Additional Resources

Complete HIPAA Audit Checklist for Healthcare Organizations

A HIPAA audit can arrive with little warning—triggered by a patient complaint, a reported breach, or simply random selection by the Office for Civil Rights (OCR). When it does, auditors expect to see documented policies, completed risk assessments, and evidence that your organization actually follows the rules it claims to follow.

This checklist walks through every major HIPAA requirement, from Privacy and Security Rule safeguards to breach notification procedures and business associate management, so you can identify gaps before an auditor does.

What is a HIPAA Audit Checklist

A HIPAA audit checklist is a structured document that helps healthcare organizations verify compliance with the Health Insurance Portability and Accountability Act (HIPAA). The checklist evaluates privacy, security, and breach notification requirements by reviewing policies, testing technical safeguards, and confirming that Protected Health Information (PHI) stays secure. Organizations typically conduct internal audits annually, though the Office for Civil Rights (OCR) can audit at any time following a breach, complaint, or random selection.

The checklist covers three core areas:

  • Administrative safeguards: Policies, procedures, and workforce training
  • Physical safeguards: Facility access controls and workstation security
  • Technical safeguards: Encryption, access controls, and audit logs

Think of the checklist as a roadmap for identifying gaps before an auditor does. It's far easier to fix problems on your own timeline than under OCR scrutiny.

Prepare for Your HIPAA Audit

Get a practical starting point for audit preparation. Download Drata’s HIPAA Audit Checklist to review key steps and keep your preparation on track.


Who Needs a HIPAA Audit Checklist

Two categories of organizations fall under HIPAA requirements, and both face audit scrutiny. HIPAA requirements, and both face audit scrutiny.

Covered Entities

Covered entities include healthcare providers, health plans, and healthcare clearinghouses that transmit health information electronically. Hospitals, clinics, pharmacies, dentists, and insurance companies all fall into this category.

Business Associates

Business associates are third-party vendors that handle PHI on behalf of covered entities. IT service providers, billing companies, cloud storage vendors, and electronic health record (EHR) system providers all qualify. If your organization creates, receives, maintains, or transmits PHI as a covered entity or business associate, HIPAA applies to your organization and you need to be HIPAA compliant.

$7.42M

Healthcare remains the costliest industry for data breaches for the 14th consecutive year at $7.42M per incident.

IBM Cost of a Data Breach Report 2025


HIPAA Privacy Rule Audit Checklist

The Privacy Rule governs how organizations use and disclose PHI. Here's what auditors review most frequently.

Designate a HIPAA Privacy Officer

Every covered entity appoints someone responsible for developing and implementing privacy policies. In smaller organizations, this person often wears multiple hats, but the role itself is non-negotiable.

Identify All Protected Health Information

Your team maps where PHI exists across the organization: paper records, electronic systems, emails, and third-party platforms. You can't protect what you haven't identified.

Establish Permissible Uses and Disclosures

HIPAA distinguishes between required disclosures (to patients and the Department of Health and Human Services), permissible disclosures (treatment, payment, operations), and disclosures requiring written authorization. Document which category applies to each type of disclosure your organization makes.

Create Patient Authorization Procedures

Certain disclosures require written patient consent. A valid HIPAA authorization includes specific elements: a description of the information, who will receive it, the purpose, and an expiration date.

Publish Notices of Privacy Practices

Patients receive clear documentation explaining how their PHI will be used, shared, and protected. This notice goes out at the first point of service.

Implement Patient Rights Request Procedures

Patients have the right to access, amend, and restrict their PHI. Your procedures outline how to handle requests within HIPAA's required timeframes.

Maintain an Accounting of Disclosures

Organizations track when and to whom PHI was disclosed. Patients can request this accounting, so accurate record-keeping matters.

Conduct Workforce Privacy Training

All employees receive documented HIPAA training. Workforce training is a frequent focus area in OCR investigations and audit activity.. Training happens at onboarding and annually thereafter.

HIPAA Security Rule Audit Checklist

The Security Rule specifically protects electronic PHI (ePHI) through required safeguards—critical given the 264% increase in ransomware breaches since 2018. This is where most audit findings occur.

Designate a HIPAA Security Officer

This role implements and maintains security policies. In smaller organizations, the same person often serves as both Privacy and Security Officer.

Conduct a Security Risk Assessment

This is the single most critical audit requirement. Organizations perform comprehensive annual risk assessments to identify vulnerabilities in ePHI systems. Failing to conduct one, or conducting an incomplete one, is the most frequently cited violation in OCR enforcement.

Implement Administrative Safeguards

Administrative safeguards include workforce security (background checks and access authorization), information access management (role-based access limiting PHI to job necessity), security awareness training, and contingency planning for data backup and disaster recovery.

