Table of Contents
Key Takeaways
- HIPAA isn’t just for hospitals. If you’re a software company, IT firm, or cloud service working with patient data, you’re covered. Non-compliance fines start at $100 per record and go up to $50,000. That adds up fast.
- Encryption, access control, and audit logs stop most breaches. These three things matter more than anything else on this list.
- You need written agreements (called BAAs) with every vendor that touches patient data. Without one, you’re liable if they get hacked.
- HIPAA compliance isn’t a one-time project. You have to keep checking, updating, and improving your controls year after year.
- Your staff will accidentally expose data if they’re not trained. Annual training cuts these mistakes down significantly.
- The government is actively looking for non-compliant organizations right now. Getting ahead of this is smart business.
Let me be real. If you handle patient data, HIPAA compliance checklist isn’t optional. It’s required by law.
HIPAA stands for the Health Insurance Portability and Accountability Act. It’s a federal law from 1996 that sets rules for protecting patient health information. If you handle it, store it, or move it around, HIPAA applies to you.
HIPAA compliance checklist applies to everyone who touches patient health information – small clinics, SaaS startups, IT firms, cloud providers. The government doesn’t care about size. If you handle PHI, you must comply.
Skip it and fines start at $100 per exposed record, up to $50,000. A breach affecting 1,000 patients costs hundreds of thousands in fines alone. Add lawsuits and reputation damage.
Good news: compliance doesn’t require rocket science. Most breaches happen because of basic failures: unencrypted data, weak passwords, no access logging, unsecured vendors.
This HIPAA compliance checklist breaks down exactly what you need to do. We cover the 20 controls that actually stop breaches.
What’s PHI (Protected Health Information)?

PHI is anything that links a person to their health info. That includes:
- Medical records and diagnoses
- Lab results and x-rays
- Names, birthdates, and Social Security numbers (when attached to health data)
- Insurance information
- Billing and payment details
- Therapy notes and mental health records
- Genetic information
- Even appointment schedules if they’re connected to a patient
If you can identify someone and the data relates to their health, it’s PHI. Protect it like it’s gold.
Who Has to Follow HIPAA?
If you’re a covered entity, you must comply. That means:
- Hospitals and clinics
- Doctors’ offices and dentists
- Health insurance companies
- Pharmacies
- Mental health providers
- Urgent care centers
If you’re a business associate, you must comply too. That means:
- Cloud storage companies (AWS, Microsoft Azure, Google Cloud)
- EHR software vendors
- Email and collaboration platforms
- IT support firms and managed service providers
- Backup and disaster recovery companies
- Billing and coding services
- Telehealth platforms
- Analytics tools
If you work in any of these areas and touch patient data, you need HIPAA controls. Period.
Why This Actually Matters
Let’s be honest. You don’t want a breach. Here’s what happens if you get one:
- The average healthcare data breach costs $10.7 million in direct expenses
- Fines from the government run from $100 to $50,000 per exposed record
- You have to notify every affected patient within 60 days
- Patients sue
- Your reputation takes a hit
- News outlets cover it
- Customers leave
That’s why organizations take this seriously. It’s expensive to mess up.
The Three Types Of Security Controls HIPAA Requires
HIPAA breaks down into three main categories. You need all three.
Administrative: These are your policies, training, and decision-making. Who has access? How do you onboard people? What happens when someone leaves? What’s your training program? Who’s in charge?
Physical: This is about the real world. Who can walk into your server room? How do you lock down laptops and phones? How do you destroy old hard drives? Can visitors wander near patient data?
Technical: This is your technology. Encryption, passwords, logging who accesses what, detecting threats, patching software, and keeping the bad guys out. All three work together.
Skip one and you have gaps.
The HIPAA Compliance Checklist
Part 1: Administrative Controls (The Policies and People)

1. Assign Someone to Own HIPAA Compliance
Pick a person or small team. Give them the title and the responsibility. Document it in writing.
They need to:
- Run risk assessments every year
- Update policies when things change
- Make sure vendors have proper agreements
- Make sure everyone gets trained
- Handle breaches if they happen
- Get ready for audits
One person can’t do this alone at a large organization. But someone has to own it. This prevents it from falling through the cracks.
