Knowledge base

HIPAA: Documentation and Compliance Requirements

This document explains what HIPAA requires, section by section, and what an auditor may ask you to show as evidence.

Prem Kumar Dvivedi · 12 septembre 2026

It covers 63 requirements across 7 major areas.

This is not just a checklist. A checklist asks, “Do you have this?” This document explains what you need to have and what evidence can prove that you are actually following it.

If you first want to understand your current level of compliance, you can use a HIPAA readiness assessment to identify gaps and measure your readiness.

________________________________________

1. Know Your Organisation and Where Your Data Is
Clauses: §160.103, §164.105, §164.308

Know what type of organisation you are

You must clearly identify whether your organisation is:

• A Covered Entity

• A Business Associate

• A Subcontractor of a Business Associate

Evidence an auditor may ask for:

• Written classification

• Reason for the classification

• Explanation of the healthcare activities you perform

Identify hybrid entities

If only certain parts of your organisation perform healthcare-related activities, you may need to formally identify yourself as a hybrid entity.

Evidence:

• Written hybrid-entity designation

• List of healthcare components

• If not applicable, documented justification

Know where all protected health information (PHI) is stored

You should know where all your PHI exists, including:

• Applications and databases

• Servers and cloud systems

• Laptops and mobile phones

• USB/removable devices

• Backups

• Email and fax

• Medical devices

• Paper records

• Home and remote-working locations

• Third-party systems

Evidence:

• PHI/data inventory

• Data-flow diagrams

• List of systems, devices and third parties handling PHI

A complete inventory is important because most other HIPAA controls depend on knowing where your information is.

________________________________________

2. Privacy Rule — How Health Information Is Used and Shared
Clauses: §164.502, §164.508, §164.520, §164.524, §164.526, §164.522, §164.528, §164.530

Use and disclose PHI only when permitted

You must make sure health information is only used or shared when HIPAA allows it or when the required authorization has been obtained.

Evidence:

• Review of what information is shared

• Reason for each disclosure

• Applicable permission or authorization

Examples include treatment, payment, healthcare operations, public-interest activities, individual agreement, or limited data sets.

Follow the "minimum necessary" rule

Only provide the amount of information that is actually needed.

Access should be based on people's roles and responsibilities.

Evidence:

• Access policies

• Role-based access controls

• Rules for routine disclosures

• Review process for unusual requests

Use proper authorization forms

When authorization is required, the form must contain all required information.

It should identify:

• What information can be disclosed

• Who can disclose it

• Who can receive it

• Why it is being disclosed

• When the authorization expires

• Signature and date

• Information about withdrawing the authorization

• Required statements regarding conditions and further disclosure

Evidence:

• Completed authorization form

• Review showing that all required elements are included

Maintain a Notice of Privacy Practices

You must have a current Notice of Privacy Practices (NPP) containing the required information.

Evidence:

• Current notice

• Review against HIPAA requirements

• Effective date

Provide and publish the privacy notice

The notice should be provided to individuals as required and made available at your facility and on your website.

Evidence:

• Records showing the notice was provided

• Evidence of good-faith efforts to obtain acknowledgement

• Website and facility posting

Give individuals access to their records

Individuals should be able to request copies of their health information.

Generally, requests must be handled within 30 days, subject to the permitted extension.

Evidence:

• Access-request procedure

• Request register

• Dates showing requests were completed on time

• Copies provided in the requested format where possible

• Records showing permitted fees were applied

Handle requests to correct information

Individuals may ask for their records to be amended.

Evidence:

• Amendment requests

• Approval or rejection records

• Required explanation when a request is denied

Handle restriction and confidential communication requests

Individuals may request restrictions on how their information is used or request alternative ways of communication.

You must apply the required restriction when an individual pays the full cost of a service themselves and asks that the information not be shared with their health plan.

Evidence:

• Restriction requests

• Records showing mandatory restrictions were applied

• Alternative communication arrangements

Maintain an accounting of disclosures

You must be able to provide an accounting of certain disclosures going back six years.

