Mitti by SafetyCulture
Pricing
Log inSign up for free
  1. Home
  2. Checklist guides
  3. Compliance
  1. Home
  2. Checklist guides
  3. Compliance
Mitti by SafetyCulture

The way the world works

Follow us

App Store
Google Play

Product

  • Pricing
  • Book a demo
  • Product updates
  • Mitti (by SafetyCulture)

Support

  • Help center
  • Contact us
  • API developer documentation
  • Digitize your checklist

Resources

  • Content library
  • App & software guides
  • Checklist guides
  • Topic guides
  • eBooks
  • Blog

Company

  • About
  • Careers
  • News room
  • Meet the leadership team
  • Events & webinars
Copyright © 2026 Mitti
StatusLegalPrivacyTerms & ConditionsSecurity

SafetyCulture has a new name. Say hello to Mitti. Learn More.

Powered by

HIPAA Compliance Checklist

Conduct HIPAA risk assessments and compliance checks to address security risks using HIPAA compliance checklists.

Rated 4.6/5 stars on Capterra | 3k+ app store reviews
Use templatePreview template
HIPAA Compliance Checklist
Mobile Preview
See the template in action (opens in new tab)

Download and use this free HIPAA compliance checklist to determine how compliant your institution is with HIPAA provisions. Information security officers can use this as a guide to do the following:

  1. Check the administrative safeguards currently in place, physical safeguards being implemented, and technical safeguards being used.

  2. Add relevant notes and upload file attachments to provide further context on the audit or assessment being conducted.

  3. Include any comments or recommendations before signing off with a digital signature.

  4. Export it into a HIPAA compliance checklist PDF, CSV, XLS, or Word report for recordkeeping and store it securely on the cloud.

HIPAA Compliance Checklist
Mobile Preview
See the template in action (opens in new tab)

Why Mitti digital checklists?

  • Free to use for up to 10 users

  • Eliminate paperwork with digital checklists

  • Generate reports from completed checklists

Use template
  • What is a HIPAA Compliance Checklist?
  • Biggest Causes of HIPAA Breach
  • Why Use a Checklist For HIPAA Compliance
  • What to Include in a HIPAA Compliance Checklist
  • 5 Steps to be HIPAA Compliant
  • How to Stay HIPAA-Compliant with the Help of Checklists
  • HIPAA Compliance Checklist PDF
  • FAQs About HIPAA Compliance Checklist

In this article

  • What is a HIPAA Compliance Checklist?
  • Biggest Causes of HIPAA Breach
  • Why Use a Checklist For HIPAA Compliance
  • What to Include in a HIPAA Compliance Checklist
  • 5 Steps to be HIPAA Compliant
  • How to Stay HIPAA-Compliant with the Help of Checklists
  • HIPAA Compliance Checklist PDF
  • FAQs About HIPAA Compliance Checklist

Eliminate paperwork with digital checklists

Skip the setup and get to work in seconds.

Use template

Article by

Mitti (by SafetyCulture) Content Team

|

6 min read

|

26 Jun 2025

What is a HIPAA Compliance Checklist?

A HIPAA compliance checklist is a tool that helps organizations stay compliant with the Health Insurance Portability and Accountability Act or HIPAA. This document is typically used by institutions and their associates who handle Protected Health Information (PHI). HIPAA is a US law that requires the careful handling of PHI or individually identifiable health information. Violation of HIPAA can lead to costly fines and legal action.

Biggest Causes of HIPAA Breach

HIPAA breaches can happen due to several reasons, including the following:

  • Unintentional error – This refers to instances wherein medical practitioners disclose medical conditions and sensitive patient information to the wrong person. It also covers situations where unsecured medical documents can be easily accessed by unauthorized people.

  • Cyberattacks – Cases of hacking, ransomware, or malware can compromise information security and expose massive sensitive data containing individually identifiable health information leading to millions of dollars in settlement.

  • Lost/stolen device – Lost or stolen laptops, USBs, or handheld devices can lead to unauthorized access to electronic PHI (ePHI). Devices with proper encryption of PHI can help avoid HIPAA breaches.

  • Unauthorized disclosure/access – exposing PHI to inappropriate avenues or not correcting unauthorized access can be costly if not addressed appropriately.

Why Use a Checklist For HIPAA Compliance

It’s important to note that vulnerabilities and new threats to the security of PHI need to be addressed to stay HIPAA compliant. This is why using a HIPAA compliance checklist is highly recommended.

Apart from that, the following are some of the benefits organizations can achieve from using one:

  • Ensuring in-depth and streamlined coverage – Since HIPAA regulations are complex, a checklist can help provide a structured approach to ensure comprehensive coverage of all relevant requirements.

  • Identifying potential gaps – A checklist helps identify any gaps in compliance that may exist in an organization’s policies, procedures, and practices to address them toward full compliance.

  • Providing a standardized approach – It provides a standardized format for HIPAA compliance that can be used consistently across an organization.

  • Facilitating audits and assessments – Also, HIPAA compliance checklists can help provide a clear record of an organization’s compliance activities to demonstrate to auditors that the necessary PHI protection safeguards are in place.

