HIPAA Assessment Checklist: What to Review for Compliance

HIPAA

Having HIPAA policies in place is a good start. But compliance is about more than having the right documents; it’s about making sure those policies translate into consistent practices across your organization. A HIPAA assessment helps you take a closer look at how PHI is handled, how systems and devices are protected, how employees and vendors access information, and what happens when something goes wrong.

HIPAA compliance is an ongoing process, not a one-time task. As your technology, workforce, vendors, and workflows change, your risks can change too. In this checklist, we'll walk through the key areas to review—from risk analysis and Privacy Rule requirements to security safeguards, vendor relationships, incident response, and the documentation that demonstrates your controls are working.

Who Should Use a HIPAA Assessment Checklist?

If your organization is covered by HIPAA, a regular assessment can help you understand whether your privacy and security practices are keeping up with your current operations.

This includes:

  • Healthcare providers, such as hospitals, physician practices, and other providers covered by HIPAA
  • Health plans, including health insurance companies and certain employer-sponsored plans
  • Healthcare clearinghouses, which process health information between healthcare organizations
  • Business associates, which provide services involving PHI on behalf of covered entities

A covered entity generally provides or administers healthcare-related services, while a business associate is an organization that performs certain services for a covered entity and handles PHI as part of those services. Both have responsibilities under HIPAA, although the specific requirements can differ.

HIPAA Assessment Checklist at a Glance

Before getting into the details, it helps to see what a HIPAA assessment covers as a whole. The checklist below provides a quick starting point. You can use it to see which areas are already covered and where you may need a closer review.

Assessment Area What to Review
HIPAA scope Covered entity or business associate status
Risk analysis Risks and vulnerabilities affecting ePHI
Privacy Uses, disclosures, patient rights, and minimum necessary
Security Administrative, physical, and technical safeguards
Access controls User access, authorization, and authentication
Workforce Training, sanctions, and onboarding/offboarding
Vendors Business Associate Agreements and third-party access
Incident response Security incidents and response procedures
Breach notification Investigation, documentation, and notification processes
Documentation Policies, procedures, assessments, and supporting evidence
Ongoing monitoring Reviews, testing, remediation, and reassessment

HIPAA Risk Analysis

Start your HIPAA assessment checklist by reviewing the risks to ePHI. Identify where ePHI is created, received, stored, maintained, and transmitted, then evaluate potential threats and vulnerabilities.

Check whether you have:

  • Identified systems, applications, devices, and locations containing ePHI
  • Documented reasonably anticipated threats and vulnerabilities
  • Evaluated likelihood and potential impact
  • Documented the results
  • Created a plan for addressing identified risks
  • Reassessed risks when technology, vendors, or processes change

Risk analysis vs. risk management

These two terms are closely related but serve different purposes. Risk analysis is about understanding the risks your organization faces. Risk management is about deciding how to address those risks and putting appropriate measures in place.

Privacy Rule Assessment

The Privacy Rule focuses on how your organization uses and discloses PHI and gives individuals certain rights over their health information. As part of your assessment, review whether your policies are clear, up to date, and reflected in everyday practices.

Review how PHI is handled

Ask:

  • Are permitted uses and disclosures clearly defined?
  • Is the minimum necessary standard addressed?
  • Are patient requests for access to PHI handled appropriately?
  • Are amendment requests handled appropriately?
  • Are accounting-of-disclosures requirements addressed where applicable?
  • Is the organization's Notice of Privacy Practices current?
  • Are privacy policies documented, reviewed, and updated when needed?

Review workforce practices

Your assessment should also look at whether employees understand their responsibilities when handling PHI.

  • Do workforce members know when they can access or disclose PHI?
  • Do they understand the organization's privacy procedures?
  • Are privacy responsibilities covered during training?
  • Are violations addressed through appropriate sanctions?

The goal isn't simply to confirm that a privacy policy exists. Look for evidence that employees understand the policy and that the organization follows its procedures consistently.

Security Rule: Administrative Safeguards

Administrative safeguards focus on the people, policies, and processes your organization uses to protect ePHI. They help establish who is responsible for security, how access is managed, and how your organization prepares for and responds to security issues.

As part of your assessment, review whether you have:

  • Completed and documented a security risk analysis
  • Established a process for managing identified risks
  • Assigned responsibility for HIPAA security
  • Defined workforce security procedures, including access and termination processes
  • Established information access management procedures
  • Provided security awareness and training
  • Documented procedures for responding to security incidents
  • Established contingency plans for emergencies and disruptions
  • Conducted periodic evaluations of your security practices

Don't just check whether these processes exist. Look for evidence that they're being used. For example, you might review access records for recently hired or departed employees, training records, incident documentation, or the results of a recent security evaluation.

Security Rule: Technical Safeguards

Technical safeguards are the technology-based controls used to protect ePHI. They cover how users access systems, how activity is monitored, how information is protected from improper changes, and how ePHI is secured when it is transmitted.

