Pabau Engage inbox

Pabau Engage is here: every patient conversation in one inbox.

Learn more
Book a demo Book a demo
☰
Compliance and security

A complete HIPAA compliance checklist for primary care in the U.S.

Avatar photo Katy Piper
Last Updated: September 22, 2026
Reviewed by: Avatar photo Lucy Galloway

This HIPAA compliance checklist for primary care covers the 10 steps a US practice works through to protect patient data and satisfy HIPAA.

A HIPAA compliance checklist is a structured list of the safeguards, policies, and documents the law requires of you. Working through one turns a sprawling federal rulebook into tasks you can assign, date, and evidence.

The checklist below is current for 2026. It carries the penalty figures that took effect on January 28, 2026, and the Security Rule overhaul that HHS has proposed but not yet finalized.

Whether you are opening a new primary care practice or reviewing protocols you wrote years ago, work down the list in order.

Key takeaways
Found our content helpful?

Key takeaways

HIPAA applies to covered entities, their business associates, and any subcontractor those associates hire to handle patient data.

The 10-step checklist below runs from risk analysis to employee termination, and each step produces documentation you can show an auditor.

Penalty tiers rose on January 28, 2026, and now run from $145 to $73,011 per violation, capped at $2,190,294 a year.

HHS has proposed making multi-factor authentication and encryption of e-PHI mandatory, so close those two items before the rule is final.

Practice management software like Pabau holds the audit logs, access controls, and consent records that prove compliance rather than assert it.

Who needs to be HIPAA compliant?

HIPAA applies to three covered entities — healthcare providers, health plans, and healthcare clearinghouses — plus every business associate handling patient data on their behalf.

Covered entities are the organizations the federal law names directly:

  • Healthcare providers are the organizations and individuals who handle protected health information (PHI) or electronic protected health information (e-PHI) directly. Physicians, primary care practices, hospitals, and med spas all sit in this group.
  • Health plans include insurance companies, HMOs, government programs such as Medicare and Medicaid, employer-sponsored plans, and Medicare prescription drug card sponsors.
  • Healthcare clearinghouses process health information for billing and convert non-standard electronic formats into standardized ones, so data can pass cleanly between providers, patients, and payers.

Two further groups sit behind them, and both are bound by the same rules:

  • Business associates (BAs) provide services to covered entities that involve PHI, such as third-party billing, IT support, medical transcription, and cloud storage. Each one signs a Business Associate Agreement (BAA) committing it to protect that data.
  • Subcontractors of BAs are the third parties a business associate hires to handle PHI on its behalf. The software company that stores or processes the records is the usual example.

HIPAA compliance checklist for business associates

A HIPAA compliance checklist for business associates has four items: a signed BAA, an independent risk analysis, the Security Rule safeguards, and subcontractor flow-down agreements.

The BAA is the contract that starts the relationship, and a thin one causes trouble later. The agreement has to state the permitted uses of PHI, the safeguards the associate will apply, and how quickly a suspected breach reaches you.

The BAA also has to say what happens at the end. When the contract stops, the associate returns or destroys the PHI it holds, and the agreement names which of the two applies.

Flow-down is worth verifying in writing. A business associate that hires a subcontractor has to bind that subcontractor by contract to the same obligations it owes you. Ask your billing company who hosts its servers, then ask to see that agreement.

Since the Omnibus Rule took effect, business associates are also directly liable to the Office for Civil Rights. A breach at your transcription vendor is their enforcement problem as well as yours.

What are the 4 main HIPAA rules that primary care providers must know?

Four rules define what HIPAA compliance means in practice: the Privacy Rule, the Security Rule, the Breach Notification Rule, and the Omnibus Rule.

  • The HIPAA Privacy Rule limits who can access and share PHI, and protects a patient’s rights over their own health data.
  • The HIPAA Security Rule sets the administrative, physical, and technical safeguards that protect e-PHI.
  • The HIPAA Breach Notification Rule sets who you tell after an incident compromises patient data, and how long you have to do it.
  • The HIPAA Omnibus Rule extended and clarified those protections, and it is what made business associates and their subcontractors directly accountable.

The four rules differ in what triggers them and in how fast you have to move. The table below is short enough to pin above the front desk.

