Updated July 19, 2026

The foundation: HIPAA compliance requires implementing administrative, physical, and technical safeguards to protect electronic protected health information (ePHI) — and maintaining them continuously. It is not a one-time certification. This checklist covers the five core steps every covered entity and business associate must complete: understanding the Security Rule, assigning a compliance officer, mapping your data flows, conducting risk assessments, and documenting everything. For organizations that store or transmit PHI in the cloud, a HIPAA-compliant hosting environment with a signed Business Associate Agreement (BAA) is the non-negotiable foundation.


  • HIPAA compliance is an ongoing process, not a one-time certification — it must be continuously maintained
  • The three safeguard categories are administrative, physical, and technical — all three are required
  • An Annual Security Risk Assessment (SRA) is the most frequently cited reason for OCR fines — it is mandatory
  • Every vendor that touches PHI must sign a Business Associate Agreement (BAA) before accessing your data
  • The 2025 proposed HIPAA Security Rule update eliminates the “addressable” loophole — MFA, backups, and vulnerability scanning are effectively required now
  • Documentation must be retained for 6 years — including risk assessments, BAAs, training records, and breach notifications

Need help getting your organization HIPAA compliant? HIPAA Vault provides fully managed hosting with a signed BAA, U.S.-based private servers, and 24/7 compliance support — starting at $120/month.

Schedule a free consultation →  |  View hosting plans →

What Is HIPAA Compliance?

HIPAA — the Health Insurance Portability and Accountability Act of 1996 — establishes national standards for protecting sensitive patient health information. Of its five titles, Title II has the greatest impact on data security and patient privacy, covering administrative simplification, fraud prevention, and medical liability reform.

The HIPAA Security Rule requires covered entities and business associates to implement safeguards protecting electronic protected health information (ePHI). The HIPAA Privacy Rule governs how PHI can be used and disclosed. The HIPAA Breach Notification Rule requires notification to affected individuals and HHS within 60 days of discovering a breach.

In 2013, HHS issued the Omnibus Rule implementing the HITECH Act — extending HIPAA Security Rule requirements directly to business associates and their subcontractors. In 2025, HHS proposed the most significant Security Rule update since 2005, eliminating the distinction between “required” and “addressable” implementation specifications. As of July 2026, the final rule has not been issued — but healthcare organizations should treat all formerly addressable controls as required now.


Don’t Trust Patient Data to Standard Web Hosting

Protect your practice from breaches and fines. Our hosting includes intrusion detection, firewalls, and audit logs.

Learn More

Who Is Subject to HIPAA?

HIPAA applies to two categories of organizations:

Covered Entities:

  • Healthcare providers (hospitals, clinics, physicians, dentists, therapists, pharmacies)
  • Health plans (insurance companies, HMOs, employer health plans)
  • Healthcare clearinghouses

Business Associates — any organization that creates, receives, maintains, or transmits PHI on behalf of a covered entity, including:

  • Cloud hosting providers
  • Medical billing services
  • EHR vendors
  • IT service providers
  • Telehealth companies
  • Marketing companies with PHI access
  • Attorneys and accountants with PHI access
  • Shredding services

As Gil Vidals, CTO and co-founder of HIPAA Vault, explains:

“A lot of people think HIPAA only applies to hospitals and doctors. But if you’re a software company, a hosting provider, a billing service — anyone who touches that data — you’re a business associate, and you have to sign a BAA and meet the same standards.”

A signed Business Associate Agreement (BAA) must be in place before any business associate accesses PHI. This is a legal requirement, not a best practice.


The HIPAA Compliance Checklist

Step 1: Understand and Implement the Three HIPAA Safeguards

The HIPAA Security Rule (45 CFR Part 164) organizes required protections into three safeguard categories. All three are required — not optional.


I. Administrative Safeguards

Administrative safeguards are the policies and procedures that govern how your organization manages PHI security.

Required actions:

  • [ ] Assign a Security Officer and a Privacy Officer — designating responsible individuals is a HIPAA requirement
  • [ ] Conduct an Annual Security Risk Assessment (SRA) — the most frequently cited reason for OCR fines; failure to conduct and document an SRA is an immediate compliance gap (HHS free SRA tool available)
  • [ ] Establish workforce access policies — who can access PHI, under what conditions, and how access is granted and revoked
  • [ ] Implement employee security training — annually, with documentation; must include phishing awareness, password hygiene, and PHI handling
  • [ ] Execute BAAs with all business associates — before any PHI is shared with any vendor
  • [ ] Apply the Principle of Least Privilege — users should have access only to the PHI they need to perform their job
  • [ ] Establish incident response procedures — documented plan for identifying, reporting, and mitigating security incidents
  • [ ] Create a contingency/disaster recovery plan — documented procedures for recovering ePHI after system failures, ransomware, or natural disasters
  • [ ] Conduct regular audits and assessments — verify that security controls remain in place and functioning

II. Technical Safeguards

Technical safeguards are the technologies and technical policies that protect ePHI.

