Digital Product · Instant Access

HIPAA Compliance
Checklist Pack

120+ action items, templates, and worksheets to establish and maintain a complete HIPAA compliance program.

📋 6 Sections ✅ 120+ Checklist Items 📄 BAA Template Included 📅 2026 Edition

Table of Contents

1Privacy Rule Requirements22 items
2Security Rule — Administrative Safeguards18 items
3Security Rule — Physical Safeguards14 items
4Security Rule — Technical Safeguards16 items
5Breach Notification & Incident Response20 items
6Business Associate Agreements (BAA)Template + 15 items
1
Privacy Rule Requirements (45 CFR Part 164, Subpart E)

The Privacy Rule establishes standards for the use and disclosure of PHI. Verify each item below with your Privacy Officer.

High Priority — OCR Audit Focus
Medium — Implement Within 90 Days
Best Practice — Ongoing
2
Security Rule — Administrative Safeguards (45 CFR §164.308)

Administrative safeguards are policies and procedures designed to manage the selection and implementation of security measures.

3
Security Rule — Physical Safeguards (45 CFR §164.310)

Physical safeguards limit physical access to information systems and the facilities housing them.

4
Security Rule — Technical Safeguards (45 CFR §164.312)

Technical safeguards are the technology and policy controls that protect ePHI and control access to it.

5
Breach Notification & Incident Response (45 CFR Part 164, Subpart D)

A breach is any impermissible use or disclosure that compromises the security or privacy of PHI. Follow this checklist for incident response.

6
Business Associate Agreements (BAA)

A Business Associate Agreement is required with any vendor or third party that creates, receives, maintains, or transmits PHI on your behalf.

📄 BAA Core Required Provisions (Template Guide)

Every HIPAA-compliant BAA must include these 7 elements (per 45 CFR §164.504(e)):

1. Permitted Uses & Disclosures — Specify exactly what the BA may do with PHI (e.g., "solely for billing services on behalf of Covered Entity")
2. Prohibited Uses — BA shall not use or further disclose PHI other than as permitted or required by this Agreement or as required by law.
3. Appropriate Safeguards — BA agrees to use appropriate safeguards and comply with Security Rule with respect to ePHI.
4. Breach Reporting — BA shall report any breach of unsecured PHI to Covered Entity within [60 days / specify timeframe] of discovery.
5. Subcontractors — BA shall ensure that any subcontractors that create, receive, maintain, or transmit PHI agree to the same restrictions.
6. Individual Rights — BA shall make PHI available to Covered Entity to respond to individual rights requests (access, amendment, accounting).
7. Termination — Upon termination, BA shall return or destroy all PHI. If infeasible, protections shall extend beyond termination.