RuleWhat it governsKey triggerDeadlinePenalty tie-in
Privacy RuleWho may use or disclose PHI, and what rights patients hold over itAny use or disclosure beyond treatment, payment, or healthcare operations30 days to give a patient a copy of their recordImpermissible use and disclosure is the issue OCR investigates most
Security RuleAdministrative, physical, and technical safeguards for e-PHICreating, receiving, storing, or transmitting e-PHI in any systemNo single clock, but safeguards have to be in place continuouslyA missing risk analysis is one of OCR’s most cited failures
Breach Notification RuleWhat you do once unsecured PHI has been exposedUnsecured PHI accessed, used, or disclosed without permission60 days to notify patients and OCR, plus local media at 500 or more peopleLate notice is a separate violation, on top of the breach itself
Omnibus RuleBusiness associate and subcontractor liabilityA contractor or its subcontractor touches your patients’ PHIA signed BAA before any PHI changes handsBusiness associates answer to OCR directly, not only to you

The next section goes deeper on the Security Rule and the administrative, physical, and technical safeguards that protect e-PHI. Practices running a system built for primary care get several of these controls configured from the start.

Ensure confidentiality, integrity, and availability of e-PHI

A Security Rule checklist starts with three properties. Your e-PHI has to stay confidential, intact, and available on every system that holds it.

  • Confidentiality means only authorized people reach e-PHI. A receptionist who books appointments does not need the clinical note attached to them.
  • Integrity means nobody alters or destroys e-PHI without authorization, and that any change is traceable to a named user.
  • Availability means an authorized clinician can open the record when the patient is in front of them, including during an outage.

Identify and protect against security threats

Threats to e-PHI are found by looking for them on a schedule, not by waiting for an incident to surface one.

Run regular risk assessments across your systems and processes. The recurring findings are unpatched software, weak or shared passwords, and personal devices holding patient data. Many practices now run compliance software that automates the scan and flags patient information heading to the wrong recipient.

Protect against unauthorized uses or disclosures

Unauthorized disclosure is controlled by limiting who can reach a record in the first place, rather than by trusting people not to look.

Restrict access to e-PHI by job role, so a staff member sees the fields their work needs and no others. Then add two-factor or multi-factor authentication (MFA) on every system holding patient data.

MFA is worth doing now for a second reason. HHS has proposed making it mandatory, which we cover further down.

Ensure workforce compliance

Workforce compliance rests on training that is mandatory, repeated, and recorded against each named employee.

Your team handles sensitive information every hour of the day, so the training has to cover the situations they meet on a normal day. Teach them to recognize a phishing email, to handle a patient’s request for records, and to keep patient detail off social media.

Keep the attendance record. Training you cannot evidence counts as training you did not deliver.

Diagram of the 4 main HIPAA rules: Privacy, Security, Breach Notification, and Omnibus
The four rules overlap in practice, so a single incident can engage the Privacy Rule and the Breach Notification Rule at once.

What are the penalties for non-compliance with HIPAA?

HIPAA penalties run from $145 to $73,011 per violation, with an annual cap of $2,190,294 for repeated violations of the same requirement.

Those figures come from the Department of Health and Human Services, which published its annual inflation adjustment in the Federal Register on January 28, 2026. The Office for Civil Rights (OCR) enforces them, and it opens an investigation whether or not the failure was deliberate.

Which tier you land in depends on what you knew and what you did about it:

  • Tier 1 — no knowledge. You did not know about the violation and could not reasonably have known. $145 to $73,011 per violation.
  • Tier 2 — reasonable cause. You should have known, but the failure does not amount to willful neglect. $1,461 to $73,011 per violation.
  • Tier 3 — willful neglect, corrected. You disregarded the requirement, then fixed it within 30 days. $14,602 to $73,011 per violation.
  • Tier 4 — willful neglect, not corrected. You disregarded the requirement and left it uncorrected past 30 days. $73,011 to $2,190,294 per violation.

One nuance is worth knowing. Since 2019, OCR has applied lower annual caps to the first three tiers under a notice of enforcement discretion. The statutory figures above are what the Federal Register publishes, so budget your risk against those.

A HIPAA violation can also be a criminal offense. Where PHI is knowingly stolen or misused for commercial advantage, personal gain, or malicious harm, the sentence can reach ten years.

What’s changing in HIPAA compliance for primary care in 2026?

No new HIPAA requirement took effect in 2026, but HHS has proposed a Security Rule overhaul that would make multi-factor authentication and e-PHI encryption mandatory.

OCR published the notice of proposed rulemaking on January 6, 2025, and the comment period closed on March 7, 2025. Thousands of comments came back, and the rule is still proposed rather than final.

The structural change is the one to understand. Today the Security Rule splits its specifications into “required” and “addressable”, and addressable lets you document a reasonable alternative instead. The proposal removes that split, with narrow exceptions, so almost every specification becomes required.