Evidence:

• Disclosure log

• Date of disclosure

• Recipient

• Description of information

• Purpose

• Ability to produce the accounting within the required timeframe

Appoint privacy responsibility

You must designate:

• A privacy official

• A person/contact for privacy complaints

Evidence:

• Written appointment/designation

Train employees

Employees must receive training on your privacy policies.

Training should happen:

• When they join

• When significant changes are made

Evidence:

• Training records

• Training dates

• Employee attendance/completion records

Protect PHI in all forms

You must protect health information whether it is:

• Electronic

• Printed

• Spoken

This includes protecting information on screens, printers, files and conversations.

Evidence:

• Administrative safeguards

• Technical safeguards

• Physical safeguards

Handle complaints

People must have a way to submit privacy complaints.

You must record, investigate and respond to complaints.

Evidence:

• Complaint procedure

• Complaint register

• Investigation and resolution records

Apply sanctions for violations

Employees who violate HIPAA requirements must be subject to appropriate disciplinary action.

Evidence:

• Sanction policy

• Records showing that sanctions were actually applied when required

Reduce harm after a violation

When you discover a privacy violation, you must take reasonable steps to reduce or correct the harm.

Evidence:

• Incident records

• Corrective actions

• Mitigation records

Do not retaliate

Employees or individuals who make complaints or report violations must not be punished for doing so.

People should also not be forced to give up their HIPAA rights.

Evidence:

• Written policy or commitment

• Evidence that rights are not being waived as a condition of treatment or payment

________________________________________

3. Security Rule — Administrative Safeguards
Clauses: §164.308

Perform a complete risk analysis

You must conduct a risk analysis covering all electronic protected health information (ePHI).

The analysis should consider:

• Threats

• Vulnerabilities

• Existing controls

• Likelihood

• Potential impact

• Overall risk

Evidence:

• Formal risk analysis

• Scope and methodology

• Date of assessment

• Systems and devices covered

• Third parties included

• Identified risks

A vulnerability scan, questionnaire or simple HIPAA gap assessment is not the same as a risk analysis.

Update the risk analysis

The risk analysis should be reviewed when important changes occur, such as:

• New systems

• System migration

• Mergers

• Major incidents

Evidence:

• Review and update records

Manage identified risks

You must take reasonable steps to reduce identified risks.

Evidence:

• Risk treatment/management plan

• Risk owner

• Corrective action

• Target/completion date

• Evidence that significant risks were addressed

Apply sanctions

Employees who do not follow security requirements should be subject to appropriate sanctions.

Evidence:

• Sanction policy

• Records of actions taken

Review system activity

You must regularly review activity involving systems containing health information.

This can include:

• Audit logs

• Access reports

• Security alerts

• Incident records

Simply collecting logs is not enough. You should be able to show that someone reviewed them and acted when necessary.

Evidence:

• Review records

• Responsible person

• Review frequency

• Actions taken

Appoint a security official

Someone must have responsibility for HIPAA security policies and procedures.

Evidence:

• Formal designation

• Responsibilities and authority

Control employee access

Access to PHI must be:

• Properly authorised

• Supervised

• Removed when employment ends

Evidence:

• Access procedures

• Employee clearance process

• Termination records

• Evidence that access was removed promptly

Manage access based on job roles

Employees should receive access according to their responsibilities.

Access should be updated when their role changes and reviewed regularly.

Evidence:

• Access approval records

• Role definitions

• Periodic access reviews

• Corrective actions for inappropriate access

Provide security awareness training

Everyone who works with your organisation, including management, should receive appropriate security awareness training.

Training should cover areas such as:

• Security reminders

• Malware protection

• Login monitoring

• Password security

Evidence:

• Training records

• Refresher-training schedule

Manage security incidents

You must identify, respond to, reduce the impact of and document security incidents.

This includes incidents that do not necessarily become breaches.

Evidence:

• Security incident register

• Investigation records

• Actions taken

• Final outcomes

Have a backup and recovery process

You must have a system for backing up important data and should demonstrate that the data can actually be restored.

Evidence:

• Backup procedures

• Backup records

• Restore-test results

Have a disaster recovery plan

You need a documented plan for recovering systems and data after a major disruption.

