HIPAA Compliance Checklist

Would your handling of patient data stand up to scrutiny?

The five areas HIPAA itself is organized around — administrative, technical and physical safeguards, privacy and patient rights, vendors and breach readiness. Plain language, scored on screen, with a branded PDF report to keep.

Start the checklist
  • 15 questions
  • About 5 minutes
  • Results on screen
  • No email required

Take the assessment

Ready to start: HIPAA Compliance Checklist

Before you start

Your level, five-dimension profile and recommendations appear on screen the moment you finish — no email, and the branded PDF report is yours to keep.

  1. 01Administrative Safeguards
  2. 02Technical Safeguards
  3. 03Physical Safeguards
  4. 04Privacy & Patient Rights
  5. 05Vendors & Breach Readiness
Scored in this browser — nothing is sent unless you choose to.

Written by DigiWagon’s delivery practiceScored with the published DigiWagon HIPAA Readiness FrameworkISO/IEC 27001 and ISO 9001 certifiedWork we’ve delivered

This checklist is an educational self-assessment built from the HIPAA Security and Privacy Rules’ published safeguards. It is not legal advice, an audit, or a certification — engage qualified counsel for compliance determinations.

Who this is for

The flow

How it works

  1. 01Answer quick multiple-choice questions about how patient data is actually handled today — options, not essays.
  2. 02Get your readiness level and a five-area profile, scored against the published rubric.
  3. 03Keep the branded PDF report — and send your results through if software that touches PHI is on your roadmap.
AdminTechnicalPhysicalPrivacyVendors
Every result is one level and five area scores — an example profile.

The framework

Five areas, scored in the open

Every answer carries zero to three points by the maturity it describes. Three questions per area give an area score out of nine; the five dimensions together map to one of four readiness levels. The rubric is published because a score you can't inspect isn't worth acting on.

0–3 per answer3 questions per dimensiondimension score out of 95 dimensionsyour result out of 45

All five dimensions weigh equally in v1 — deliberately, until real-world results earn differentiated weights. Framework v1 · September 2026.

Full methodology

The five dimensions

01

Administrative Safeguards

The management layer HIPAA checks first: a current risk analysis, named security and privacy officers, and a trained workforce.

Why this matters

Enforcement actions cite a missing or stale risk analysis more than any technical failure — the fines follow the paperwork. Administrative safeguards are also where every other control gets its authority and budget.

  1. When did your organization last complete a HIPAA risk analysis?
  2. Who is responsible for HIPAA security and privacy?
  3. How is your workforce trained on handling patient information?
02

Technical Safeguards

The controls inside your systems: who can access patient data, whether it's encrypted in transit and at rest, and whether access leaves an audit trail.

Why this matters

Technical safeguards decide the blast radius of every mistake: stolen laptops and phished passwords become reportable breaches or non-events depending on the encryption and access design underneath.

  1. How is access to patient data controlled?
  2. Is patient data encrypted?
  3. Could you tell who accessed a specific patient record, and when?
03

Physical Safeguards

The tangible layer: who can walk up to systems and records, how laptops and phones that touch patient data are managed, and how hardware and paper leave the building.

Why this matters

Breach reports are full of physical stories — the unencrypted laptop from a car, the un-wiped copier sold on. Physical safeguards are the cheapest ones to get right and the most embarrassing to explain when missed.

  1. How is physical access to systems and records controlled?
  2. How are laptops and phones that touch patient data managed?
  3. What happens to old hardware and paper records?
04

Privacy & Patient Rights

The Privacy Rule in daily practice: minimum-necessary access, an honest Notice of Privacy Practices, and what actually happens when a patient asks for their records.

Why this matters

Patient-rights failures generate complaints, and complaints are how small organizations end up under investigation — the right-of-access rules have their own enforcement program with a steady record of penalties.

  1. How does "minimum necessary" work in your organization?
  2. Where does your Notice of Privacy Practices stand?
  3. A patient asks for their records — what happens?
05

Vendors & Breach Readiness

The perimeter you don't control: Business Associate Agreements with every vendor touching PHI, a tested incident plan, and the 60-day breach-notification clock.

