HIPAA checklist

The HIPAA safeguards the mid-market clinic actually faces.

The Privacy Rule, the Security Rule, and the Breach Notification obligations the HHS Office for Civil Rights pulls on first — mapped to the administrative, physical, and technical safeguards the mid-market clinic actually faces. The full control walk-through, the evidence artifacts each one demands, and the package the auditor signs off on are written up in the long-form checklist.

Privacy Rule · Security Rule · Breach Notification

What “HIPAA-ready” looks like

A working HIPAA program at the Tier 1 Foundation level covers the Security Rule technical safeguards (access control, audit controls, integrity, transmission security), the administrative safeguards (workforce training, contingency planning, the BAA roster), and the Breach Notification clock — the 60-day notification window that drives most of the operational risk in the clinic.

The full checklist — control-by-control evidence list, the workforce-training cadence, and the BAA/DPA templates — is being written up against the founder’s first reviewer round. For now, the hub at /resources indexes all four framework checklists; pricing for HIPAA-only coverage starts at the $2K Foundation tier.

See pricing →

More frameworks

See all checklists →

HIPAA, SOC 2, PCI DSS, GDPR — pick by the framework your auditor opens on first.