An acceptable risk analysis inventories systems, identifies threats and vulnerabilities, assesses likelihood and impact, and assigns a risk level. A vendor's "you passed" certificate is not a risk analysis. ONC and OCR jointly publish a free Security Risk Assessment Tool for small and mid-sized practices, and NIST's SP 800-66r2 maps Security Rule requirements to practical safeguards.
2. Risk management plan with closure dates
The analysis identifies risks. The management plan, required by 164.308(a)(1)(ii)(B), shows what you did about them. Each finding needs an owner, a target date, and a closure entry. An open finding with a documented decision and a rescheduled date is defensible. A finding from 2022 with no entry since is not.
3. Written policies with adoption and revision history
Privacy Rule and Security Rule policies, each showing an adoption date, an approver, and a revision log. When OCR asks what your policy said on the date of an incident, you need the version that was in effect then — which means keeping superseded versions, not overwriting them.
4. Training records tied to named individuals
164.530(b) requires privacy training for all workforce members, and 164.308(a)(5) requires a security awareness program. Your documentation is the roster: employee name, date, topic, and format. New hires need training within a reasonable period after hire; material policy changes trigger retraining for affected staff. Keep the sign-in sheets and the completion exports.
5. Business associate agreements and a current vendor inventory
Every vendor that creates, receives, maintains, or transmits PHI on your behalf needs a signed agreement before access begins. Your evidence is the executed BAA plus a list showing which vendors have one, which are exempt, and when each was last reviewed.
6. Access provisioning and termination records
164.308(a)(3) and (a)(4) require you to authorize, review, and terminate access. The evidence is a ticket, form, or log showing who requested access for whom, who approved it, and — critically — the date access was revoked when someone left. Terminated-employee accounts left active are a recurring finding.
7. Audit log review notes
Having audit logs is a technical control. Reviewing them is an administrative one under 164.308(a)(1)(ii)(D). Document the review: who looked, at what period, what they found, and what they escalated. A quarterly one-page memo is sufficient and is far more than most practices produce.
8. Incident and breach documentation
Every security incident gets a record, whether or not it becomes a reportable breach. Include the four-factor risk assessment under 164.402 when you conclude PHI was not compromised — that written analysis is your evidence for a non-report decision. Breach notification deadlines run from discovery: 60 days for affected individuals, and for breaches affecting 500 or more, notice to HHS and the media within that same window. Smaller breaches are reported annually within 60 days of year-end. OCR's breach portal shows the pattern of what actually gets reported.
9. Sanctions actually applied
164.308(a)(1)(ii)(C) requires a sanction policy. Investigators ask a follow-up question: has it ever been used? Keep de-identified records of disciplinary action taken for privacy violations — a snooping incident, a misdirected fax, an ignored training deadline. Consistent application is what makes the policy credible.
10. Contingency plan tests and data restoration proof
Backups are not evidence. A dated restoration test is. Document who ran it, which system, how long it took, and whether the restored data was verified. Once a year, minimum.
11. Periodic evaluation
164.308(a)(8) requires periodic technical and non-technical evaluation of your safeguards, especially after environmental or operational changes — a new EHR, a new location, a shift to remote billing staff. The output is a dated memo comparing current state against your policies.
Who Owns Each Artifact in a 25-Person Practice
Evidence collapses when ownership is ambient. Assign names.
- Privacy officer: policies, Notice of Privacy Practices postings and acknowledgments, right-of-access request log, complaint log, training records, sanction records.
- Security officer (often the same person in a small practice, and that is permitted): risk analysis, risk management plan, audit log reviews, contingency testing, evaluation memos.
- Practice manager or office administrator: vendor inventory, BAA execution and renewal, onboarding and termination checklists.
- IT contractor: asset inventory, patch and configuration records, encryption status, media disposal certificates. Your contractor is almost certainly a business associate — get the BAA signed before the next ticket.