Why this matters

Your compliance is only as strong as the vendors holding your data — and when something goes wrong, the clock starts at discovery, not at readiness. Improvised breach response is how bad days become penalties.

  1. Do Business Associate Agreements cover the vendors that touch patient data?
  2. If patient data leaked tonight, what would happen?
  3. How prepared are you for breach-notification obligations?

What your score means

Exposed0–13 of 45

Gaps at this level aren't paperwork problems — they're the conditions breaches and penalties come from, and most carry personal stress for whoever owns the fallout. The sequence that works: risk analysis, named owner, encryption, BAAs. Weeks of focused work changes your position materially; start with the lowest area below.

Patchwork14–24 of 45

Real safeguards exist — what's missing is the system holding them together, and patchwork fails exactly where the pieces meet: the unmanaged laptop, the vendor without a BAA, the log nobody reads. Pick each area's recommendation and finish it; completion, not sophistication, is this level's work.

Structured25–35 of 45

Your program is genuinely organized — the remaining distance is between 'we have it' and 'we can prove it': reviews on calendars, plans actually tested, documentation that would satisfy an auditor on a bad day. If you're building software that touches PHI, this is a strong position to build from.

Audit-Ready36–45 of 45

This posture would stand up to scrutiny, and it compounds: partners sign faster, enterprise deals clear security review, and new products inherit controls instead of retrofitting them. The work now is keeping it true through change — every new vendor, system and hire arrives inside the discipline.

FAQ

About this checklist

Short answers to what people ask before they take it — including what a self-assessment can and cannot tell you.

01What is a HIPAA compliance checklist?

A HIPAA compliance checklist is a structured way to assess how an organization handles protected health information against the safeguards the law requires — administrative, technical and physical controls, privacy practices, and vendor management. It turns a dense regulation into concrete questions you can answer, showing which obligations are covered and which need work.

02Who should use this checklist?

Anyone responsible for an organization that creates, stores or transmits protected health information: healthcare providers, digital health startups, and the operations or product leaders building software that touches patient data. The questions are written in plain language — you need working knowledge of your organization, not a compliance background.

03Is this checklist legal advice or a certification?

No. This is an educational self-assessment built from the HIPAA Security and Privacy Rules' published safeguards. It shows where your posture likely stands and what typically closes each gap, but it is not legal advice, an audit, or any form of certification — engage qualified counsel for compliance determinations.

04What does the checklist cover?

Five areas mirroring how HIPAA itself is organized: administrative safeguards like risk analysis and training, technical safeguards like access control and encryption, physical safeguards for facilities and devices, privacy practices and patient rights, and vendor management with breach readiness. Three questions each show exactly where attention is needed first.

05Do I need to share my email address to see the results?

No. Your score, the five-area breakdown and every recommendation appear on screen the moment you finish, and the branded PDF report generates locally in your browser. Contact details only come into it if you choose to send your results to our team for a build-readiness conversation.

06What should we do after a low score?

Start with whichever area scored lowest — its recommendation names the first concrete step, and the highest-risk gaps are usually a current risk analysis, encryption coverage and Business Associate Agreements. If you're building or commissioning software that touches patient data, send your results through and we'll walk the technical gaps with you.

Building software that touches patient data?

Send your results through and we'll walk the technical gaps with you — access design, encryption, audit trails and the architecture choices that make compliance a property of the system rather than a promise. A working conversation, not a pitch.

Ask an AI about this page

Before you choose a partner, ask your own AI

One click opens the assistant you already use with a question that points it at this page, so the answer comes from what we publish, not a guess.

The question it opens withRead https://digiwagon.com/tools/hipaa-compliance-checklist and tell me what "HIPAA Compliance Checklist" helps me decide, what inputs I should gather before using it, and how DigiWagon suggests acting on the result. Stick to what the page says and mark anything you are not sure about.