HIPAA isn't a certificate you buy — it's a program you operate and can evidence. Here's a practical checklist of what you actually need in place to protect PHI.
Administrative safeguards
- A documented risk analysis of where PHI lives and how it could be exposed.
- A risk management process to remediate what the analysis finds.
- Workforce security training and sanction policies.
- Access management — least-privilege access to PHI, granted and revoked deliberately.
- An incident response plan and a contingency / disaster-recovery plan.
Physical safeguards
- Facility access controls for anywhere PHI is stored or processed.
- Workstation and device controls, including secure disposal of media.
Technical safeguards
- Access controls (unique user IDs, automatic logoff).
- Audit controls — logging of access to PHI.
- Integrity controls to prevent improper alteration or destruction.
- Transmission security — encryption of PHI in transit (and at rest).
Contracts & process
- A signed Business Associate Agreement (BAA) with every vendor that touches PHI.
- A breach notification process that meets HIPAA timelines.
- Documentation of policies, procedures and evidence — kept current, not written once.
HIPAA is self-attestedThere's no official HIPAA certificate. You demonstrate compliance through implemented safeguards, a documented risk analysis, BAAs and evidence — which is exactly what a continuous-compliance platform maintains for you. Keeping PHI on infrastructure you control removes an entire category of exposure.
A practical starting checklist, not legal advice. Confirm your specific HIPAA obligations with your compliance and legal teams.