2. Do a Real Risk Assessment Every Year
Sit down and figure out where your patient data lives. Where is it stored? How does it move around? Who can access it? What could go wrong?
Look at:
- Your databases and servers
- Cloud storage and backups
- Email and file sharing
- APIs and integrations
- Physical devices (laptops, phones, tablets)
- Paper records
- Third-party vendors
- Your staff and what they can do
Write down the risks you find. Rate them as high, medium, or low. Fix the high ones first. Keep this written down. The government wants to see that you did this work.
3. Write Down Your Policies
You need written policies for:
- How people get access to patient data and how they lose it
- Password rules (length, complexity, how often to change)
- Device security (encryption, lock screens, what happens when someone leaves)
- How you encrypt data
- Remote access (VPN, two-factor login)
- What staff can and can’t do with PHI
- What to do if there’s a breach
- How to manage vendors
- Logging and monitoring
- How long you keep records before deleting them
- Who needs training and when
Put these in a document. Update them every year or when something changes.
4. Get Business Associate Agreements With Every Vendor
A Business Associate Agreement (BAA) is a contract. If a vendor touches patient data, you need one.
Who needs a BAA?
- Your cloud provider (AWS, Azure, Google Cloud, Dropbox)
- Your EHR software company
- Your email provider (if it handles patient info)
- Your IT support company
- Your backup company
- Any analytics or reporting tool
- Your telehealth platform
- Anyone else with access
What should the BAA say?
- The vendor will protect data with the same safeguards you use
- The vendor will tell you immediately if there’s a breach
- You can audit their security
- The vendor won’t use your data for their own purposes
- The vendor will delete your data when you ask
- The vendor won’t let subcontractors touch your data without agreements
Keep copies of all BAAs in one place. Check them annually. Without a BAA, you’re responsible if a vendor gets hacked. That’s not a risk you want to take.
5. Train Everyone Who Touches Patient Data, Every Year
This includes:
- Clinical staff
- Administrative staff
- IT people
- Contractors
- Temporary workers
- Anyone with access
Training should cover:
- What HIPAA is
- What PHI is and how to spot it
- How to use and share patient data properly
- How to protect it
- Phishing and social engineering (recognizing scams)
- What happens if you violate HIPAA
- How to report concerns
- Password security
- Device security
- Getting rid of patient data safely
Keep records of who trained, when they trained, and what they learned. Aim for everyone to complete it. Don’t just go through the motions.
6. Control Who Has Access to Patient Data
Use role-based access. Define roles like: receptionist, nurse, doctor, billing staff, admin. Give each role only the access they need.
- A receptionist sees appointment schedules and contact info
- A nurse sees clinical notes
- Billing staff sees insurance and payment info
- A doctor sees everything for their patients
- An admin can manage accounts but shouldn’t see actual data
Use unique logins. Never share passwords. Require two-factor authentication (a code from your phone plus your password).
Review access every quarter. Remove access immediately when someone leaves.
Log everything. Who logged in when? What did they see? This is crucial if a breach happens.
7. Handle Patient Requests for Their Own Data
Patients have rights. They can ask for:
- Copies of their records
- Corrections if information is wrong
- A list of who accessed their data
- Limits on how you use their data
Create a process. Respond within 30 days for most requests. Keep records. This isn’t a burden; it builds trust.
8. Create a Breach Response Plan
If someone accesses patient data without permission, that’s a breach (usually). You need a plan for what happens.
When a breach occurs:
- Figure out what actually happened
- Find out if real unauthorized access occurred
- Stop it from getting worse
- Notify patients within 60 days
- Report to HHS (the government agency that enforces HIPAA)
- Fix what went wrong
- Document everything
Write this down now. Don’t wait for a breach to figure it out.
Part 2: Physical Controls (Locks, Encryption, Devices)

9. Lock Down Your Server Room
Only IT staff should access servers. Use badge readers or keys. Keep a log of who goes in and when. Position servers away from patient areas.