What to Include in a HIPAA Compliance Checklist

To help make your HIPAA compliance template comprehensive, ensure that it includes elements such as a title page and sections for administrative, physical, and technical safeguards. Here are example questions to ask using the checklist:

Questions

Compliant

Non-Compliant

Not Applicable

Administrative

Has a Risk Analysis been completed IAW NIST Guidelines?

Has the Risk Management process been completed IAW NIST Guidelines?

Do you have formal sanctions against employees who fail to comply with security policies and procedures?

Have you implemented procedures to regularly review records of IS activity such as audit logs, access reports, and security incident tracking?

Identify the security official who is responsible for the development and implementation of the policies and procedures required by this subpart for the entity.

Physical

Have you established (and implemented as needed) procedures that allow facility access in support of restoration of lost data under the disaster recovery plan and emergency mode  operations plan in the event of an emergency?

Have you implemented policies and procedures to safeguard the facility and the equipment therein from unauthorized physical access, tampering, and theft?

Have you implemented procedures to control and validate a person’s access to facilities based on their role or function?

Including visitor control, and control of access to software programs for testing and revision?

Have you implemented physical safeguards for all workstations that access EPHI to restrict access to authorized users?

Technical

Have you assigned a unique name and/or number for identifying and tracking user identity?

Have you established (and implemented as needed) procedures for obtaining necessary EPHI during an emergency?

Have you implemented procedures that terminate an electronic session after a predetermined time of inactivity?

Have you implemented a mechanism to encrypt and decrypt EPHI?

Have you implemented Audit Controls, hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use EPHI?

5 Steps to be HIPAA Compliant

Follow these simple steps below to ensure HIPAA compliance:

  1. Identify and assess potential risks and vulnerabilities to PHI and evaluate the likelihood and impact of a breach.

  2. Develop and implement policies and procedures that address the identified risks and vulnerabilities.

  3. Train all employees who have access to PHI on HIPAA regulations, the organization’s policies and procedures, and the importance of protecting PHI.

  4. Implement technical safeguards to secure PHI, such as encryption, access controls, and backups, and physical safeguards such as secure storage and disposal of records.

  5. Regularly review and update policies, procedures, and security measures to ensure they remain effective and compliant with HIPAA regulations.

How to Stay HIPAA-Compliant with the Help of Checklists

Avoid HIPAA violations with these straightforward tips:

Start with Human Resources (HR).

Recruit the right staff, conduct background checks, and provide the proper training on handling patient information. Keep your staff updated about new risks to information security.

Evaluate the compliance of staff and partners.

Check the practices of staff and vendors handling PHI. Reinforce HIPAA-compliant practices by conducting audits (per HIPAA) and observing staff while on the job. Ask vendors for evidence of HIPAA compliance.

Set up access controls.

Establish physical safeguards for access to information and implement encryption of PHI to mitigate the risk of an information breach. Also, make sure that your IT team is always updated about threats and that the systems in place are prepared for cyberattacks.

Conduct security risk assessments.

Institutions and their staff are constantly exposed to new threats to information security. Hence, conducting regular security risk assessments can help identify and immediately mitigate new and evolving risks to prevent costly HIPAA breaches from taking place.

HIPAA Compliance Checklist PDF

Here’s a look of a completed HIPAA compliance report in the format of a PDF:

HIPAA Compliance Checklist Sample Report

HIPAA Compliance Checklist Sample PDF Report | Mitti (by SafetyCulture)

Content library templates

Still looking for a checklist?

Search, filter, and customize 60,000+ templates across industries and use cases.

Browse Library

FAQs About HIPAA Compliance Checklist

MT

Article by

Mitti (by SafetyCulture) Content Team

Mitti (by SafetyCulture) Content Contributor

View author profile

Related resources you might like

Templates

Powered by

HIPAA Risk Assessment Template

Use this HIPAA risk assessment checklist to determine the threats and vulnerabilities in your institution that can put PHI at risk. Privacy compliance officers can use this as a guide to:

  1. Observe the current practices among staff and record how PHI is being handled;

  2. Take photo evidence of non-compliance;

  3. Assign actions for immediate resolution of urgent information security risks found; and

  4. Generate reports of assessments on the spot.

View template in library

Powered by

HIPAA Privacy Risk Analysis

Use this template to check how PHI and other sensitive information is generally handled in your institution. Use this for conducting regular internal audits to reinforce best practices, call out gaps, and watch out for trends of risks that may need to be prioritized.

View template in library

Articles

REACH Compliance Software

Explore 7 of the best REACH compliance software to enhance regulatory adherence and chemical management for businesses.

Learn more

A Comprehensive Guide to Creating a Risk Treatment Plan

Learn how to write a risk treatment plan, align it with ISO 27001 and 31000, and monitor it over time with practical steps and examples.

Learn more

ISO 17025 Checklist

Use this free ISO 17025 checklist template to help your lab meet accreditation requirements and digitize preparations for certification.

Learn more