For a primary care practice, four items move from optional-with-paperwork to expected:

  • Multi-factor authentication on every system that reaches e-PHI, including the ones a locum tenens physician uses once a month.
  • Encryption of e-PHI both at rest and in transit, which reaches your backups as well as your email.
  • A written asset inventory and network map showing where patient data lives and how it moves between systems.
  • A tested restoration plan that brings critical systems and data back within 72 hours.

There is no effective date yet, and HHS has pushed final action into 2027 on its regulatory agenda. Treat the list as preparation rather than obligation.

Preparing early is cheap here. MFA, encryption, and an asset inventory are worth having on their own merits. Doing them now also spreads the work over a year, rather than into the 180-day compliance window the proposal envisages.

HIPAA compliance checklist for primary care providers: 10 steps

Ten steps make up the HIPAA checklist below, and each one ends in a document or a log you can hand to an auditor.

  1. Run a risk analysis, then act on what it finds.
  2. Put administrative policies and a named security officer in place.
  3. Secure the building, the workstations, and the devices.
  4. Apply technical safeguards to every system holding e-PHI.
  5. Meet the Privacy Rule on use, disclosure, and patient access.
  6. Build a breach notification procedure you can run under pressure.
  7. Audit and review on a fixed schedule.
  8. Keep your HIPAA compliance documents for six years.
  9. Write a contingency plan for outages and disasters.
  10. Close accounts and collect devices the day an employee leaves.

Before you start, it helps to see where patient data moves during a primary care day. We call this the Primary Care PHI Touchpoint Map, and it pairs four everyday handoffs with the rule that governs each one.

The Primary Care PHI Touchpoint Map.
The Primary Care PHI Touchpoint Map ties each handoff to one rule, drawn from the HHS Privacy, Security, and Breach Notification Rules described above.

Each touchpoint has a characteristic way of going wrong, and each one is covered by a step further down this page.

TouchpointWhat goes wrong hereRule that governs itChecklist step
Specialist referral letterThe letter carries the whole record when the specialist needed one resultPrivacy Rule, minimum necessaryStep 5
Lab order and result exchangeResults arrive by unencrypted email, or on a fax line nobody ownsSecurity Rule, transmission securityStep 4
E-prescribingA shared login leaves no audit trail showing who issued the prescriptionSecurity Rule, access and audit controlsStep 4
Patient portal messagingA message routed to the wrong patient exposes PHI and starts the 60-day clockBreach Notification RuleStep 6

1. Risk analysis and management

Risk analysis finds the weak points in how you handle e-PHI, and risk management is what you do about them. OCR’s HIPAA audit programs have repeatedly found this to be the requirement practices handle worst.

The Department of Health and Human Services lists four activities for a security risk assessment:

  • Evaluate the likelihood and impact of each risk to e-PHI, from aging servers to mobile devices to third-party services.
  • Put security measures in place for the risks you identified, such as encryption, password policy, or access control.
  • Document the measures you chose and, where it is required, your reasoning for choosing them.
  • Maintain those protections continuously, rather than treating the assessment as a one-off.

Worked examples make the assessment easier to run. Three turn up in almost every primary care practice:

  • A laptop that goes home with a clinician each night.
  • A fax line nobody owns, receiving results all day.
  • A departed nurse whose login still works.

Each one is a finding, and each gets an owner and a fix date.

2. Administrative actions and policies

Administrative safeguards are the internal processes that decide how staff reach and handle e-PHI. Your HIPAA compliance policies and procedures live here, and they cover four areas:

  • Security management process for identifying risks and vulnerabilities, and for tracking each one to closure.
  • Security personnel. Name a security officer and a privacy officer who own these policies. In a small practice that is often one person, and the appointment still gets written down.
  • Information access management. Grant access to e-PHI by role. Practice management software like Pabau applies role-based access from the staff record, so permissions follow the job rather than a spreadsheet.
  • Workforce training and management. Anyone handling patient information trains on the HIPAA requirements before they get a login.

Add a sanctions policy while you are here. A sanctions policy sets out what happens when a workforce member breaks one of these rules. OCR expects to see it applied consistently, rather than case by case.

Then evaluate. Reassess your policies on a set date each year and update them against the Security Rule. If the difference between a policy and a procedure is still fuzzy in your practice, our guide to protocol versus procedure untangles the two.

HIPAA policy template: What to include

A HIPAA policy template needs seven parts: scope, definitions, the rule it implements, a named owner, the procedure itself, sanctions, and a review date.

Most policies that fail an audit fail on two of those seven. They name no owner, so nobody keeps them current. And they carry no review date, so the version on file predates the system it describes.

Write the procedure section as steps a new hire could follow without asking. “Verify patient identity before releasing records” is a principle. “Ask for date of birth and address, check both against the record, then log the release” is a procedure.

