Where to Start
HIPAA exists with a singular goal: to protect health information from improper use and disclosure. Two rules underpin the majority of it, the Privacy Rule (how you may use and share that information) and the Security Rule (how you protect electronic PHI, “ePHI”).
The law was intentionally written using terms like reasonable and appropriate such that organizations of various sizes and resources can implement standards that make sense for them. A small practice and a large hospital are held to the same rules but not the same complexity.
What you'll find below is what we believe to be the shortest sensible path to a strong HIPAA compliance posture. A dozen steps prioritized by ease to implement, risk of ignoring it, and impact to the security of ePHI. Each explains what it is, why it matters, where to turn it on, and free templates to record it. We recommend working through them from the top to the bottom. Each recommendation unlocks the next.
- 1
Assign Responsibility
One-timeName a Security Official and a Privacy Official (one person can hold both, a contractor or FTE).
HIPAA requires a named, in-writing owner for the same reason each ship has a captain.
Anywhere: Record it anywhere, but here's a one-page charter naming the person and the date.
Prove it: Security & Privacy Program Charter
- 2
Perform a Right-sized Risk Analysis
AnnualA meaningful look at where ePHI lives, how it's used and secured.
This is a foundational Security Rule annual requirement and one of the top indicators of breach penalty because we can't protect something unless we know how it's at risk.
Where: Every system, device, and vendor that touches ePHI.
How To HIPAA: Take our free self-assessment to start your annual risk analysis. The output contains a prioritized gap list to start your risk register where you'll track risk.open →
Prove it: Your Assessment · Risk Register
- 3
Sign BAAs with every vendor that touches ePHI
One-timeA Business Associate Agreement is a signed contract you'll need with every vendor that handles patient information. Using Slack to discuss patient outcomes? Using Google Drive to store patient health information? You need a BAA with them.
It's legally required, and without one a vendor's breach becomes your violation.
Where: Email, cloud storage, your EHR, billing, IT/MSP, transcription, and more.
Anywhere: List every vendor that is exposed to ePHI and make sure you have an executed BAA with them. When unsure whether a vendor needs one, it's usually safer to ask for it.
Prove it: Business Associate Agreement
- 4
Turn on multi-factor authentication (MFA) everywhere
One-time + regular confirmationA second check beyond the password, usually a tap or code on a phone.
Stolen or guessed passwords are the leading cause of health-data breaches, and MFA stops nearly all of them. It's the highest-impact hour you'll spend.
Where: Each platform in use within your organization. Start with email and your EHR, then communication, cloud storage, product, HRIS, & marketing platforms.
Google Workspace: Admin console → Security → Authentication → 2-Step Verification → enforce for everyone.docs
Microsoft 365: Entra admin → enable security defaults, or Conditional Access to require MFA.docs
Your EHR: Ask your vendor to turn it on for all users.
Shortcut: If you use single sign-on (Okta, Entra, Google), enforce MFA there and it covers every connected downstream app.
Prove it: Platform Configuration Snapshot (Log or Screenshot) · Regular Review Log
- 5
Encrypt Devices and Data
One-timeScramble stored data so a lost laptop or phone isn't a reportable breach.
Encryption is HIPAA's closest thing to a safe harbor as properly encrypted data that's lost or stolen generally isn't a breach you have to report.
Where: Laptops, phones, backups, and data in transit (email, patient portal).
Mac: System Settings → Privacy & Security → FileVault → On.docs
Windows: Turn on BitLocker (Device encryption) in Settings.docs
Phones: On by default once a passcode/biometric is set. Require one.
Shortcut: If you manage devices with an MDM (Mosyle, Intune, Jamf, Kandji), enforce encryption fleet-wide and export the compliance report whenever evidence is required.
Prove it: Asset & ePHI Inventory
- 6
Remove any shared logins and equip staff with only the access they need
AnnualFor OCR, account sharing is a clear sign of negligence. If staff share logins, how can an organization prove who viewed ePHI? Provision staff account access based on their role such that they can reach only the systems and data required to perform their job. This is referred to as “role-based access control” (RBAC) and meets the “minimum necessary” rule.
Shared logins and default access permissions are two of the most common audit findings, and they make a breach both likelier and harder to trace.
Where: Every system that touches ePHI.
Everywhere: Remove shared/generic accounts. Assign staff the lowest-privilege role that still lets them work. Use a ticketing platform or brief justification document for exceptions.