Required actions:

  • [ ] Implement unique user identification — every user must have their own login credentials; shared logins are not compliant
  • [ ] Deploy multi-factor authentication (MFA) — required under the 2025 proposed Security Rule update; treat as mandatory now
  • [ ] Configure automatic session logoff — terminate inactive sessions after a predefined period
  • [ ] Establish emergency access procedures — document who can access PHI in emergencies and how
  • [ ] Implement audit controls — log all system access, PHI access, creation, modification, and deletion with timestamps and user identifiers
  • [ ] Enable encryption at rest — AES-256 for all stored ePHI, per NIST SP 800-111 guidance
  • [ ] Enable encryption in transit — TLS 1.2 or higher for all data transmission
  • [ ] Implement integrity controls — mechanisms to detect unauthorized alteration or deletion of PHI
  • [ ] Conduct regular vulnerability scanning — required under the 2025 proposed Security Rule update; treat as mandatory now

III. Physical Safeguards

Physical safeguards protect the physical facilities and hardware that house ePHI.

Required actions:

  • [ ] Restrict facility access — access controls for data centers and server rooms; only authorized personnel
  • [ ] Implement workstation security — policies governing how workstations containing or accessing PHI are used and secured
  • [ ] Establish device and media controls — documented procedures for disposing of hardware, including multi-pass hard drive wiping
  • [ ] Ensure data center physical security — locked doors, biometric scanners, security cameras, access logs (required for HIPAA Vault’s hosted environments)

✅ Step 2: Assign a Compliance Officer

Designating a Compliance Officer is not optional — it is a required element of the administrative safeguards. This person is responsible for:

  • [ ] Creating and maintaining HIPAA-compliant policies and procedures
  • [ ] Overseeing employee HIPAA training and documenting completion
  • [ ] Investigating and reporting security incidents and breaches
  • [ ] Ensuring patient rights are protected under federal and state law
  • [ ] Staying current with HIPAA regulatory changes (including the pending 2025 Security Rule update)
  • [ ] Ensuring annual risk assessments are conducted and documented

“If you only had one question that was going to make a big difference — you talk to a provider and say, ‘Hey, do you have a compliance manager?’ If they say no, they flunk it right away. Go on to the next one.” — Gil Vidals


✅ Step 3: Map Your PHI Data Flows

Before you can protect PHI, you need to know exactly where it is, how it moves, and who handles it.

  • [ ] Identify all sources of PHI — websites, forms, EHR systems, email, fax, file uploads, chat tools, billing systems
  • [ ] Map how PHI travels — from patient submission → web server → database → backup → third-party vendors
  • [ ] Identify all business associates — every vendor that touches PHI in your workflow
  • [ ] Verify BAAs are in place — for every business associate identified
  • [ ] Identify subcontractor chains — ensure your vendors have BAAs with their own subcontractors who access PHI
  • [ ] Review third-party integrations — analytics tools, marketing platforms, chat widgets, and scheduling tools may inadvertently receive PHI

✅ Step 4: Conduct Your HIPAA Risk Assessments

A risk assessment is how you identify the gaps between your current security posture and what HIPAA requires. Six audits must be conducted:

  • [ ] Security Risk Assessment (SRA) — identify threats to ePHI confidentiality, integrity, and availability; document likelihood and impact of each threat; implement controls proportionate to risk
  • [ ] Privacy Standards Audit — verify compliance with the Privacy Rule
  • [ ] HITECH Subtitle D Privacy Audit — covers electronic health records and related privacy requirements
  • [ ] Security Standards Audit — verify Security Rule technical and administrative safeguard implementation
  • [ ] Asset and Device Audit — inventory all devices and media that store or access ePHI
  • [ ] Physical Site Audit — verify physical access controls at all facilities housing ePHI

For each audit, document:

  • Identified threats and vulnerabilities
  • Current security measures in place
  • Likelihood and potential impact of each threat
  • Risk level determination
  • Planned remediation measures

✅ Step 5: Document Everything

If it isn’t documented, it didn’t happen — especially during an OCR audit. HIPAA requires documentation of:

  • [ ] All security policies and procedures
  • [ ] Risk assessments and analyses
  • [ ] BAAs with all business associates
  • [ ] Employee training completion records
  • [ ] Incident and breach notification documentation
  • [ ] Disaster recovery and contingency plans
  • [ ] PHI access and disclosure authorizations
  • [ ] Notice of Privacy Practices

Retention requirement: All HIPAA documentation must be retained for a minimum of 6 years from the date of creation or the date it was last in effect — whichever is later.