Keep the superseded versions too. When OCR asks what your policy was on the date of an incident, the answer has to come from the file rather than from memory.

3. Physical safeguards

Physical safeguards protect the rooms, workstations, and devices where PHI is stored or processed.

Start with facility access controls that limit who gets into those areas. Keycard or biometric entry, security cameras, and a visitor sign-in protocol all count, and a locked records room counts too.

Then secure the equipment itself:

  • Place screens where a waiting patient cannot read them
  • Lock computers and portable devices when they are not in use
  • Require a password or biometric check at every login
  • Wipe devices before you dispose of them, and record that you did

4. Technical safeguards

Technical safeguards make activity involving e-PHI both controlled and traceable. Databases sit here too. Every database and EHR holding patient records needs its own access controls and its own audit log.

  • Access controls. Give each user a unique username and password, set automatic log-off after inactivity, and assign permissions by role.
  • Audit controls. Log who opened which record and when, monitor those logs, and alert on activity that looks wrong.
  • Integrity controls. Run systems that detect unauthorized alteration or destruction of e-PHI.
  • Transmission security. Encrypt e-PHI in transit, and route remote access through a VPN rather than an open connection.

Transmission security is the one to check first in primary care, because lab results and e-prescriptions leave the building every day. Both are touchpoints on the map above.

5. Privacy Rule compliance

The Privacy Rule allows PHI to be used or disclosed for treatment, payment, or healthcare operations, and asks for the patient’s written authorization beyond that.

Marketing and research both sit outside those three purposes. Record the patient’s consent on a HIPAA authorization form that names the information shared, the recipient, and the period it covers.

Minimum necessary is the part that bites in primary care. A specialist referral needs the relevant history and results, not the entire chart, and a care-coordination message needs less again. The first touchpoint on the map above is exactly this.

Patients also hold the right to see and copy their own records. You have 30 days to provide access, and a single 30-day extension if you tell the patient why.

6. Breach Notification Rule compliance

The Breach Notification Rule sets what you do in the days after unsecured patient data is exposed.

Notify the affected patients and OCR within 60 days. A breach affecting 500 or more individuals in one state or jurisdiction adds a third notice, to prominent local media, inside the same window. OCR then posts the incident publicly.

Smaller breaches follow a different clock. Incidents affecting fewer than 500 people are logged as they happen and reported to OCR within 60 days of the year end.

Document each breach either way, and take whatever steps still reduce the harm. Then write down what you changed, so the same route cannot be used twice.

7. Regular audits and reviews

HIPAA compliance is not a one-time task. Put a HIPAA compliance audit checklist on a fixed calendar and work through it on the same dates each year.

A workable HIPAA audit checklist covers four questions:

  • Who currently has access to systems holding e-PHI, and does each of them still need it?
  • What do the audit logs and system activity reports show, and has anyone looked at them?
  • Do your policies still describe the systems and situations the practice has today?
  • Would your incident response plan work if you ran it tomorrow morning?

The access review is the one that pays for itself. In practices we onboard, the list of active logins is almost always longer than the list of current staff.

8. Documentation and record-keeping: The HIPAA compliance documents you need

HIPAA requires you to keep your HIPAA compliance documents for six years from the date they were created or last in effect, whichever is later.

That retention period covers your policies and procedures, your risk analyses, and your training records. The same six years covers your signed BAAs, your breach log, and any notice you gave patients. Keep the superseded versions, not only the current ones.

Documentation is what turns a claim into proof during an investigation. Good documentation also shortens the response when something goes wrong, because the answer is already on file. Consistent clinical records help here too, and our guide to safer clinical notes covers how to structure them.

9. Contingency planning

A contingency plan keeps patient data secure and reachable during an outage, a cyber-attack, a natural disaster, or a hardware failure.

Four parts make one that works:

  • Regular backups of patient records, billing data, and the appointment schedule.
  • A written restoration procedure with the steps for bringing critical systems and e-PHI back.
  • Named roles, so IT restores systems while the front desk handles patient communication.
  • An emergency mode plan covering how clinicians reach PHI and keep treating while systems are down.

Test the restoration once a year. A backup nobody has restored from is an assumption, and the proposed Security Rule changes would put a 72-hour target on it.

10. Employee termination procedures

When someone leaves your practice, their access to e-PHI ends the same day, and a repeatable process is what makes that happen.

Deactivate their user accounts across every system, not only the EHR. Collect keys, access badges, and any laptop, tablet, or phone the practice issued them.

Then record the date each account was closed. That log is what answers the question during an audit, and it is the fastest of all these steps to let slip.

