Guide · HIPAA

HIPAA compliance checklist

HIPAA isn't a certificate you buy — it's a program you operate and can evidence. Here's a practical checklist of what you actually need in place to protect PHI.

Administrative safeguards

  • A documented risk analysis of where PHI lives and how it could be exposed.
  • A risk management process to remediate what the analysis finds.
  • Workforce security training and sanction policies.
  • Access management — least-privilege access to PHI, granted and revoked deliberately.
  • An incident response plan and a contingency / disaster-recovery plan.

Physical safeguards

  • Facility access controls for anywhere PHI is stored or processed.
  • Workstation and device controls, including secure disposal of media.

Technical safeguards

  • Access controls (unique user IDs, automatic logoff).
  • Audit controls — logging of access to PHI.
  • Integrity controls to prevent improper alteration or destruction.
  • Transmission security — encryption of PHI in transit (and at rest).

Contracts & process

  • A signed Business Associate Agreement (BAA) with every vendor that touches PHI.
  • A breach notification process that meets HIPAA timelines.
  • Documentation of policies, procedures and evidence — kept current, not written once.
HIPAA is self-attestedThere's no official HIPAA certificate. You demonstrate compliance through implemented safeguards, a documented risk analysis, BAAs and evidence — which is exactly what a continuous-compliance platform maintains for you. Keeping PHI on infrastructure you control removes an entire category of exposure.

A practical starting checklist, not legal advice. Confirm your specific HIPAA obligations with your compliance and legal teams.

See Vallorix on your own infrastructure

Continuous evidence, auditor-ready reports, and controls that stay in your boundary.

Get a demo →
V
Vallorix AssistantAI · answers about compliance & the product
AI assistant · not a human · answers may be imperfect