HIPAA Compliance Checklist for ABA Practices

About this Resource

Use this practical checklist to review privacy, security, vendor agreements, workforce access, incident response, and website tracking.

Use this checklist to organize a compliance review across privacy, security, vendors, workforce access, incident response, and digital tools. HIPAA compliance is not a one-time form or software setting. HHS describes risk analysis as the foundational first step in Security Rule compliance and an ongoing process. 

Important: This checklist is educational and is not legal advice or a certification of compliance. HIPAA obligations depend on the organization’s role, activities, systems, contracts, and applicable state law. Obtain qualified legal or compliance review. 

 

Confirm the organization’s status 

  • Determine whether each entity is a HIPAA covered entity, business associate, subcontractor, or outside the rule for a particular activity. 
  • Document who is responsible for privacy, security, and breach-response decisions. 

Inventory PHI and ePHI 

  • Identify where PHI and ePHI are created, received, maintained, transmitted, viewed, printed, downloaded, backed up, and disposed of. 
  • Include EHR and practice-management systems, email, cloud storage, devices, phones, billing systems, forms, portals, spreadsheets, recordings, messaging tools, paper records, and vendors. 

Conduct and document risk analysis 

  • Assess risks and vulnerabilities affecting the confidentiality, integrity, and availability of ePHI. 
  • Document the methodology, systems reviewed, risks identified, existing controls, responsible owners, and remediation priorities. 
  • Repeat the analysis when systems, vendors, locations, services, or threats materially change and as part of an ongoing compliance process. 

Implement reasonable safeguards 

  • Maintain administrative, physical, and technical safeguards appropriate to the organization’s size, systems, and risk profile. 
  • Review access controls, authentication, device security, transmission security, backups, recovery, facility access, workstation use, and secure disposal. 

Apply role-based and minimum-necessary access 

  • Limit access to workforce members who need the information for their responsibilities. 
  • Review access when roles change and terminate access promptly when employment or vendor relationships end. 
  • Avoid shared accounts where unique access and accountability are required. 

Review business associates and contracts 

  • Identify vendors and subcontractors that create, receive, maintain, or transmit PHI or ePHI on the organization’s behalf. 
  • Confirm that required Business Associate Agreements are signed and address permitted uses, safeguards, reporting, subcontractors, and termination obligations. 
  • Do not assume encryption alone removes a cloud or software vendor from business-associate obligations. 

Maintain policies, training, and documentation 

  • Keep written privacy, security, access, incident, breach, retention, disposal, and contingency procedures that match actual operations. 
  • Train workforce members for their roles and document completion. 
  • Retain required compliance documentation and update it when practices change. 

Prepare for incidents and breaches 

  • Create a reporting channel for suspected incidents, lost devices, misdirected communications, unauthorized access, malware, or improper disclosures. 
  • Document investigation, risk assessment, mitigation, decisions, and notifications. 
  • Know the applicable notification process before an incident occurs. HHS requires notification after breaches of unsecured PHI and sets specific deadlines and recipients. 

Review websites, forms, analytics, and marketing 

  • Map the data collected by public pages, authenticated pages, forms, chat, call tracking, pixels, analytics, cookies, session replay, and advertising tools. 
  • Do not rely only on a privacy-policy disclosure to authorize a PHI disclosure to a tracking-technology vendor. 
  • Confirm whether vendors need BAAs and whether the data flow is permitted before deploying a tool on a page that may involve PHI. 
  • Do not publish patient testimonials, images, treatment details, or success stories without the required valid written authorization. 

Test continuity and recovery 

  • Document how the practice will continue critical operations during outages, cyber incidents, disasters, or vendor failures. 
  • Test backups and recovery instead of assuming they work. 
  • Maintain current contact information for technology, legal, compliance, insurance, and incident-response partners. 

Minimum evidence to retain 

  • Current risk analysis and remediation plan 
  • System, device, vendor, and data-flow inventories 
  • Policies and revision history 
  • Business Associate Agreements and vendor reviews 
  • Workforce training and access-review records 
  • Incident and breach documentation 
  • Contingency, backup, recovery, and test records 
  • Approvals for marketing uses of patient information 

Sources and further reading 


Have a Resource to Share?

Help the ABA community by contributing your knowledge.

Submit a Resource
Scroll to Top