Implement Physical Safeguards

Physical safeguards protect the facilities and equipment housing ePHI. Facility access controls include secure entry points, visitor logs, and badge access. Workstation security covers screen positioning, automatic logoff, and secured devices. Device and media controls address proper disposal and sanitization of hardware containing ePHI.

Establish Security Incident Procedures

Documented procedures help you identify, respond to, and report security incidentsDocumented procedures help you identify, respond to, and report security incidents. The faster you detect and contain an incident, the better your audit position.

Develop Contingency and Disaster Recovery Plans

Your plans include data backup procedures, disaster recovery protocols, and emergency mode operations to maintain ePHI access during crises.

HIPAA Technical Safeguards Checklist

Technical safeguards are the technology and policies protecting ePHI access.

Access Controls

Control Type

Requirement

Unique user identification

Each user has unique login credentials

Emergency access procedures

Methods to access ePHI during emergencies

Automatic logoff

Sessions terminate after inactivity

Encryption

Data encrypted at rest and in transit (AES-256, TLS 1.2+)

Audit Controls

Systems record and examine activity in systems containing ePHI. Audit logs track who accessed PHI, when, and for what purpose.

Integrity and Transmission Security

Integrity controls ensure ePHI isn't improperly altered or destroyed. Transmission security covers encryption requirements for ePHI sent over networks, including emails, file transfers, and remote access.

Authentication Requirements

Multi-factor authentication (MFA) is strongly recommended for remote access and privileged or administrative functions, and many organizations now treat it as a baseline safeguard. 

HIPAA Audit Log Retention Requirements

How long you keep records is a common compliance gap.

HIPAA requires certain compliance documentation to be retained for six years from the date of creation or the date when it last was in effect, whichever is later. Organizations should also establish log-retention practices that support security monitoring, investigations, and audit readiness.

Collecting logs isn't enough on its own. You review them regularly to detect unauthorized access. Daily or weekly reviews help you spot suspicious patterns before they become breaches.

HIPAA Breach Notification Rule Checklist

When unsecured PHI is breached, notification requirements kick in.

A breach is the unauthorized acquisition, access, use, or disclosure of PHI that compromises its security or privacy. When one occurs, you conduct a risk assessment to determine if notification is required, then notify affected individuals within 60 days. risk assessment to determine if notification is required, then notify affected individuals within 60 days.

Breaches affecting 500 or more individuals require notification to HHS and, in some cases, local media. Document all breach response activities because auditors will ask for this evidence.

Business Associate HIPAA Compliance Checklist

Managing third-party riskManaging third-party risk is a top OCR audit focus area.

Execute Business Associate Agreements

Business Associate Agreements (BAAs) are legally required contracts establishing how business associates protect PHI. Every vendor touching PHI signs one before receiving access.

Verify and Monitor Business Associate Security

Signed BAAs aren't enough. You verify vendors actually implement appropriate safeguards through due diligence questionnaires and periodic reassessments. Maintain an updated vendor inventory and review it annually.

How to Prepare for a HIPAA Compliance Audit

When facing an OCR audit, whether triggered by a complaint, breach, or random selection, preparation makes the difference.

1. Gather All Required Documentation

Compile your policies, procedures, risk assessments, training records, BAAs, and incident reports into a HIPAA compliance binder.

2. Review Policies and Procedures

Verify all policies are current, comprehensive, and actually implemented, not just documented on a shelf.

3. Conduct a Pre-Audit Self-Assessment

Use your HIPAA audit checklistConduct a HIPAA readiness assessment to identify gaps before auditors arrive. Fix what you can and document remediation efforts for what you can't.

4. Prepare Staff for Auditor Interviews

Auditors interview staff to verify policies are understood and followed. Training documentation proves your team knows the rules.

How Drata Automates HIPAA Compliance Audits

Manual compliance is slow, error-prone, and resource-intensive. Continuous compliance monitoring replaces point-in-time audits with real-time visibility into your security posture.

Drata automates evidence collection, continuously tests controls, and centralizes policy management. When auditors arrive, your documentation is already organized and current.

FAQs about HIPAA Audit Checklists

Many organizations perform comprehensive internal HIPAA reviews annually, with ongoing monitoring throughout the year to maintain continuous compliance, and identify any gaps or issues as they occur.

A risk assessment identifies potential vulnerabilities and threats to PHI. A HIPAA audit evaluates whether your organization has implemented required safeguards and follows documented policies.

HIPAA violations can lead to corrective action plans, resolution agreements, and significant civil monetary penalties, depending on the severity of the issue, the number of records involved, and whether willful neglect was found.


August 24, 2026
HIPAA Collection

Navigate HIPAA with Confidence

Navigate to new worlds of trust with Drata.