---
title: "HIPAA Compliance Checklist"
description: "A practical checklist for HIPAA Security Rule and Privacy Rule readiness — safeguards, risk analysis, business associate agreements, and breach notification."
keywords:
  - HIPAA checklist
  - HIPAA compliance checklist
  - HIPAA Security Rule checklist
  - PHI security checklist
---

# HIPAA Compliance Checklist

A working checklist for covered entities and business associates preparing for HIPAA scrutiny — audits, breach investigations, or routine due diligence. Pair this with our full [HIPAA compliance program](/compliance/hipaa) for implementation detail.

## Risk Analysis & Management

- [ ] Formal, documented risk analysis covering all systems that touch PHI
- [ ] Risk management plan in place addressing identified gaps, with owners and timelines
- [ ] Risk analysis refreshed on a recurring cycle and after significant system changes

## Administrative Safeguards

- [ ] Designated Security Officer and Privacy Officer named
- [ ] Workforce security training on PHI handling delivered and documented
- [ ] Sanction policy exists for workforce members who violate PHI policies
- [ ] Business Associate Agreements (BAAs) signed with every vendor that touches PHI

## Technical Safeguards

- [ ] Unique user IDs and MFA enforced for access to systems containing PHI
- [ ] Automatic session logoff configured on workstations and applications
- [ ] Encryption applied to PHI at rest and in transit
- [ ] Audit logging enabled on all systems storing or transmitting PHI, with regular review

## Physical Safeguards

- [ ] Facility access controls documented and enforced for on-prem systems
- [ ] Workstation use policies restrict PHI access to authorized devices
- [ ] Device and media disposal procedures ensure PHI is unrecoverable

## Breach Notification Readiness

- [ ] Breach detection capability exists that can identify unauthorized PHI access quickly
- [ ] Documented breach notification process meets the 60-day HHS reporting requirement
- [ ] Incident response plan tested at least annually with a tabletop exercise

## Ongoing Testing

- [ ] Continuous vulnerability scanning covers systems in scope for PHI
- [ ] Penetration testing performed regularly, not as a one-time exercise
- [ ] Findings are tracked to remediation with defined SLAs by severity

## Where Alastor InfoSec Fits

[Alastor Shield](/products/alastor-shield) keeps risk analysis documentation and BAA tracking continuously current instead of reconstructed before an audit. [Alastor Pulse](/products/alastor-pulse) provides the ongoing penetration testing and vulnerability management HIPAA's Security Rule expects as an active, evolving program.

[Talk to our team](/about-us) about a HIPAA readiness assessment scored against this checklist.
