Resources

HIPAA compliance checklist for teams and small practices.

If you need a sane starting point, start here. This checklist focuses on the controls most healthcare teams need in place before audits, onboarding pushes, vendor reviews, or security incidents expose a weak process.

Core checklist

  1. Assign HIPAA training by workforce role before staff handle PHI.
  2. Keep an annual training log with completion dates, certificate IDs, and renewal due dates.
  3. Inventory every vendor that creates, receives, maintains, or transmits PHI and confirm BAAs are in place.
  4. Run and document a HIPAA risk assessment for systems, devices, and remote workflows that touch ePHI.
  5. Review access controls for EHR, cloud storage, email, texting, and patient communication tools.
  6. Document incident response, breach review, and escalation steps before something goes sideways.
  7. Maintain policy evidence for mobile devices, workstations, password hygiene, and data retention.
  8. Verify certificate, policy, and audit evidence can be retrieved without inbox archaeology.

What to review first

  • Training records and renewal gaps for anyone touching PHI.
  • Vendor tools that still do not have signed BAAs or clear owners.
  • Remote work, email, texting, and mobile-device workflows with weak safeguards.
  • Evidence retrieval: can you find certificates, policies, and incident logs fast?

Best next steps