Knowledge base

HIPAA: documentation and compliance requirements

Everything HIPAA requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checklist.

Prem Kumar Dvivedi · 12 September 2026

This is what HIPAA requires you to have, clause by clause, and what an auditor will ask to see for each of it. It covers 63 requirements across 7 areas.

It is deliberately not a checklist. A checklist asks whether you have something; this says what is required and what counts as evidence, which is the question that matters when you are building a system rather than testing one. If you would rather find out where you stand first, the same ground is covered by our free HIPAA readiness assessment, which scores you out of 100.

Where you stand, and what you hold

Clauses §160.103, §164.105, §164.308.

You must have written down what you are — a covered entity, a business associate, or a subcontractor of one.

Evidence: The determination with the reasoning. Health plan, clearinghouse or provider transmitting electronically; or someone handling protected health information on their behalf. Subcontractors are directly regulated in their own right.

If only part of your organisation does covered work, you must have designated yourself a hybrid entity.

Evidence: The hybrid entity designation with the health care components listed. N/A with a reason if it does not apply.

You must know where ALL your protected health information is — every system, device, place, medium and third party.

Evidence: An inventory covering applications, databases, servers, cloud services, laptops, phones, removable media, backups, email, fax, imaging, medical devices and paper. Data flow diagrams. Home and remote working locations. Everything downstream depends on this being complete.

Privacy Rule — using and sharing health information

Clauses §164.502, §164.502(b), §164.508, §164.520, §164.524, §164.526, §164.522, §164.528, §164.530(a), §164.530(b), §164.530(c), §164.530(d), §164.530(e), §164.530(f), §164.530(g).

Every must be use and disclosure of health information one the rules permit, or covered by an authorisation.

Evidence: An analysis of what you disclose and the permission relied on: to the individual; for treatment, payment or operations; incidental; public interest activities; with agreement or opportunity to object; or as a limited data set.

You must limit information to the minimum needed, with role-based access.

Evidence: Policies naming who needs access to what, and under what conditions. Role-based access reflecting it. Criteria for routine disclosures and a review process for unusual ones.

Where you need an authorisation, your form must contain everything required.

Evidence: The form checked against the core elements: a specific description of the information, who may disclose, who may receive, the purpose, an expiry, and the signature and date. Plus the required statements on revoking, on conditioning, and on redisclosure.

You must have a Notice of Privacy Practices with the required content and a current effective date.

Evidence: The notice checked against the requirements. Note the reproductive health provisions from April 2024 were struck down nationwide in June 2025 and should NOT be in a current notice.

The must be notice actually given out, posted, and on your website.

Evidence: Evidence of provision at first service with a good-faith effort to get written acknowledgement. Posting at the site and online.

You must be able to answer: Can individuals get access to and copies of their records within 30 days?

Evidence: A request procedure with the 30-day limit and the single extension. A register with elapsed times. Copies provided in the format asked for where you can. Fees limited to the permitted cost-based fee.

You must be able to answer: Can individuals ask for their records to be amended, and do you handle it properly?

Evidence: Amendment requests with acceptance or denial, and the required statements where you deny.

You must be able to answer: Can individuals request restrictions and confidential communications — and do you honour the mandatory restriction where they pay in full themselves?

Evidence: Restriction request records. The mandatory restriction applied where someone pays out of pocket in full. Alternative contact arrangements.

You must be able to give someone an accounting of disclosures going back six years.

Evidence: A disclosure log capturing the disclosures that must be accounted for, with date, recipient, description and purpose. Ability to produce it within 60 days.

You must have named a privacy official and a contact for complaints.

Evidence: Both designations, documented.

Everyone must be trained on your privacy policies — new starters and after any material change.

Evidence: Training records with dates.

You must have safeguards protecting health information, including paper and conversations.

Evidence: Administrative, technical and physical safeguards. Screens, printers, filing, and how staff discuss cases where they can be overheard.

People must be able to complain, and you must record and act on complaints.

Evidence: A complaints process with a register and outcomes.

You must apply sanctions to staff who break the rules.

Evidence: A sanction policy and evidence of use.

You must mitigate harm when you find out about a violation.

Evidence: Records of what you did to limit harm.

You must avoid retaliating against anyone who complains or reports, and avoid making people waive rights.

Evidence: A written commitment. Evidence no waiver is required as a condition of treatment or payment.