Access controls

Review whether access to ePHI is limited to authorized users based on their roles and responsibilities. Check for:

  • Unique user IDs and appropriate authorization
  • Emergency access procedures
  • Automatic logoff where appropriate
  • Encryption and decryption where appropriate

Access should be reviewed when employees change roles or leave the organization.

Audit controls

Check whether systems record relevant activity involving ePHI and whether those records are reviewed.

  • Are access and system activities logged?
  • Are logs reviewed for unusual or unauthorized activity?
  • Are suspicious events investigated?

Integrity

Review safeguards that protect ePHI from unauthorized alteration or destruction. Check whether important data and system changes can be detected and monitored.

Authentication

Confirm that users are properly verified before accessing systems containing ePHI. Authentication methods should be appropriate to the organization's risks.

Transmission security

Review how ePHI is protected when transmitted between systems or locations. Confirm that secure communication methods are used and that electronic transmissions are appropriately protected.

Business Associates and Third-Party Vendors

Your HIPAA assessment shouldn't stop at the systems and processes you control directly. If outside vendors handle PHI on your organization's behalf, their access and security practices should also be part of your review.

Review whether:

  • All relevant vendors have been identified
  • Business associate relationships have been determined
  • Required Business Associate Agreements (BAAs) are in place
  • Vendor security practices and access are reviewed periodically
  • Subcontractors are appropriately addressed
  • Access is revoked when a vendor relationship ends

A BAA alone isn't enough. Also consider what PHI the vendor can access, why it needs that access, and how the information is protected.

Workforce Training and Awareness

Your HIPAA assessment should check not only whether training is provided, but whether employees understand their responsibilities.

Review whether:

  • Required HIPAA and security training is provided and documented
  • Training is updated when policies or responsibilities change
  • Employees receive guidance on phishing and other security risks
  • Workforce members understand access, authentication, and reporting requirements
  • Appropriate sanctions are documented for policy violations

Training should reflect employees' roles and the PHI they handle.

Incident Response and Breach Readiness

Your HIPAA assessment should confirm that your organization can identify, contain, investigate, and document incidents.

Review whether you have:

  • A documented incident-response process
  • Clear reporting and investigation procedures
  • A process for evaluating potential breaches
  • Assigned breach-notification responsibilities
  • Procedures that are periodically tested or reviewed

Not every security incident is a reportable breach. Your process should help determine what happened, what PHI was involved, and what action is required. Under the Breach Notification Rule, breaches of unsecured PHI generally require notification, subject to applicable requirements and exceptions.

Contingency Planning and Disaster Recovery

Review whether your organization can protect and restore access to ePHI during disruptions.

Check that:

  • ePHI is regularly backed up and backups are protected
  • Critical systems and data can be restored
  • Disaster-recovery and emergency procedures are documented
  • Recovery procedures are tested periodically
  • Lessons from tests, outages, and incidents are incorporated into the plan

Don't just confirm that backups exist—test whether you can actually restore from them.

HIPAA Policies, Procedures, and Documentation

A HIPAA assessment shouldn't end with a list of controls that are supposedly in place. You should also be able to show how those controls work and demonstrate that your organization follows them.

As part of your review, gather and check documentation such as:

  • HIPAA privacy policies
  • Security policies and procedures
  • Incident-response procedures
  • Breach notification procedures
  • Workforce training records
  • Risk assessments and risk-management documentation
  • Business Associate Agreements
  • Access reviews and audit records
  • Security evaluations
  • Incident and investigation records
  • Contingency and disaster-recovery plans
  • Remediation and corrective-action records

For each control you review, try to connect the requirement to evidence. For example, instead of simply marking “employee training: implemented,” record what training was provided, when it occurred, who completed it, and where the records are maintained.

This makes the assessment more useful because it creates a record of what was reviewed, what was found, and what actions were taken.

HHS generally requires organizations to retain required Security Rule documentation for six years from its creation or the date when it last was in effect, whichever is later.

What Evidence Should You Collect?

A HIPAA assessment is more useful when findings are supported by clear evidence. Depending on the area you're reviewing, this may include:

  • Policies and procedures
  • Risk assessments and remediation plans
  • Access reviews and audit logs
  • Training records
  • Business Associate Agreements
  • Incident records
  • Backup and recovery test results
  • Security assessment reports

For each control, record what you reviewed, what you found, and whether any follow-up is needed.

Turn Findings Into Action

Once you've identified gaps, turn them into a simple action plan. For each finding, note:

  • What needs to be addressed
  • Who is responsible
  • Target completion date
  • Evidence needed to confirm completion

Prioritize findings based on their potential impact and track open items until they're addressed.

Make HIPAA Assessments Part of Your Routine

A HIPAA assessment doesn't have to be complicated. By reviewing your risks, privacy practices, security safeguards, vendors, workforce, incident response, and documentation, you can get a clearer picture of how your organization protects PHI and where improvements may be needed.

Use the checklist as a practical starting point, document what you find, address priority gaps, and revisit your assessment as your organization changes.

‍

Your Complete Resource Hub for Online Faxing

Explore the future of faxing and secure document sharing. Find practical guides, helpful tips, and expert resources to streamline your workflow.