Free HIPAA Compliance Checklist and Risk Assessment:
Would Your Practice Would Pass an Audit?
- 9 quick questions
- Takes about 2 minutes
- No sign-up to see your result
Your top next moves
Use the interactive HIPAA compliance checklist to see where your practice actually stands.
Answer 8 plain-English questions and get your audit-readiness in about 2 minutes, your risk level, the specific gaps to fix, and a printable checklist you can hand to your team or IT provider. No sign-up to see your result.
What HIPAA compliance actually covers (the short version)
Governs how you use and disclose patient information (PHI)
Governs how you protect the electronic version of it (ePHI), your EHR, email, backups, and file shares.
To satisfy the Security Rule you put three categories of safeguards in place:
Administrative: Policies, risk analysis, training, a named Privacy Officer and Security Officer.
Technical: Access control, encryption, audit logging.
Physical: Facility and device controls.
Governs what you do, and how fast, when protected data is exposed (for most breaches, affected individuals and the HHS Office for Civil Rights must be notified without unreasonable delay and no later than 60 days)
The Full HIPAA Compliance Checklist
- 1. Security Risk Analysis:
✓ A documented HIPAA risk analysis completed in the last 12 months (the single most-audited item, and the first thing OCR asks for).
✓ A written inventory of everywhere ePHI lives: EHR, email, imaging, backups, laptops, phones, cloud apps.
✓ A risk-management plan that tracks identified threats through to remediation.
- 2. Access Control:
✓ A unique login for every user (no shared accounts).
✓ Access granted on a “minimum necessary” / least-privilege basis.
✓ Multi-factor authentication (MFA) enforced on systems and remote access to ePHI.
✓ Automatic log-off on unattended workstations.
- 3. Encryption:
✓ ePHI encrypted at rest (databases, servers, laptops, backups; AES-256).
✓ ePHI encrypted in transit (TLS on email, portals, file transfers).
- 4. Audit Logging and Monitoring:
✓ Access logs enabled on every system that holds ePHI.
✓ Someone actually reviews those logs for failed logins, unusual access, and large data exports.
- 5. Workforce training:
✓ All staff complete HIPAA training at least annually, with signed attestations.
✓ Training and attestation records retained for six years.
✓ A written sanctions policy for staff who violate procedures.
- 6. Business Associate Agreements (BAAs):
✓ A current inventory of every vendor that stores, processes, or transmits your ePHI (IT provider, EHR, billing, cloud apps).
✓ A signed BAA in place with each vendor before they access ePHI.
- 7. Breach response and incident management:
✓ A documented, tested incident-response and recovery plan.
✓ Your breach-notification obligations and timelines are known (individuals, HHS, and media where required; the 60-day clock).
- 8. Device and media controls:
✓ Physical access to ePHI controlled (badge/locked-door access, visitor logs).
✓ Secure wipe or destruction of devices and media before disposal or reuse.
✓ Mobile devices and laptops that touch ePHI are managed and encrypted.
- 9. Contingency planning and backup:
✓ Regular backups of ePHI that someone has actually tested by restoring.
✓ An emergency-access procedure and a disaster-recovery / continuity plan.
- 10. Administrative wrapper:
✓ A formally designated Privacy Officer and Security Officer.
✓ Written Privacy, Security, and Breach-Notification policies.
✓ A Notice of Privacy Practices, plus patient access and amendment procedures.
How to read your gaps?
Most of the technical items above (MFA, encryption, audit logging, tested backups) live in your IT setup, not a policy binder, which is the half of HIPAA a managed IT partner operates for you.
- 0 – 2 Gaps
Strong Shape
- 3 – 6 Gaps
Real, findable gaps that would draw findings in an audit.
- 7+ Gaps
You’d likely fail an audit today and carry meaningful breach risk right now.
HIPAA Compliance Checklist FAQ
Ready to close your gaps?
If your result flagged three or more gaps, most of them are technical work an IT partner handles day to day. LeadingIT helps Chicagoland medical, dental, and specialty practices get, and stay, audit-ready, with the risk assessment, security controls, and documentation HIPAA requires.
Email yourself the full result from the tool above, or book a free 15-minute gap review, or see how we deliver HIPAA compliance as a managed service.