Security Rule — administrative safeguards

Clauses §164.308(a)(1)(ii)(A), §164.308(a)(1)(ii)(B), §164.308(a)(1)(ii)(C), §164.308(a)(1)(ii)(D), §164.308(a)(2), §164.308(a)(3), §164.308(a)(4), §164.308(a)(5), §164.308(a)(6), §164.308(a)(7), §164.308(a)(8).

You must have carried out a risk analysis covering ALL your electronic health information.

Evidence: A risk analysis covering every system, device, place and third party in your inventory: threats, vulnerabilities, current measures, likelihood, impact and resulting risk. Its date, scope, method and author. THIS IS THE MOST CITED FAILURE IN OCR ENFORCEMENT. A vulnerability scan, a questionnaire or a gap assessment against the Rule is NOT a risk analysis.

The must be risk analysis updated when things change.

Evidence: Review records. Update after a new system, a migration, a merger or an incident.

You must have reduced the risks to a reasonable level, with decisions traceable back to the analysis.

Evidence: A risk management plan mapping each risk to a measure, an owner and a date. Evidence the high risks were actually dealt with.

You must have a sanction policy for staff who do not comply, and you must have used it.

Evidence: The policy and records of sanctions applied.

You must regularly review system activity — audit logs, access reports, incident tracking.

Evidence: Evidence of the review itself, not just log collection: who looks, how often, and what they did about what they found. This is a REQUIRED specification, not an optional one.

You must have named a security official responsible for the policies and procedures.

Evidence: The designation with responsibilities and authority.

Workforce access to health information must be authorised, supervised and removed on termination.

Evidence: Authorisation and supervision procedures. A clearance procedure. Termination records with evidence access was removed promptly.

Access must be granted by role, changed when roles change, and reviewed.

Evidence: Access authorisation records. Role definitions. Periodic access reviews with action on exceptions.

You must be able to answer: Do all workforce members, including management, get security awareness training?

Evidence: Training records covering security reminders, malware protection, login monitoring and password management. Refresher cadence.

You must identify, respond to, mitigate and document security incidents and their outcomes.

Evidence: An incident register covering ALL security incidents, not just breaches. The Rule requires documenting incidents and their outcomes regardless of whether they were breaches.

You must have a data backup plan, and you must be able to actually restore.

Evidence: Backup arrangements and restore test evidence. This is a REQUIRED specification.

You must have a disaster recovery plan.

Evidence: The plan for restoring lost data. REQUIRED.

You must have an emergency mode operation plan so critical work continues.

Evidence: The plan. REQUIRED.

You must have tested and revised the contingency plans, and worked out which systems matter most.

Evidence: Test records with dates. An applications and data criticality analysis.

You must periodically evaluate whether your security measures still meet the Rule — technically and non-technically.

Evidence: Evaluation records with date, scope, method and findings. Done periodically and after significant change. Findings tracked to closure.

Security Rule — physical and technical safeguards

Clauses §164.310(a), §164.310(b), §164.310(c), §164.310(d), §164.312(a), §164.312(b), §164.312(c), §164.312(d), §164.312(e), §164.316.

You must control physical access to facilities and systems holding health information.

Evidence: Facility access controls, contingency operations, a facility security plan, validation procedures and maintenance records.

You must have set rules for how workstations are used and where they are placed.

Evidence: Workstation use policy specifying proper functions and the physical surroundings.

Workstations must be physically secured so only authorised people can use them.

Evidence: Physical security measures, including for home and remote working.

You must control devices and media — disposal, re-use, movement and backup before moving equipment.

Evidence: Disposal and sanitisation records. Certificates of destruction. Movement records. Backup before moving equipment.

Every must user have a unique identifier, with no shared accounts.

Evidence: User account records. Any shared or generic account justified and controlled. REQUIRED.

There must be an emergency access procedure for getting to health information in a crisis.

Evidence: The break-glass procedure. REQUIRED.

You must use automatic logoff and encryption — or you must have documented why not and what you do instead.

Evidence: Configuration evidence, or the written assessment explaining why the addressable specification was not reasonable and appropriate and what equivalent you adopted. THE MISSING DOCUMENT IS THE VIOLATION — addressable does not mean optional.

You must record and examine activity in systems holding health information.

Evidence: Audit controls configured and the logs actually examined.

You must protect health information from being improperly altered or destroyed.

