Alastor InfoSec
← All Checklists

HIPAA Compliance Checklist

A working checklist for covered entities and business associates preparing for HIPAA scrutiny — audits, breach investigations, or routine due diligence. Pair this with our full HIPAA compliance program for implementation detail.

Risk Analysis & Management

  • Formal, documented risk analysis covering all systems that touch PHI
  • Risk management plan in place addressing identified gaps, with owners and timelines
  • Risk analysis refreshed on a recurring cycle and after significant system changes

Administrative Safeguards

  • Designated Security Officer and Privacy Officer named
  • Workforce security training on PHI handling delivered and documented
  • Sanction policy exists for workforce members who violate PHI policies
  • Business Associate Agreements (BAAs) signed with every vendor that touches PHI

Technical Safeguards

  • Unique user IDs and MFA enforced for access to systems containing PHI
  • Automatic session logoff configured on workstations and applications
  • Encryption applied to PHI at rest and in transit
  • Audit logging enabled on all systems storing or transmitting PHI, with regular review

Physical Safeguards

  • Facility access controls documented and enforced for on-prem systems
  • Workstation use policies restrict PHI access to authorized devices
  • Device and media disposal procedures ensure PHI is unrecoverable

Breach Notification Readiness

  • Breach detection capability exists that can identify unauthorized PHI access quickly
  • Documented breach notification process meets the 60-day HHS reporting requirement
  • Incident response plan tested at least annually with a tabletop exercise

Ongoing Testing

  • Continuous vulnerability scanning covers systems in scope for PHI
  • Penetration testing performed regularly, not as a one-time exercise
  • Findings are tracked to remediation with defined SLAs by severity

Where Alastor InfoSec Fits

Alastor Shield keeps risk analysis documentation and BAA tracking continuously current instead of reconstructed before an audit. Alastor Pulse provides the ongoing penetration testing and vulnerability management HIPAA's Security Rule expects as an active, evolving program.

Talk to our team about a HIPAA readiness assessment scored against this checklist.

We use cookies to keep the platform secure and understand how our site is used. See our Security & Data policy for details.