Your HIPAA compliance software checklist: What Pabau covers

A HIPAA compliance software checklist comes down to one question. Can the system produce the evidence on demand, or only promise that the controls exist?

Most practices we onboard arrive with patient data spread across a paper file, a scheduling tool, a forms app, and a shared inbox. Four systems mean four access lists to review, four audit trails to pull, and four places a breach can start.

Pabau is an all-in-one practice management system that holds records, scheduling, forms, consent, and patient communication in one place. One access review then covers the lot, and the audit trail sits against the patient record rather than in a separate log nobody opens.

The security controls that map onto this checklist:

  • Data encryption, in transit and at rest
  • Secure hosting
  • Role-based access control and user authentication
  • Two-factor authentication
  • Audit logs and trails against every record
  • Regular data backups and disaster recovery

Every Pabau subscription includes all of them, so a smaller practice gets the same controls as a multi-site group. Dedicated medical scheduling software also keeps appointment records centralized and straightforward to audit.

If you are still choosing a platform, our roundup of primary care software compares the options on the controls that matter here.

Pabau security settings showing HIPAA compliance controls
Pabau’s security settings gather the controls this checklist asks for, so an access review is one screen rather than four systems.
Role-based access control settings in Pabau showing user permissions by job role
Pabau’s role-based access control sets permissions by job role, which is the evidence step 2 of this checklist asks you to produce.

Software supports compliance, and it does not hand it to you. Pabau gives you the controls and the logs. The risk analysis, the policies, and the training stay yours to run.

Keep your HIPAA evidence in one system

Pabau holds patient records, consent forms, audit logs, and role-based access in a single practice management system. Your access reviews and breach investigations then start from one place instead of four.

Pabau clinic management dashboard

Conclusion

HIPAA reads as an unmanageable body of regulation until you break it into steps with owners and dates. Ten of them is the whole job for a primary care practice.

Two of those steps earn attention before the rest. The risk analysis, because OCR asks for it first and so few practices can produce a current one. And the access review, because it is the cheapest control you own and the one that drifts fastest.

The proposed Security Rule changes are worth acting on ahead of the deadline. Turning on MFA and encrypting e-PHI takes an afternoon now, against a 180-day scramble once a final rule lands.

Whichever way you get there, you have to produce the evidence on the day someone asks. Book a demo to see how Pabau keeps access controls, audit logs, and consent records in one place for your primary care practice.

Continue your research

Continue your research

Writing up consultations that hold up to scrutiny? Safer clinical notes sets out how to structure records so the next clinician, and any auditor, can follow them.

Comparing platforms on their compliance controls? Primary care software weighs the main options on records, scheduling, and the audit trail behind both.

Running video appointments as well as in-person ones? Telehealth in GP clinics covers how remote consultations change where patient data travels.

Setting up a practice from scratch? Starting a medical practice walks through the licensing, staffing, and systems decisions that come before your first patient.

Frequently asked questions

What is the key to HIPAA compliance?

The key to HIPAA compliance is documentation: a current risk analysis, written policies, training records, and audit logs that show what you did and when. Best practices for HIPAA compliance all reduce to the same habit. Do the work, then leave evidence that the work happened. A control nobody can prove was in place counts for very little during an OCR investigation.

What is the first step toward Security Rule compliance?

The first step toward Security Rule compliance is a risk analysis covering every system that creates, receives, stores, or transmits e-PHI. Step 1 of the checklist above sets out what it involves. Until you know where patient data lives and how it moves, you cannot choose safeguards that fit. OCR also treats a missing risk analysis as a finding in its own right.

Which is a recommended best practice to maintain HIPAA compliance?

A scheduled access review is the single recommended best practice most worth adopting. Once a quarter, list every active login to systems holding e-PHI and confirm each person still needs it. This catches departed staff, temporary cover, and permissions that were widened for one task and never narrowed again. The whole review takes under an hour in a small practice.

Is there a free HIPAA compliance checklist available?

Yes. The 10-step checklist on this page is free to read and use, with no signup and no email required. Several compliance vendors also publish a HIPAA compliance checklist PDF, though most sit behind a form. We do not gate ours, so copy the 10 steps into your own document and assign an owner and a date to each one.

What are the 7 elements of healthcare compliance?

The seven elements come from the Office of Inspector General and describe an effective healthcare corporate compliance program. Those elements are written policies and standards of conduct, a designated compliance officer and committee, and effective training. The remaining four are open lines of communication, internal monitoring and auditing, enforced disciplinary standards, and prompt corrective action. They frame compliance across the whole organization, so HIPAA sits inside them rather than replacing them.

Found our content helpful?
×