🚀 DocRepute is in early access — free to startGet early access →
HIPAA compliance checklist illustration
✨ Early access — free to start

A HIPAA compliance checklist that tells you what each item actually means

Free to read, free to print, nothing to sign up for. It is an educational readiness aid for your own review — not a score, not a pass mark, and not a determination that your practice is compliant. HHS remains the authority.

D
M
R
S
Join healthcare practices on the waitlist

What this checklist is, and what it deliberately is not

This HIPAA compliance checklist is an educational readiness aid, and it is worth being blunt about the difference. It does not score you, it does not pass or fail you, and working through it does not make your practice compliant — no checklist can do that, and any tool that hands back a green tick and a percentage is selling a feeling rather than a finding. What it does is give a small US practice a structured way to ask the right questions in the right order, with every item explained in plain English so you know why it is on the list at all. Read it here, print it from your browser, and work down it with your practice manager and the door shut. There is nothing to sign up for and no form on this page collecting your answers, because a HIPAA readiness checklist that harvests your weak points would be a strange thing to publish. Compliance is a legal determination about your particular practice, and none of this is legal advice; where an item raises a question you cannot answer confidently, that is exactly the moment to bring in your privacy officer or your counsel.

  • Built for HIPAA-compliant workflows

  • Free to start — 50 patient actions each month

Administrative safeguards: the half most practices underestimate

Most of the weight sits in administration rather than technology, which surprises practices expecting a shopping list of software. Work through these. A written risk analysis covering every place electronic protected health information is created, received, maintained or transmitted — including the laptop at reception, the practice phone in somebody's pocket, and anything sitting with a vendor. A written risk management plan recording what you decided to do about what the analysis found, and what you decided to accept and why, because an accepted risk that was reasoned is a very different document from one nobody noticed. A named security official and a named privacy official; in a five-person practice that is usually one person, and the point is that they have been told they hold the role rather than assumed to. Written policies covering uses and disclosures, minimum necessary, patient rights of access and amendment, and complaints. Workforce training on those policies with a record of who was trained and when, plus a sanctions policy that has actually been applied at least once. Business associate agreements with every vendor that touches PHI on your behalf. And a documented process for removing access the day somebody leaves — the item that fails most often, because it belongs to nobody until it matters.

Physical and technical safeguards: where small practices actually slip

The physical items are unglamorous and cheap to fix. Can somebody standing at your reception desk read a screen or a schedule that is not theirs, and are workstations positioned or shielded so that they cannot? Is there a record of which devices hold ePHI and who has them, including personal phones carrying the practice email? Is there a documented way a hard drive, a phone or a copier is wiped before it leaves the building, given that a modern copier stores an image of everything it has ever scanned? On the technical side: a unique user ID for every person, so an audit trail can say who rather than which computer; automatic logoff on unattended workstations; audit controls that genuinely record access, and somebody who looks at them occasionally rather than never; and an encryption decision documented either way, because encryption is an addressable specification, which means you implement it or you record a reasoned alternative — not that you may quietly skip it. Add the two items that keep practices out of trouble: a backup somebody has actually tested by restoring from it, and a written breach response process that names who gets called first.

The annual myth, and every other frequency claim

This is the item worth reading twice. A great many checklists tell you to perform a risk analysis annually, and you may have heard it from a vendor selling the annual service. There is no universal calendar in the rule. The requirement is that the analysis is accurate and thorough and that it is reviewed and updated as needed — and what creates the need is change: a new practice management system, a new location, a move to cloud storage, a new vendor with access, a security incident, or a material change in how the practice works. A practice that changed nothing all year and a practice that switched systems in March do not owe the same review, and a calendar reminder is a poor substitute for a list of triggers. Treat anything on this page that sounds like a fixed schedule the same way, and check it against HHS rather than against a template. The HHS guidance is free, it is more current than any checklist including this one, and it is the place that explains which specifications are required and which are addressable — a distinction most published checklists flatten into a single tick box.

A HIPAA audit checklist is a different animal

Two neighboring searches bring people to this page with different problems. A HIPAA audit checklist is usually wanted by a practice facing something concrete: an OCR investigation following a complaint or a breach report, a payer security questionnaire, or a hospital partner running a vendor review. That is a document-production exercise rather than a fresh assessment, and it is answered by the paperwork described above — the risk analysis, the risk management plan, the training records, the business associate agreements, the policies and the access logs. If you are in that position, your counsel should be in the room before anything is sent. The other search is for a HIPAA compliance checklist PDF, and the honest answer is that we would rather you used this page than a file. A downloaded PDF is a snapshot of what somebody believed on the day they generated it, and guidance moves; this page prints cleanly from the browser onto paper you can write on, and when it changes you get the change instead of a stale copy sitting in a shared drive.

A five-person dermatology practice, one Friday afternoon

A dermatology practice with two clinicians, two medical assistants and a practice manager blocked out a Friday afternoon and worked down this list with the phones diverted. Most of it was fine. Three things were not. They had never written a risk analysis down, though they had plenty of opinions about their risks, so they spent an hour listing every place patient data actually sat: the practice management system, the imaging drive holding clinical photographs, the shared inbox, and the phone the on-call clinician carries. Doing that turned up the second thing — the imaging drive had been backing up to a consumer cloud account belonging to an employee who left eighteen months earlier, which took a morning and one awkward phone call to resolve. The third was a medical assistant who left in November and still had an active login in February. Nothing about that afternoon was technical. It needed a list, a closed door, and somebody with the authority to say yes.

Where DocRepute fits, honestly

DocRepute is a HIPAA-focused patient-experience platform for US practices, built for HIPAA-compliant workflows around digital intake, patient surveys and neutral review requests, with BAA availability planned at launch. We are pre-launch and in validation, which is exactly why this checklist exists as an educational page rather than as a claim about a running service — being useful to you now beats implying a production service that is not open yet. What any vendor can do for your compliance position is narrower than most vendors suggest, and worth stating plainly: pick suppliers who will sign a business associate agreement, who collect the minimum information the workflow needs rather than everything they could, and who keep patient data out of a scatter of tools nobody has inventoried. What no vendor can do is hold your risk analysis, train your staff, or close a leaver's account on the Monday. That work stays with you, which is the whole reason this checklist is written the way it is. If it is the intake side that worries you, the free healthcare form builder is live today and needs no account.

Official sources

Where an authority publishes its own form or guidance, take the current version from them rather than from any template library, including this one.

Get early access

Be first to use DocRepute when it launches — including AI intake and conversational surveys on paid plans.

  • Free to start — 50 action credits a month
  • Building and publishing forms uses none of them
  • No card, and no sales call booked

No spam, ever. Unsubscribe anytime.

Frequently Asked Questions

It gives a small practice a structured, plain-English readiness review: the administrative, physical and technical items to work through, what each one means, and where practices most often find a gap. It is educational. It produces no score, no pass mark, no certificate and no determination about your practice, and it is not a substitute for a risk analysis conducted for your specific environment.

View raw text version for AI/LLMs