SSO (Okta, Entra, Google): If you have a single sign-on platform like Okta or Google, you can manage roles and access in one place instead of system by system.docs
Shortcut: Plan it once on paper first: the Role / Permission Matrix maps each role to each system and level. Grant access deliberately rather than by habit.
Prove it: Role / Permission Matrix · Access Request & Review Log
- 7
Onboarding & Offboarding Process
OngoingPerform background checks for all new employees (and contractors!) and disable a departing worker's accounts the same day and record it (a checklist is fine).
Lingering former-employee access is a classic breach and a top audit finding. Timely termination is specifically called out in the rules.
SSO or each system: Disable the identity centrally (SSO) or in each system; collect devices and rotate any shared credentials.
How To HIPAA: The Onboarding / Offboarding Tracker turns this into a per-person checklist so nothing is missed and it flags if access was cut late.
Prove it: Onboarding / Offboarding Tracker
- 8
Train your workforce
OngoingProvide IT security and HIPAA compliance training for everyone who touches PHI, when they start and at least yearly. Best practice for early- and mid-stage companies is to provide this for all staff.
Staff are the most common pathway for information leaks. Training and awareness is the first step towards ensuring a vigilant workforce.
Training options: HHS.gov offers a free training. Easyllama offers a HIPAA module (and Fraud, Waste, and Abuse for those handling insurance or codes). Assign it, then track who completed it and when. HowToHIPAA provides custom, live training through our Guided and Managed program tiers.
Prove it: Training Roster & Completion Log
- 9
Data & Service Redundancy
One-timeYou'll need reliable, encrypted backups of ePHI, plus one real test that you can actually restore from them.
Ransomware and unintentional deletion can interrupt patient care and backups require a restore test to ensure they're completing as intended.
Where: Patient data stores. Google Drive, your EHR, local hard drives, and production platform databases are the most common.
Prove it: Data Backup Plan · Contingency Plan Test Record
- 10
Logging & Monitoring
OngoingThe expectation is that your systems record who accessed what, and you review those records on a set cadence.
Logs are how you catch snooping or misuse and how you answer “who saw this record?” after the fact.
EHR + cloud: Enable audit logging where it isn't already, and set a recurring time (e.g. monthly) to review access reports.
Shortcut: Your EHR, Google Workspace, and Microsoft 365 already keep access logs you can export. Set up a twice-yearly calendar reminder to review them, or use Datadog to consolidate and flag them.
Prove it: Audit Controls policy
- 11
Understand How ePHI Flows Through Your Platform
One-timeKnow where ePHI lives and how it moves (an inventory + a data-flow map).
Much like the risk assessment, we need to understand how data is created or ingested by the organization to how it's processed and stored to how it's deleted. The process informs the Privacy Policy and is a valuable asset in decision making and privacy impact assessments.
How To HIPAA: Use our Asset Inventory and Data Flow List & Map features, and adopt the incident-response runbook. Or create your own list and map it in Figma.
Shortcut: You may not need to fill these by hand: an MDM exports your device list, and your EHR and cloud consoles list your systems: a great place to start.
Prove it: Asset & ePHI Inventory · Data Flow Map · Incident Response Runbook
- 12
Covered entities: Publish and Honor Patient Rights
One-timeCovered entitiesA Notice of Privacy Practices (NPP), plus a way to handle patients' requests to see, amend, or get an accounting of their records.
These are Privacy-Rule duties unique to covered entities: patients have enforceable rights and there are deadlines.
Where: Post the NPP (front desk + website), and set a simple intake + log for access, amendment, and accounting requests.
Prove it: Notice of Privacy Practices · Accounting of Disclosures Log · Amendment Request Form & Log
- 13
Business Associates: Extend Your Requirements to Downstream Vendors & Associates
One-timeBusiness associatesEven BAs need BAAs with any subcontractor and vendor that touches ePHI, and a process to report incidents up to the covered entities you serve.
Business associates carry the Security Rule directly and their obligations flow down to subcontractors and subvendors. Each must notify your customers of a breach on a deadline.
Where: Inventory your subcontractors, sign flow-down BAAs, and define who reports a breach to which customer, and how fast.
Prove it: Subcontractor Business Associate Agreement · Subcontractor Management Policy · Breach Reporting to the Covered Entity
Not sure where you stand on these? Our free self-assessment turns this list into your own prioritized plan.
Check your readiness