It sounds basic, but a stolen hard drive is one of the fastest ways to expose thousands of patient records. Make it hard to steal.
10. Secure Laptops and Devices
All laptops and tablets need:
- Disk encryption (BitLocker on Windows, FileVault on Mac)
- Strong passwords
- Screen lock after 5 minutes of inactivity
- Up-to-date software and security patches
- Antivirus software
For phones:
- Password or fingerprint lock
- Encryption turned on
- Screen lock after 5 minutes
- Remote wipe capability if lost or stolen
- No sensitive data stored if not needed
A lost unencrypted laptop is a serious breach. An encrypted one is just an inconvenience.
11. Protect Backups
All backups need encryption. Store them somewhere different from your main systems (off-site or in a different cloud region). Test that you can restore them. Keep them for several years. Restrict who can access backups.
If ransomware locks up all your systems, a good backup lets you recover. Make sure the backups themselves are protected.
12. Destroy Old Devices Properly
Before you get rid of any device that held patient data, wipe it completely. Use tools that write over the data multiple times (DOD standards). Or physically destroy the hard drive.
Never donate a computer that had PHI on it, even if you think you deleted everything. Use a certified e-waste company that destroys data on-site and gives you a certificate.
Part 3: Technical Controls (Encryption, Passwords, Logging)

13. Encrypt Data When It’s Stored
Patient data on servers, databases, and cloud storage needs encryption. Use AES-256 encryption (the gold standard).
Where to encrypt:
- Databases with patient records
- Cloud file storage (AWS S3, Azure Blobs, Google Cloud Storage)
- Backups
- Laptops and desktops
- USB drives
Most cloud providers have encryption built in. Turn it on. Rotate encryption keys once a year.
If someone steals a hard drive or accesses your database without permission, encrypted data looks like gibberish. They can’t read it.
14. Encrypt Data When It Moves
Patient data moving between systems needs protection too.
Use:
- HTTPS for websites (the “s” is important)
- VPN for remote workers
- Encrypted email (not all email is encrypted by default)
- Secure APIs for integrations
- TLS (Transport Layer Security) for connections between servers
Disable unencrypted methods. No plain HTTP. No regular FTP. No unencrypted email.
A hacker on your WiFi network can intercept unencrypted data. Encryption stops this.
15. Log Who Accesses Patient Data
Set up logging on every system that touches PHI. Record:
- Who logged in
- When they logged in
- From where (IP address)
- What they accessed
- What they did (viewed, edited, deleted)
- Failed login attempts
- System changes and configuration updates
Centralize logs in one place. Keep them for at least 6 years. Review them monthly. Set up alerts for suspicious activity: huge downloads, logins after hours, failed attempts.
Logs are how you prove a breach happened and who did it.
16. Require Two-Factor Authentication
Passwords alone aren’t enough. Require a second factor:
- A code from an authenticator app on your phone
- A code texted to your phone (weaker, but better than nothing)
- A hardware key you plug in
- Biometric (fingerprint or face recognition)
Use two-factor for:
- All systems with patient data
- Remote access (VPN, cloud portals)
- Admin accounts
If a hacker steals your password through a phishing email, two-factor stops them. They don’t have your phone.
17. Check Third-Party Tools and Integrations
If you connect your EHR to a billing system, or your database to an analytics tool, those connections need security.
Ask questions:
- Is it using HTTPS and encrypted connections?
- Can we audit their access?
- Are they logging access?
- Can we turn off access immediately if we need to?
- Do they have a BAA?
- Do they have security certifications?
Keep a list of all integrations. Review quarterly. Rotate API keys annually. Turn off integrations you’re not using.
APIs are common attack targets because they often get less attention than main systems.
18. Use Tools to Detect Threats
Install software that watches for attacks:
- Firewalls (block bad traffic)
- Intrusion detection (alert on suspicious patterns)
- Antivirus and malware detection
- Endpoint detection and response (EDR) on all computers and servers
These tools watch for ransomware, hacking attempts, malware, and suspicious behavior. They alert you fast.