Evidence:

• Disaster recovery plan

• Recovery procedures

Have an emergency operating plan

You need a plan to keep critical healthcare operations running during an emergency.

Evidence:

• Emergency operating plan

Test your contingency plans

You should test and update your contingency plans and identify which systems and data are most critical.

Evidence:

• Test records

• Test dates

• Results

• Corrective actions

• Criticality analysis

Regularly evaluate your security controls

You must periodically check whether your security measures continue to meet HIPAA requirements.

This should happen periodically and after significant changes.

Evidence:

• Evaluation reports

• Date and scope

• Method used

• Findings

• Corrective actions and closure records

________________________________________

4. Security Rule — Physical and Technical Safeguards
Clauses: §164.310, §164.312, §164.316

Control physical access

Physical access to locations and systems containing PHI must be controlled.

Evidence:

• Facility access controls

• Facility security plan

• Emergency access arrangements

• Maintenance records

Define workstation requirements

You should have rules explaining:

• How workstations may be used

• Where they should be located

• What activities are permitted

Evidence:

• Workstation-use policy

Protect workstations

Workstations should be physically protected from unauthorised use.

This includes remote and home-working environments.

Evidence:

• Physical security controls

• Remote-working safeguards

Control devices and media

You must have procedures for:

• Disposal

• Re-use

• Movement of equipment

• Media handling

• Backups before equipment is moved

Evidence:

• Disposal records

• Data sanitisation records

• Destruction certificates

• Equipment movement records

• Backup records

Give every user a unique ID

Users should have individual accounts.

Shared accounts should not be used unless there is a documented reason and appropriate controls.

Evidence:

• User-account records

• Justification and controls for any shared accounts

Have emergency access procedures

There must be a way for authorised people to access necessary health information during an emergency.

Evidence:

• Emergency or "break-glass" access procedure

Use automatic logoff and encryption appropriately

Where required, use controls such as:

• Automatic logoff

• Encryption

If an addressable safeguard is not implemented, you should document why it is not reasonable or appropriate and what alternative control is being used.

Evidence:

• System configuration

• Written assessment

• Alternative safeguards

Monitor system activity

You should record and review activity in systems containing PHI.

Evidence:

• Audit controls

• Audit logs

• Evidence that logs are reviewed

Protect data integrity

You must protect PHI against unauthorised changes or destruction.

Evidence:

• Integrity controls

• System safeguards

Verify user identity

You must confirm that a person or system requesting access is actually authorised.

Evidence:

• Authentication controls

• MFA where appropriate based on risk

Protect information during transmission

PHI must be protected when it is being transmitted.

Evidence:

• Transmission-security controls

• Encryption and integrity controls

• Written risk assessment if encryption is not used

Maintain policies and records for six years

HIPAA policies and procedures must be documented and retained for six years from creation or the date they were last in effect, whichever is later.

Evidence:

• Current policies

• Previous versions

• Review and update records

• Retention records

Document important decisions

Required assessments and decisions must be documented, including decisions not to implement an addressable safeguard.

Evidence:

• Written assessments

• Risk-based decisions

• Alternative controls

________________________________________

5. When a HIPAA Breach Happens
Clauses: §164.402, §164.404, §164.406, §164.408, §164.410

Investigate every suspected breach

When PHI is improperly used or disclosed, you need to perform the required four-factor assessment.

Consider:

1. What information was involved?

2. Who received or used it?

3. Was the information actually viewed or obtained?

4. What steps were taken to reduce the risk?

Evidence:

• Documented assessment

• Investigation findings

• Final conclusion

A decision that there is a low probability of compromise should be supported by evidence.

Record incidents that are not considered breaches

Even when an incident is determined not to be a breach, the decision and reasoning should be documented.

Evidence:

• Incident register

• Assessment

• Reason for the decision

Understand encryption and destruction exceptions

Properly encrypted or properly destroyed information may fall outside the breach definition.

Evidence:

• Encryption evidence

• Destruction/sanitisation evidence

Notify affected individuals

Affected individuals must generally be notified without unreasonable delay and within 60 days of discovering the breach.

