Free printable template · PDF

HIPAA Compliance Checklist

A checklist of the main HIPAA Privacy, Security and Breach Notification Rule requirements for a small practice, with space for the date each was done, who owns it and where the evidence is. Start by checking whether HIPAA applies to you.

Free, no email needed. Guidance reviewed .

HIPAA Compliance Checklist

MedSpaBinder

Clinic

Privacy / security official

Review date

HIPAA covers providers who bill health plans electronically. Many cash-only med spas aren't covered: check first.

Requirement
Done (Y / N)
Date
Owner
Evidence / where kept
Does HIPAA apply?
Checked whether we're a covered entity (e.g. bill insurance)
Privacy Rule
Privacy official named
Notice of privacy practices given and posted
Policies for use and disclosure of patient info
Patient access requests answered within 30 days
Privacy complaint process in place and logged
Staff trained on privacy (with dates)
Sanctions policy for staff who break the rules
Security Rule
Security official named
Security risk analysis done and updated
Risk management plan for what it found
Unique logins; access removed when staff leave
Devices encrypted or safeguarded; screens locked
Backups and a plan for outages
Business associate agreements with vendors
Breaches and records
Breach response plan, including notification
Policies and records kept 6 years
Reviewed by (initials)

Reviewed by: ______________________ Date: ____________ Next review: ____________

Does HIPAA apply to a med spa?

HIPAA's rules apply to covered entities, and a health care provider is covered only if it transmits health information electronically in connection with a standard transaction, such as billing a health plan. Many cash-only med spas don't, and so aren't HIPAA covered entities.

That doesn't mean patient information is unprotected. State privacy and medical records laws still apply, and patients expect HIPAA-level care. Many uncovered clinics follow this checklist anyway. Check your status with HHS's guidance or an attorney.

What the checklist covers

  • Privacy Rule: a privacy official, a notice of privacy practices, policies, patient access, complaints, training and sanctions.
  • Security Rule: a security official, a written risk analysis and plan, access controls, device safeguards, backups and business associate agreements with vendors that handle patient information.
  • Breach Notification Rule: a plan for notifying patients, HHS and, for large breaches, the media, within the deadlines the rule sets.
  • Documentation: HIPAA policies and required records are kept for 6 years.

How to use it

  • Work through it once, recording where the evidence for each item is kept.
  • Redo the risk analysis when something changes, such as a new EHR, new devices or a new location.
  • Review the whole list at least yearly and after any incident.

Questions

What's the most commonly missed HIPAA requirement?

The security risk analysis. It's a written assessment of where patient information is, what could go wrong, and what you're doing about it. HHS offers a free security risk assessment tool for small practices.

Do I need business associate agreements?

If you're a covered entity, yes, with any vendor that creates, receives, keeps or transmits patient information for you, such as your EHR, booking system or billing service.

Sources

General guidance, not legal or medical advice. Requirements vary by state; follow your medical director and product labels.