19. Keep Software Patched and Secure
Hackers exploit known vulnerabilities in outdated software. Patch everything:
- Operating systems
- Databases
- Applications
- Cloud services
- Mobile apps
Apply critical patches within 30 days. High-risk patches within 60 days. Document what you patch.
Also:
- Turn off features you don’t use
- Use strong password policies
- Disable default accounts
- Restrict what services can do
20. Review and Improve Continuously
Compliance isn’t a one-time thing. Do these regularly:
- Monthly: Review access logs and look for anything strange
- Quarterly: Check vendor security and BAAs
- Annually: Full risk assessment, security testing (penetration testing), policy updates, training
- After any breach: Figure out what went wrong and fix it
Track metrics like how many breaches happened, how fast you detected them, and whether your controls actually worked.
Practical Steps To Get Started
If you’re starting from zero, here’s what to do first.
This week:
- Appoint someone to own HIPAA compliance
- List who has access to patient data
- List all systems and tools that store or move patient data
Next week:
- Ask: What could go wrong? Where are the risks?
- Check what security you already have
- Identify what’s missing
Week three:
- Contact every vendor and request a BAA
- Turn on encryption for databases and cloud storage
- Set up two-factor authentication for critical systems
Week four:
- Write basic policies for access control, passwords, devices, and incident response
- Train staff on HIPAA basics
- Set up logging and start reviewing logs
After that, do annual risk assessments, update policies, retrain staff, and keep improving.
Learn More About HIPAA Requirements
The government has official guidance. Check out the HHS Security Rule page for detailed technical requirements.
For a more thorough checklist approach, HIPAA Journal offers a detailed compliance checklist that covers additional considerations.
If you’re looking to implement HIPAA compliance for IT systems specifically, Digacore provides in-depth guidance on HIPAA compliance for IT systems healthcare that covers cloud environments and complex integrations.
Frequently Asked Questions
What is HIPAA compliance?
HIPAA compliance means following a set of rules that protect patients’ health information. If your business stores, shares, or processes medical data, you need to keep it secure and make sure only authorized people can access it.
Who needs to follow HIPAA?
HIPAA applies to healthcare providers, insurance companies, medical software companies, cloud service providers, IT firms, and any business that handles patient health information. If you work with medical data, HIPAA likely applies to you.
What happens if a business is not HIPAA compliant?
Failing to follow HIPAA can lead to large fines, legal issues, and loss of customer trust. A data breach can also damage your company’s reputation and cost much more than preventing the problem in the first place.
What are the most important HIPAA security requirements?
The most important steps are encrypting patient data, limiting who can access it, keeping activity logs, using strong passwords with two-factor authentication, and training employees to handle sensitive information safely.
Why are Business Associate Agreements (BAAs) important?
A Business Associate Agreement is a legal contract between you and any vendor that handles patient data. It makes sure both parties understand their responsibilities for protecting sensitive health information.
Is HIPAA compliance a one-time process?
No. HIPAA compliance is an ongoing process. Businesses should regularly review their security, update policies, train employees, and perform risk assessments to stay compliant and protect patient information.
Real Talk: Why This Matters
HIPAA compliance checklist implementation is real work, but it’s not impossible. The organizations that get this right treat it as a core business function, not a compliance checkbox.
Start with the highest-impact controls: encryption, multifactor authentication, access logging, and vendor agreements. These stop most breaches. Build from there with annual risk assessments, policy updates, and staff training.
Your HIPAA compliance checklist is ongoing. You can’t do it once and forget about it. Review controls monthly. Update policies when systems change. Retrain staff every year. Monitor continuously. That’s the reality, but it becomes routine once you establish the rhythm.
Your patient data is your responsibility. Protect it seriously, and HIPAA compliance checklist becomes a competitive advantage, not a risk.
Need help building your HIPAA compliance checklist? Digacore specializes in healthcare IT support that keeps compliance requirements front and center. We help organizations implement real controls that actually protect patient data.
Ready to assess your current program? Contact Digacore for a free consultation. We’ll review where you stand and what comes next. Your patients deserve protection. Build it right.