Free checklist

The HIPAA compliance checklist for businesses.

Twelve questions across administrative, technical, physical and contingency safeguards — the same ones an auditor opens with, and the same ones our guided self-audit is built around.

HIPAA's Security Rule organizes requirements into a handful of safeguard categories. None of this replaces a formal risk analysis, and answering "yes" to everything below isn't a certification — but if you can't say yes to most of it, that's exactly what an investigation finds first.

Administrative safeguards

Policies, training and accountability — the paperwork an auditor asks for first.

  • Has a written security risk analysis been completed in the last 12 months?

    Required under the Security Rule, and the most cited deficiency in audits.

  • Have you designated a Privacy and Security Official?

    A named person accountable for policies and incident response.

  • Has every workforce member completed HIPAA training in the last 12 months?

    Track this on your team dashboard.

  • Do you have signed Business Associate Agreements with every vendor handling PHI?

    Billing services, cloud storage, IT support, transcription.

  • Is there a written breach response plan with notification deadlines?

    Include the 60-day individual notification requirement.

Technical safeguards

Access controls, encryption and authentication on the systems that touch PHI.

  • Are all laptops, phones and tablets that touch patient data fully encrypted?

    Full-disk encryption (FileVault, BitLocker, or mobile device encryption).

  • Does every staff member have unique login credentials?

    No shared accounts, no generic 'frontdesk' logins.

  • Is multi-factor authentication enabled on systems holding patient data?

    Email, EHR, cloud storage and remote access.

  • Do workstations lock automatically after a period of inactivity?

    Recommended: 10 minutes or less in shared spaces.

Physical safeguards

Locks, storage and disposal for the devices and paper that hold PHI.

  • Are paper records and servers stored in locked, access-controlled areas?

    Include visitor logs where applicable.

  • Is there a secure disposal process for paper and retired devices?

    Shredding and certified media sanitisation.

Contingency safeguards

What happens when something goes wrong — backups, restores, and recovery.

  • Are patient records backed up and has a restore been tested?

    An untested backup is not a backup.

Answered "no" somewhere?

That's normal — most businesses have gaps. What matters is documenting how you're closing them.

AI drafts the fix

Run this same checklist inside HIPAA TrustGuard and AI drafts the policy or procedure for every gap, from your actual answers.

Prove it, don't just say it

Pass an independent AI validation pass and publish a trust badge clients can verify themselves at a public URL.

Turn this checklist into a real audit trail.

$499/year, unlimited staff — the guided self-audit, AI-drafted documentation, and a verifiable trust badge.

Start your compliance suite