HIPAA Compliant Cloud Hosting Checklist

For organizations storing or transmitting PHI in the cloud, your hosting provider must meet these ten requirements:

🔄 Rotate your phone for a better view of the comparison table.
Requirement What to Verify
1. Signed BAA Provider signs a BAA before any PHI is hosted
2. Proven HIPAA infrastructure Dedicated HIPAA environment, not shared consumer hosting
3. Encryption at rest AES-256 encryption for all stored ePHI
4. Encryption in transit TLS 1.2+ for all data transmission
5. 24/7 monitoring Continuous malware monitoring, intrusion detection
6. Vulnerability scanning Regular scans with documented remediation
7. Server hardening Automated patches, managed firewalls, security updates
8. Off-site backups Geographically separate backups, minimum 50 miles from primary
9. 6-year log retention Access logs retained for 6 years per HIPAA requirement
10. Compliance manager Dedicated compliance contact accessible to you

HIPAA Vault meets all ten requirements — with a signed BAA, NIST 800-53 and SOC 2 certified infrastructure, U.S.-based servers and staff, and a dedicated compliance manager on every account.


2026 Updates: What’s Changed in HIPAA Compliance

The End of “Addressable” Specifications

The 2025 proposed HIPAA Security Rule update — the first major revision since 2005 — proposes eliminating the distinction between “required” and “addressable” implementation specifications. Under the current framework, organizations could document a reason not to implement certain controls (like MFA or encryption) if they deemed it unreasonable.

The proposed rule would make the following controls explicitly required:

  • Multi-factor authentication (MFA)
  • Data backup and disaster recovery with specific technical parameters
  • Vulnerability scanning on a defined schedule
  • Encryption as the standard, not an addressable alternative

As of July 2026, the final rule has not been issued. Healthcare organizations should treat all formerly addressable controls as mandatory now.

OCR Enforcement Is Accelerating

HHS Office for Civil Rights enforcement has increased significantly. A single 2024 enforcement action against Montefiore Medical Center resulted in a $4.75 million penalty — exceeding OCR’s total HIPAA enforcement collections for all of 2023. Civil penalties are adjusted periodically for inflation, with annual caps reaching into the millions for willful neglect.


Quick-Reference HIPAA Compliance Checklist

Copy and use this checklist for your organization’s compliance review:

Administrative Safeguards

  • [ ] Security Officer assigned and documented
  • [ ] Privacy Officer assigned and documented
  • [ ] Annual Security Risk Assessment (SRA) completed and documented
  • [ ] Workforce access policies established
  • [ ] Employee HIPAA training completed annually with records
  • [ ] BAAs executed with all business associates
  • [ ] Principle of Least Privilege enforced
  • [ ] Incident response plan documented
  • [ ] Disaster recovery/contingency plan documented
  • [ ] Regular compliance audits scheduled

Technical Safeguards

  • [ ] Unique user IDs for all staff accessing PHI
  • [ ] Multi-factor authentication (MFA) enabled
  • [ ] Automatic session logoff configured
  • [ ] Audit logging enabled and reviewed regularly
  • [ ] Encryption at rest (AES-256) implemented
  • [ ] Encryption in transit (TLS 1.2+) implemented
  • [ ] Vulnerability scanning scheduled and documented
  • [ ] Emergency access procedures documented

Physical Safeguards

  • [ ] Facility access controls in place
  • [ ] Workstation security policies established
  • [ ] Device and media disposal procedures documented
  • [ ] Data center physical security verified

Cloud Hosting

  • [ ] HIPAA-compliant hosting provider selected
  • [ ] BAA signed with hosting provider
  • [ ] Encryption at rest confirmed
  • [ ] Off-site backups configured
  • [ ] 6-year log retention confirmed
  • [ ] Compliance manager identified

Documentation

  • [ ] All policies and procedures documented
  • [ ] All BAAs retained
  • [ ] Training records retained
  • [ ] Risk assessment records retained (6 years)
  • [ ] Breach notification procedures documented

Is your organization HIPAA compliant? HIPAA Vault provides fully managed hosting with a signed BAA, NIST 800-53 certified infrastructure, and a dedicated compliance manager — starting at $120/month.

View hosting plans →  |  Schedule a free risk assessment →


Frequently Asked Questions


This article is educational and does not constitute legal advice. Consult a qualified HIPAA compliance attorney for guidance specific to your organization.