Free printable template · PDF
HIPAA Compliance Checklist
A checklist of the main HIPAA Privacy, Security and Breach Notification Rule requirements for a small practice, with space for the date each was done, who owns it and where the evidence is. Start by checking whether HIPAA applies to you.
Free, no email needed. Guidance reviewed .
HIPAA Compliance Checklist
MedSpaBinder
Clinic
Privacy / security official
Review date
HIPAA covers providers who bill health plans electronically. Many cash-only med spas aren't covered: check first.
Reviewed by: ______________________ Date: ____________ Next review: ____________
Does HIPAA apply to a med spa?
HIPAA's rules apply to covered entities, and a health care provider is covered only if it transmits health information electronically in connection with a standard transaction, such as billing a health plan. Many cash-only med spas don't, and so aren't HIPAA covered entities.
That doesn't mean patient information is unprotected. State privacy and medical records laws still apply, and patients expect HIPAA-level care. Many uncovered clinics follow this checklist anyway. Check your status with HHS's guidance or an attorney.
What the checklist covers
- Privacy Rule: a privacy official, a notice of privacy practices, policies, patient access, complaints, training and sanctions.
- Security Rule: a security official, a written risk analysis and plan, access controls, device safeguards, backups and business associate agreements with vendors that handle patient information.
- Breach Notification Rule: a plan for notifying patients, HHS and, for large breaches, the media, within the deadlines the rule sets.
- Documentation: HIPAA policies and required records are kept for 6 years.
How to use it
- Work through it once, recording where the evidence for each item is kept.
- Redo the risk analysis when something changes, such as a new EHR, new devices or a new location.
- Review the whole list at least yearly and after any incident.
Questions
What's the most commonly missed HIPAA requirement?
The security risk analysis. It's a written assessment of where patient information is, what could go wrong, and what you're doing about it. HHS offers a free security risk assessment tool for small practices.
Do I need business associate agreements?
If you're a covered entity, yes, with any vendor that creates, receives, keeps or transmits patient information for you, such as your EHR, booking system or billing service.
Sources
General guidance, not legal or medical advice. Requirements vary by state; follow your medical director and product labels.