Evidence: Integrity controls.

You must verify that a person or system seeking access is who they claim to be.

Evidence: Authentication controls, including multi-factor where the risk warrants it.

You must protect health information while it is being transmitted.

Evidence: Transmission security. Integrity controls and encryption, or the written assessment where encryption is not used.

Your policies and procedures must be written down and kept for six years.

Evidence: The policy set covering all three rules, reviewed and updated as things change. Retention for six years from creation or from when last in effect, whichever is later.

The must be required assessments and decisions documented — including every addressable specification you did not implement.

Evidence: The written assessments. This is where organisations most often have nothing.

When there is a breach

Clauses §164.402, §164.404, §164.406, §164.408, §164.410.

When health information is used or disclosed improperly, you must carry out the four-factor assessment.

Evidence: An assessment for every incident covering: the nature and extent of the information including identifiers and the chance of re-identification; who used or received it; whether it was actually acquired or viewed; and how far the risk has been reduced. The conclusion recorded either way — a low probability of compromise has to be shown, not assumed.

You must keep a record of incidents you decided were NOT breaches, with the reasoning.

Evidence: The register including non-breaches. This is what an investigator asks for first.

You must know that encrypted or properly destroyed information is outside the definition.

Evidence: Evidence of encryption or destruction to the specified standards, where relied on.

You must notify affected individuals without unreasonable delay and within 60 days of discovery.

Evidence: Notification letters with send dates measured from discovery — the first day you knew or should reasonably have known. Substitute notice where contact details are out of date.

The letters must contain everything required.

Evidence: A description of what happened and when, the types of information involved, what individuals should do, what you are doing, and how to contact you.

Where 500 or more residents of a State are affected, you must notify prominent media within 60 days.

Evidence: Media notice records. N/A with a reason if it has not arisen.

You must notify HHS — immediately for 500 or more, and annually within 60 days of year end for smaller ones.

Evidence: Portal submissions with dates and reference numbers. The annual small-breach log actually submitted — this is the most commonly forgotten obligation in the whole Breach Rule.

Where you are a business associate, you must notify the covered entity without unreasonable delay and within 60 days.

Evidence: Notification records identifying each affected individual. Where you are the covered entity, check your agreements shorten the associate's deadline enough to leave you time to meet your own.

Business associates and vendors

Clauses §164.502(e), §164.504(e), §164.314(a).

You must have a signed agreement with every business associate.

Evidence: A complete register, reconciled against your supplier or accounts payable list rather than compiled from memory. Unidentified business associates are the usual gap.

Each must agreement contain the required provisions.

Evidence: The agreement checked against: permitted uses, safeguards, reporting of improper uses and security incidents, flow-down to subcontractors, availability of information for access, amendment and accounting, availability of records to HHS, and return or destruction at the end.

Where you are a business associate, you must have agreements with your own subcontractors.

Evidence: Subcontractor agreements with equivalent terms.

You must do more than sign the agreement — you must check the associate actually protects the information.

Evidence: Due diligence and ongoing checks. The agreement alone does not discharge your duty.

You must have acted where a business associate breached the agreement.

Evidence: Records of what you did.

Being ready for OCR

Clauses Enforcement, State law.

You must be able to produce the whole compliance file if OCR asked.

Evidence: An indexed file assembled ahead of need. Investigations usually start from a complaint or a breach report and run to short deadlines.

Senior management must know what non-compliance costs.

Evidence: Evidence they have been briefed. Penalties are tiered by culpability and adjusted for inflation, with the highest tier for wilful neglect that is not corrected.

You must have checked whether state law is stricter than HIPAA on anything.

Evidence: Analysis of state breach notification deadlines and definitions, which are often tighter. HIPAA is a floor, not a ceiling, and stricter state law applies alongside it.

Using this document

Nothing above asks for a manual, a template pack, or a filing system. It asks for decisions that have been taken deliberately and can be shown to have been taken — which is a far smaller job than most organisations expect, and a different one.

Length is not compliance. A procedure nobody follows is worse than no procedure, because an auditor finds the gap between the two. The test we apply is whether the person who has to do the job recognises their own work in what is written down.

What this covers

See how this looks as a working system

Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for HIPAA, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.

Ask us about this

Tell us what is being asked of you and by whom.

What are you looking for?

We reply within one working day. Your details stay with our consultants.

More reading

All articles