Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

Free HIPAA Compliance Checklist and Risk Assessment:
Would Your Practice Would Pass an Audit?

HIPAA Audit Risk Check

  • 9 quick questions
  • Takes about 2 minutes
  • No sign-up to see your result

Your top next moves

    Nothing critical flagged. Keep everything current and re-check yearly.

    Book a call

    Use the interactive HIPAA compliance checklist to see where your practice actually stands.

    Answer 8 plain-English questions and get your audit-readiness in about 2 minutes, your risk level, the specific gaps to fix, and a printable checklist you can hand to your team or IT provider. No sign-up to see your result.

    What HIPAA compliance actually covers (the short version)

    HIPAA compliance comes down to three rules and three kinds of safeguards:
    The Privacy Rule

    Governs how you use and disclose patient information (PHI)

    The Security Rule

    Governs how you protect the electronic version of it (ePHI), your EHR, email, backups, and file shares.

    To satisfy the Security Rule you put three categories of safeguards in place:

    Administrative: Policies, risk analysis, training, a named Privacy Officer and Security Officer.

    Technical: Access control, encryption, audit logging.

    Physical: Facility and device controls.

    The Breach Notification Rule

    Governs what you do, and how fast, when protected data is exposed (for most breaches, affected individuals and the HHS Office for Civil Rights must be notified without unreasonable delay and no later than 60 days)

    The checklist below is organized around those safeguards.

    The Full HIPAA Compliance Checklist

    Work through each area. Anything you can’t confirm is a gap, if you can’t prove it, an auditor can’t either.
    • 1. Security Risk Analysis:

      ✓ A documented HIPAA risk analysis completed in the last 12 months (the single most-audited item, and the first thing OCR asks for).

      ✓ A written inventory of everywhere ePHI lives: EHR, email, imaging, backups, laptops, phones, cloud apps.

      ✓ A risk-management plan that tracks identified threats through to remediation.

    • 2. Access Control:

      ✓ A unique login for every user (no shared accounts).

      ✓ Access granted on a “minimum necessary” / least-privilege basis.

      ✓ Multi-factor authentication (MFA) enforced on systems and remote access to ePHI.

      ✓ Automatic log-off on unattended workstations.

    • 3. Encryption:

      ✓ ePHI encrypted at rest (databases, servers, laptops, backups; AES-256).

      ✓ ePHI encrypted in transit (TLS on email, portals, file transfers).

    • 4. Audit Logging and Monitoring:

      ✓ Access logs enabled on every system that holds ePHI.

      ✓ Someone actually reviews those logs for failed logins, unusual access, and large data exports.

    • 5. Workforce training:

      ✓ All staff complete HIPAA training at least annually, with signed attestations.

      ✓ Training and attestation records retained for six years.

      ✓ A written sanctions policy for staff who violate procedures.

    • 6. Business Associate Agreements (BAAs):

      ✓ A current inventory of every vendor that stores, processes, or transmits your ePHI (IT provider, EHR, billing, cloud apps).

      ✓ A signed BAA in place with each vendor before they access ePHI.

    • 7. Breach response and incident management:

      ✓ A documented, tested incident-response and recovery plan.

      ✓ Your breach-notification obligations and timelines are known (individuals, HHS, and media where required; the 60-day clock).

    • 8. Device and media controls:

      ✓ Physical access to ePHI controlled (badge/locked-door access, visitor logs).

      ✓ Secure wipe or destruction of devices and media before disposal or reuse.

      ✓ Mobile devices and laptops that touch ePHI are managed and encrypted.

    • 9. Contingency planning and backup:

      ✓ Regular backups of ePHI that someone has actually tested by restoring.

      ✓ An emergency-access procedure and a disaster-recovery / continuity plan.

    • 10. Administrative wrapper:

      ✓ A formally designated Privacy Officer and Security Officer.

      ✓ Written Privacy, Security, and Breach-Notification policies.

      ✓ A Notice of Privacy Practices, plus patient access and amendment procedures.

    How to read your gaps?

    Most of the technical items above (MFA, encryption, audit logging, tested backups) live in your IT setup, not a policy binder, which is the half of HIPAA a managed IT partner operates for you.

    • 0 – 2 Gaps

      Strong Shape

    • 3 – 6 Gaps

      Real, findable gaps that would draw findings in an audit.

    • 7+ Gaps

      You’d likely fail an audit today and carry meaningful breach risk right now.

    HIPAA Compliance Checklist FAQ

    What should be on a HIPAA compliance checklist?
    A complete checklist covers the Security Rule’s administrative, physical, and technical safeguards plus the Privacy and Breach Notification Rules: a current risk analysis, access control and MFA, encryption of ePHI at rest and in transit, audit logging, workforce training, signed Business Associate Agreements, a breach-response plan, device and media controls, tested backups, and named Privacy and Security Officers. The 10 areas above map to each.
    How do I know if my practice is HIPAA compliant?
    Start with a documented Security Rule risk analysis. It inventories where ePHI lives, measures your safeguards against the rule, and produces a prioritized list of gaps. The self-assessment tool at the top of this page is a fast first read; a formal risk analysis is the documented version an auditor expects to see.
    What triggers a HIPAA audit?
    Usually one of three things: a complaint (from a patient, employee, or competitor), a reported breach (breaches affecting 500 or more individuals draw scrutiny automatically), or random selection under OCR’s audit program. Because you can’t predict the timing, the practical answer is to stay audit-ready year-round.
    How often should I run a HIPAA risk assessment?
    At least annually, and any time your systems, vendors, or practice change materially. It’s an ongoing obligation, not a one-time checkbox.
    Does a small practice really need all of this?
    Yes. The Security Rule scales to your size but is not optional for small offices. A small practice simply has fewer systems and vendors to cover. The gaps that trip up small practices most are a missing risk analysis, unsigned BAAs, and unencrypted devices.
    Do we need a Business Associate Agreement with our IT provider?
    Yes. If your IT provider or MSP can access, store, or transmit ePHI (most can), they’re a business associate and a signed BAA is required before that access. LeadingIT signs BAAs with practice clients as standard.

    Ready to close your gaps?

    If your result flagged three or more gaps, most of them are technical work an IT partner handles day to day. LeadingIT helps Chicagoland medical, dental, and specialty practices get, and stay, audit-ready, with the risk assessment, security controls, and documentation HIPAA requires.

    Email yourself the full result from the tool above, or book a free 15-minute gap review, or see how we deliver HIPAA compliance as a managed service.