Cyberuptive

Healthcare HIPAA Checklist

A 40-point HIPAA Security Rule readiness checklist for clinics, practices, and health systems.

Organized by Administrative, Physical, and Technical Safeguards under the current HIPAA Security Rule, plus what’s coming if HHS’s proposed 2024 update finalizes.

Free download

Get the checklist as a PDF

We’ll email a formatted PDF you can print, share with your compliance officer, or drop into your risk analysis workflow. The full checklist is also below on this page.

How to use this

Mark each item In place / Partial / Gap. Items marked as proposed reflect HHS’s December 2024 proposed rule, currently delayed with a final rule not expected before 2027, so they’re not required today, but worth closing now while it’s cheaper to do on your own timeline instead of under an enforcement deadline. Want a scored maturity view first? Start with our HIPAA Compliance Assessment.

Administrative Safeguards

  • Comprehensive risk analysis of threats and vulnerabilities to ePHI completed in the last 12 months
  • Named Security Official with documented authority and allocated time
  • Workforce HIPAA and security awareness training delivered and tracked, including phishing simulations
  • Sanction policy for workforce members who violate security policies, documented and enforced
  • Contingency plan (data backup, disaster recovery, emergency mode operation) tested in the last 12 months

Physical Safeguards

  • Facility access controls for areas where ePHI systems are located
  • Workstation use and security policies define where and how ePHI can be accessed
  • Device and media disposal/reuse procedures documented (wiping, degaussing, or destruction)
  • Visitor and vendor access to clinical/administrative areas logged
  • Portable device (laptop, tablet) physical security policy in place for staff who work off-site

Technical Safeguards

  • Multi-factor authentication enforced for remote access and privileged accounts (proposed to become mandatory under HHS’s 2024 rule)
  • Encryption of ePHI at rest and in transit (proposed to become mandatory, currently “addressable” under the 2013 rule)
  • Audit controls log access to systems containing ePHI, reviewed on a documented cadence
  • Automatic logoff configured on workstations and systems accessing ePHI
  • Unique user identification for every account, no shared logins

EHR & Endpoint Security

  • EDR deployed on all endpoints with access to EHR-adjacent systems
  • Continuous vulnerability scanning of EHR and practice-management systems
  • Network segmentation between clinical/EHR systems and general administrative/guest networks
  • Patch management SLA defined and tracked for clinical systems
  • Medical device inventory maintained with security review for network-connected devices

Business Associate Agreements & Vendor Risk

  • Business Associate Agreements (BAAs) in place and inventoried for every vendor touching ePHI
  • BAAs reviewed annually, not signed once and forgotten
  • Vendor security posture reviewed before granting access to ePHI, not just after
  • Cloud/SaaS vendors (billing, scheduling, patient portals) confirmed to have their own HIPAA-compliant safeguards
  • Subcontractor (fourth-party) exposure identified for critical business associates

Ransomware & Backup Resilience

  • Immutable, ransomware-resistant backups for EHR and practice-management data
  • Backup restore tested at least annually with a real recovery drill, not just a completed-backup report
  • Incident response plan specifically addresses a ransomware event affecting clinical operations
  • Downtime procedures (paper backup workflows) documented for a full EHR outage
  • Tabletop exercise for a ransomware scenario completed with clinical and administrative leadership in the last 12 months

Breach Notification Readiness

  • Breach notification procedure meets the HIPAA 60-day individual notification requirement
  • HHS breach-reporting workflow (including the 60-day and annual reporting thresholds) documented and assigned to a named owner
  • State breach-notification law requirements cross-checked in addition to HIPAA (state law can be stricter)
  • Media notification procedure documented for breaches affecting 500+ individuals
  • Post-breach root-cause review process feeds back into the safeguards above

Governance & Pending Rule Readiness

  • Aware that HHS’s proposed December 2024 Security Rule update would remove the “addressable vs. required” distinction, making nearly all specifications mandatory
  • Aware the final rule has been delayed, with no earlier than 2027 expected; current 2013 rule still governs enforcement today
  • MFA and encryption gaps (items above) prioritized now, ahead of any enforcement deadline
  • Evidence library (risk analyses, training records, BAAs, audit logs) organized well enough to produce for an OCR investigation on short notice
  • Cyber liability insurance policy reviewed against actual control posture, not renewed on autopilot

Sources & further reading

This checklist maps to the current HIPAA Security Rule (45 CFR Part 164, Subpart C), the rule still in force today. HHS’s Office for Civil Rights proposed significant updates in a December 2024 Notice of Proposed Rulemaking, but as of this writing that update remains pending, with a final rule not expected before mid-2027. Use this checklist against the current rule; we’ll update it if and when the final rule publishes.

Frequently asked questions

Is the HIPAA Security Rule changing?

HHS's Office for Civil Rights published a Notice of Proposed Rulemaking in December 2024 that would meaningfully tighten Security Rule requirements, including mandatory (not just "addressable") encryption and multi-factor authentication. As of this writing the rule remains a proposal; government timelines have pushed a final rule to no earlier than mid-2027, and that date could move again. The current 2013 Security Rule is what's actually enforced today.

What's the difference between "required" and "addressable" HIPAA safeguards?

Under the current Security Rule, "required" implementation specifications must be implemented as written. "Addressable" specifications must still be addressed, but a covered entity can implement an equivalent alternative, or document why the specification isn't reasonable and appropriate for its environment. "Addressable" does not mean optional; it means you need a documented risk-based decision either way.

Does this checklist apply to business associates, not just covered entities?

Yes. Business associates, vendors and subcontractors that create, receive, maintain, or transmit PHI on behalf of a covered entity, are directly subject to the HIPAA Security Rule and to OCR enforcement, not just to whatever their Business Associate Agreement says. Most items on this checklist apply equally to both.

How does HITRUST CSF relate to HIPAA compliance?

HITRUST CSF is a certifiable framework that incorporates HIPAA Security Rule requirements alongside NIST, ISO, and other control sets into a single assessable framework. HITRUST certification isn't legally required for HIPAA compliance, but many healthcare organizations use it as a way to demonstrate compliance to partners and auditors with a recognized, third-party-verified credential.

What should a small or mid-size practice prioritize first on this checklist?

Start with the Risk Analysis category. A current, documented risk analysis is the control OCR asks for first in nearly every audit and breach investigation, and it's also the item most healthcare organizations either skip or let go stale. Everything else on this checklist is easier to prioritize once you have an honest risk analysis in hand.

Aloha, let’s talk

Want a second opinion before your next OCR audit or insurance renewal?

A 30-minute call gets you a prioritized gap list, not a sales pitch.