Put those four columns on one page with the artifact list down the left. That grid is itself a piece of HIPAA evidence of compliance, because it shows the program is administered rather than improvised.
Six Years, Measured From the Right Date
164.316(b)(2)(i) sets retention at six years from the date of creation or the date the document was last in effect, whichever is later. A policy adopted in 2016 and replaced in 2024 must be retained until 2030 — not 2022. Practices that purge on a simple creation-date rule destroy the exact version an investigator wants.
Note the separate clocks. Right-of-access requests run on 30 days with one 30-day extension under 164.524. Breach notice runs 60 days from discovery. Retention runs six years. State medical record retention laws run on their own schedule and are frequently longer — follow the stricter rule.
The Vendor File Is Where Most Practices Fail
Ask your office manager for a list of every company that touches PHI. You will get the EHR, the billing service, and the shredding company. You will not get the answering service, the transcription contractor, the marketing agency with inbox access, the IT firm, the cloud backup provider, the fax-to-email service, or the consultant who exported a patient list last spring.
Then ask for the signed agreements. A typical mid-sized practice finds a third of its vendors have no executed BAA, and another third are running on an agreement written before 2013 that never got updated for the Omnibus Rule. Both are findings. Both are also fixable in an afternoon, which is the rare compliance gap you can close faster than you can explain it.
If you are staring at a list of unpapered vendors, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — a one-time purchase, no subscription, which matters when you need eight agreements out the door this week and not a platform commitment. Date each one, file the executed copy with the vendor inventory, and set a review reminder.
A 90-Day Build for a Practice Starting From Zero
Days 1–15. Build the asset and vendor inventory. Every system holding ePHI, every vendor touching it, every location. Nothing else works without this.
Days 16–45. Complete the security risk analysis against that inventory. Produce the risk management plan with named owners and dates. Chase down missing BAAs in parallel.
Days 46–70. Adopt or refresh policies with real adoption dates and an approver signature. Train the workforce on what changed and capture the roster.
Days 71–90. Run one restoration test, one audit log review, and one evaluation memo. Assemble everything into a single indexed folder — physical or digital — with a cover sheet listing each artifact and its date. Practices that want the risk analysis, policy set, and supporting documents produced as a coordinated package can automate the full compliance document set rather than assembling it document by document.
Five Ways Evidence Falls Apart Under Review
- Undated documents. A policy with no adoption date proves nothing about what governed the practice on the day of an incident.
- Template language that never got localized. A risk analysis naming systems you do not use signals it was purchased, not performed.
- Training rosters without names. "All staff completed training" is an assertion. A roster is evidence.
- A risk analysis with no follow-through. Identifying a risk and doing nothing is arguably worse than not looking, because it establishes you knew.
- Confusing a vendor attestation with your own compliance. No product certifies your practice, and HHS does not endorse or certify any compliance vendor. Their evidence is theirs; yours is yours.
What the Proposed Security Rule Update Would Change
In January 2025, HHS published a notice of proposed rulemaking that would significantly tighten the Security Rule — including removing the "addressable" designation so nearly all specifications become required, and mandating written asset inventories, network maps, and more frequent documented reviews. As of this writing the proposal is not final, and the current rule still governs.
The practical read: the direction of travel is toward more written HIPAA evidence of compliance, not less. Asset inventories and annual documented reviews are already implied by the existing rule. Building them now means you are ahead of a final rule instead of scrambling behind it. OCR's published audit protocol remains the closest thing to an official answer key for what auditors ask.
Start With the Gap You Can Close This Week
Pull your vendor list. Mark which agreements you can actually produce as signed PDFs. If that column has holes, close them before the next risk analysis cycle — unpapered vendors are the finding that requires no investigation to prove. Draft and execute what is missing using a step-by-step BAA generator with PDF and DOCX export, file the executed copies alongside your inventory, and put a review date on the calendar. That folder is what you hand over when someone asks you to prove it.