← Back to Blog
HIPAA · December 8, 2025 · 5 min read

Comprehensive Guide to HIPAA Compliance Checklist

HIPAA compliance is essential, detailed, and non-negotiable. This guide breaks down the steps every practice and business associate needs to protect patient information while keeping operations running smoothly.

Want this as a printable PDF?Get the full checklist as a two-page download you can keep or share with your team.
Get the free PDF

The core compliance steps

  1. Conduct a risk assessment. Identify where PHI is stored, received, maintained, or transmitted, and look for vulnerabilities across your systems and processes.
  2. Develop and implement policies and procedures. Write clear policies covering data access controls and breach notification protocols, and keep them practical and accessible to staff.
  3. Train your workforce. Everyone in the organization needs to understand HIPAA rules and their role in compliance, reinforced with regular training.
  4. Secure your systems. Use technical safeguards — encryption, firewalls, secure authentication — alongside physical safeguards like locked file cabinets and controlled workstation access.
  5. Monitor and audit regularly. Compliance isn't a one-time event; regular audits catch issues early.
  6. Prepare for breaches. Have a clear incident response plan ready so you can act quickly if one occurs.

The five HIPAA rules to know

Privacy RuleProtects individually identifiable health information and limits use or disclosure without patient authorization.
Security RuleRequires administrative, physical, and technical safeguards for electronic PHI — strong passwords, encrypted transmissions, and more.
Breach Notification RuleRequires notifying affected individuals, HHS, and sometimes the media promptly after a breach of unsecured PHI.
Enforcement RuleOutlines penalties for violations and the investigation and hearing process.
Omnibus RuleStrengthens privacy and security protections, extending certain requirements to business associates.

Practical measures worth adopting

  • Role-based access controls — billing staff don't need access to clinical notes
  • Encrypt data at rest and in transit, whether stored or sent
  • Maintain audit logs of who accessed PHI and when
  • Keep software and systems current to close known vulnerabilities
  • Secure physical locations with locks, cameras, and visitor logs
  • Assign a breach response team with clear roles, and practice the plan
  • Document everything — risk assessments, training, and audits alike

HIPAA compliance is an ongoing process, not a one-time certification. See exactly how VirtualScrivener applies these principles on our HIPAA compliance page →