HIPAA

HIPAA compliance checklist: every safeguard, every rule

A working checklist covering all four HIPAA rules. Every administrative, physical and technical safeguard with its CFR citation, marked required or addressable.

HIPAA1 October 202616 min read

Most HIPAA checklists online cover the Security Rule and stop. The Security Rule is roughly a third of your obligation. This one covers all four rules that make up the HIPAA Administrative Simplification requirements, cites the regulation for every item, and marks each implementation specification exactly as the text does: required or addressable.

It is a working checklist. Tick items as you go and copy what is left. There is almost no Evidr in it, because the regulation does not care what software you use.

First: are you a covered entity or a business associate?

Nothing below is scoped correctly until you answer this. The categories come from 45 CFR 160.103.

  • CECovered entityA health plan, a healthcare clearinghouse, or a healthcare provider who transmits health information electronically in connection with a covered transaction. All four rules apply in full.
  • BABusiness associateA person or entity that creates, receives, maintains or transmits PHI on behalf of a covered entity. Most software companies in health tech are here. Directly liable for the Security Rule and the Breach Notification Rule since the 2013 Omnibus Rule, and for parts of the Privacy Rule.
  • SubSubcontractorA business associate of a business associate. Same direct liability. If you hand PHI to a vendor, they are your subcontractor and you need a BAA with them.
  • NeitherOut of scopeYou never touch PHI. Be careful here: support tickets, logs, screenshots and error payloads can all carry PHI without anybody deciding they should.

Required versus addressable

The Security Rule marks every implementation specification as one or the other, and this is where most programmes go wrong.

Addressable does not mean optional. Under 45 CFR 164.306(d)(3) you must assess whether the specification is a reasonable and appropriate safeguard in your environment, and then do one of three things: implement it, implement an equivalent alternative measure, or document why it is not reasonable and appropriate. Skipping it silently is not on the list. An OCR investigator will ask for that written assessment, and its absence is itself the finding.

The checklist

Grouped by rule and by CFR section. Tags mark what the regulation says, not what we recommend.

0 of 66 complete0%

Ticks live in this tab only and are not saved. Copy the outstanding list before you close it.

Administrative safeguards, 45 CFR 164.308

0/23

The largest group and the one most often under-evidenced, because it is paperwork rather than configuration.

Physical safeguards, 45 CFR 164.310

0/10

Still applies if you are entirely cloud-native. The data centre obligation passes to your provider under their BAA; your offices, laptops and disposal processes remain yours.

Technical safeguards, 45 CFR 164.312

0/9

The part engineers assume is the whole of HIPAA. It is the shortest section.

Organisational, policies and documentation, 45 CFR 164.314 and 164.316

0/7

Quietly mandatory and frequently missed entirely.

Privacy Rule, 45 CFR Part 164 Subpart E

0/10

Applies in full to covered entities and in part to business associates. Routinely skipped by engineering teams who only read the Security Rule.

Breach Notification Rule, 45 CFR Part 164 Subpart D

0/7

The clock starts at discovery, not at resolution or at root cause. Know these before you need them.

The encryption safe harbour

Encryption is addressable, not required, and this surprises people every time. The reason to encrypt anyway is not the Security Rule, it is the Breach Notification Rule.

Under the HHS guidance specified in 45 CFR 164.402, PHI that has been encrypted to the standard in that guidance is rendered unusable, unreadable or indecipherable to unauthorised persons, and its loss is therefore not a breach. No notification. No portal entry. No media call. Lose an unencrypted laptop and you are notifying; lose an encrypted one and you are filing a note.

Common questions that change the scope

Where most programmes actually fail

Not in the technical safeguards. Ranked by how often they turn up as the gap:

  1. No current risk analysis, or one that was never written down. It is the most cited failure in OCR enforcement and it is the cheapest item on this list to fix.
  2. Addressable specifications neither implemented nor documented. Silence reads as negligence, not as a considered decision.
  3. Termination procedures that miss a system. Usually not production, usually a monitoring tool or a shared vault nobody inventoried.
  4. BAAs that exist but are untracked. You cannot say which of your forty vendors have one, which touch PHI, and which renewed with different terms.
  5. Right of access requests handled ad hoc. This is the most enforced Privacy Rule provision and the penalties are routine rather than exotic.
  6. Contingency plans written and never tested. The testing specification is addressable; the backup and disaster recovery plans themselves are required.
  7. Six-year retention not actually implemented, so the documentation proving a control operated in year one is gone by the time anyone asks.

A note on tooling

None of the above requires software. Small teams complete HIPAA programmes with documents and discipline, and a platform will not save a programme without an owner.

What tooling does change is the evidence burden over time. The retention requirement is six years, the evaluation is annual, training and access reviews recur, and every one of those has to be provable years after the fact. That is the part that decays in a shared drive. Evidr tracks it across HIPAA and any other framework you run, which matters mainly if you are also being asked for SOC 2 or ISO 27001 and do not want to collect the same evidence three times.

02Questions

Common questions.

Ready to get audit-ready?

Start on the free Starter plan, or talk to us about SOC 2, ISO 27001, HIPAA or any framework and see the platform on your own stack.