Evidence:

• Notification letters

• Date of discovery

• Date notifications were sent

• Substitute notice where contact information is unavailable

Include the required information in notifications

The notification should explain:

• What happened

• When it happened

• What type of information was involved

• What individuals should do

• What your organisation is doing

• How they can contact you

Notify the media when required

If a breach affects 500 or more residents of a State or jurisdiction, prominent media notification may be required within 60 days.

Evidence:

• Media notification records

Notify HHS

For breaches affecting 500 or more individuals, notification to HHS is required without unreasonable delay.

For smaller breaches, reporting is generally done annually within the required timeframe.

Evidence:

• HHS submission records

• Submission dates

• Reference numbers

• Annual small-breach reports

Business Associates must notify Covered Entities

If you are a Business Associate, you must notify the Covered Entity about a breach without unreasonable delay and within the applicable HIPAA timeframe.

Evidence:

• Notification records

• Details of affected individuals

• Contractual notification requirements

________________________________________

6. Business Associates and Vendors
Clauses: §164.502(e), §164.504(e), §164.314(a)

Have agreements with all Business Associates

You should have a signed Business Associate Agreement (BAA) with every applicable Business Associate.

Evidence:

• Complete BAA register

• Signed agreements

• Supplier/vendor list reconciled with the BAA register

Make sure the BAA contains the required terms

The agreement should address areas such as:

• Permitted uses and disclosures

• Security safeguards

• Reporting of incidents

• Subcontractors

• Individual access rights

• Amendments

• Accounting of disclosures

• HHS access to records

• Return or destruction of information

Evidence:

• Reviewed and signed BAA

Manage subcontractors

If you are a Business Associate and use subcontractors who handle PHI, you must have appropriate agreements with them.

Evidence:

• Subcontractor agreements

Check that vendors actually protect PHI

Signing a BAA alone is not enough. You should perform appropriate due diligence and ongoing checks.

Evidence:

• Vendor assessments

• Due-diligence records

• Periodic reviews

• Security evidence

Take action when a vendor violates the agreement

If a Business Associate does not meet its obligations, you should take appropriate action.

Evidence:

• Investigation records

• Corrective actions

• Vendor communication

________________________________________

7. Be Ready for an OCR Investigation
Keep your HIPAA compliance records organised

You should be able to quickly provide your compliance documentation if the Office for Civil Rights (OCR) asks for it.

Evidence:

• Organised and indexed compliance file

• Policies

• Risk assessments

• Training records

• Incident records

• Vendor/BAA records

• Audit and review records

Make senior management aware of compliance risks

Management should understand the consequences of HIPAA non-compliance.

Evidence:

• Management briefings

• Meeting records

• Compliance reports

HIPAA penalties depend on factors such as the level of responsibility and whether violations were corrected.

Check state privacy and breach laws

HIPAA is not the only requirement that may apply.

You should check whether state laws impose additional or stricter requirements, particularly for:

• Breach notifications

• Privacy requirements

• Data handling

Evidence:

• State-law review

• Legal/compliance analysis

• Documented applicable requirements

________________________________________

How to Use This Document

This document is not asking you to create hundreds of manuals, forms or files.

The main objective is to show that your organisation has:

• Made the required decisions

• Implemented appropriate controls

• Assigned responsibilities

• Recorded important decisions

• Monitored what is happening

• Corrected problems when they occur

Simply having a long policy document does not mean you are compliant.

A procedure is useful only when employees actually follow it.

For example, if your policy says employees review audit logs every month, but there is no evidence that anyone actually reviewed them, an auditor may identify this as a gap.

The key question is:

Can you show that the controls you have documented are actually being followed in practice?

In simple terms, HIPAA compliance is not about having more documents. It is about having the right controls, following them consistently, and being able to provide evidence that they work.


What this covers

See how this looks as a working system

Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for HIPAA, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.

Ask us about this

Tell us what is being asked of you and by whom.

What are you looking for?

We reply within one working day. Your details stay with our consultants.

More reading

All articles