Knowledge base
HIPAA: Documentation and Compliance Requirements
This document explains what HIPAA requires, section by section, and what an auditor may ask you to show as evidence.
Prem Kumar Dvivedi · 12 settembre 2026
It covers 63 requirements across 7 major areas.
This is not just a checklist. A checklist asks, “Do you have this?” This document explains what you need to have and what evidence can prove that you are actually following it.
If you first want to understand your current level of compliance, you can use a HIPAA readiness assessment to identify gaps and measure your readiness.
________________________________________
1. Know Your Organisation and Where Your Data Is
Clauses: §160.103, §164.105, §164.308
Know what type of organisation you are
You must clearly identify whether your organisation is:
• A Covered Entity
• A Business Associate
• A Subcontractor of a Business Associate
Evidence an auditor may ask for:
• Written classification
• Reason for the classification
• Explanation of the healthcare activities you perform
Identify hybrid entities
If only certain parts of your organisation perform healthcare-related activities, you may need to formally identify yourself as a hybrid entity.
Evidence:
• Written hybrid-entity designation
• List of healthcare components
• If not applicable, documented justification
Know where all protected health information (PHI) is stored
You should know where all your PHI exists, including:
• Applications and databases
• Servers and cloud systems
• Laptops and mobile phones
• USB/removable devices
• Backups
• Email and fax
• Medical devices
• Paper records
• Home and remote-working locations
• Third-party systems
Evidence:
• PHI/data inventory
• Data-flow diagrams
• List of systems, devices and third parties handling PHI
A complete inventory is important because most other HIPAA controls depend on knowing where your information is.
________________________________________
2. Privacy Rule — How Health Information Is Used and Shared
Clauses: §164.502, §164.508, §164.520, §164.524, §164.526, §164.522, §164.528, §164.530
Use and disclose PHI only when permitted
You must make sure health information is only used or shared when HIPAA allows it or when the required authorization has been obtained.
Evidence:
• Review of what information is shared
• Reason for each disclosure
• Applicable permission or authorization
Examples include treatment, payment, healthcare operations, public-interest activities, individual agreement, or limited data sets.
Follow the "minimum necessary" rule
Only provide the amount of information that is actually needed.
Access should be based on people's roles and responsibilities.
Evidence:
• Access policies
• Role-based access controls
• Rules for routine disclosures
• Review process for unusual requests
Use proper authorization forms
When authorization is required, the form must contain all required information.
It should identify:
• What information can be disclosed
• Who can disclose it
• Who can receive it
• Why it is being disclosed
• When the authorization expires
• Signature and date
• Information about withdrawing the authorization
• Required statements regarding conditions and further disclosure
Evidence:
• Completed authorization form
• Review showing that all required elements are included
Maintain a Notice of Privacy Practices
You must have a current Notice of Privacy Practices (NPP) containing the required information.
Evidence:
• Current notice
• Review against HIPAA requirements
• Effective date
Provide and publish the privacy notice
The notice should be provided to individuals as required and made available at your facility and on your website.
Evidence:
• Records showing the notice was provided
• Evidence of good-faith efforts to obtain acknowledgement
• Website and facility posting
Give individuals access to their records
Individuals should be able to request copies of their health information.
Generally, requests must be handled within 30 days, subject to the permitted extension.
Evidence:
• Access-request procedure
• Request register
• Dates showing requests were completed on time
• Copies provided in the requested format where possible
• Records showing permitted fees were applied
Handle requests to correct information
Individuals may ask for their records to be amended.
Evidence:
• Amendment requests
• Approval or rejection records
• Required explanation when a request is denied
Handle restriction and confidential communication requests
Individuals may request restrictions on how their information is used or request alternative ways of communication.
You must apply the required restriction when an individual pays the full cost of a service themselves and asks that the information not be shared with their health plan.
Evidence:
• Restriction requests
• Records showing mandatory restrictions were applied
• Alternative communication arrangements
Maintain an accounting of disclosures
You must be able to provide an accounting of certain disclosures going back six years.
Evidence:
• Disclosure log
• Date of disclosure
• Recipient
• Description of information
• Purpose
• Ability to produce the accounting within the required timeframe
Appoint privacy responsibility
You must designate:
• A privacy official
• A person/contact for privacy complaints
Evidence:
• Written appointment/designation
Train employees
Employees must receive training on your privacy policies.
Training should happen:
• When they join
• When significant changes are made
Evidence:
• Training records
• Training dates
• Employee attendance/completion records
Protect PHI in all forms
You must protect health information whether it is:
• Electronic
• Printed
• Spoken
This includes protecting information on screens, printers, files and conversations.
Evidence:
• Administrative safeguards
• Technical safeguards
• Physical safeguards
Handle complaints
People must have a way to submit privacy complaints.
You must record, investigate and respond to complaints.
Evidence:
• Complaint procedure
• Complaint register
• Investigation and resolution records
Apply sanctions for violations
Employees who violate HIPAA requirements must be subject to appropriate disciplinary action.
Evidence:
• Sanction policy
• Records showing that sanctions were actually applied when required
Reduce harm after a violation
When you discover a privacy violation, you must take reasonable steps to reduce or correct the harm.
Evidence:
• Incident records
• Corrective actions
• Mitigation records
Do not retaliate
Employees or individuals who make complaints or report violations must not be punished for doing so.
People should also not be forced to give up their HIPAA rights.
Evidence:
• Written policy or commitment
• Evidence that rights are not being waived as a condition of treatment or payment
________________________________________
3. Security Rule — Administrative Safeguards
Clauses: §164.308
Perform a complete risk analysis
You must conduct a risk analysis covering all electronic protected health information (ePHI).
The analysis should consider:
• Threats
• Vulnerabilities
• Existing controls
• Likelihood
• Potential impact
• Overall risk
Evidence:
• Formal risk analysis
• Scope and methodology
• Date of assessment
• Systems and devices covered
• Third parties included
• Identified risks
A vulnerability scan, questionnaire or simple HIPAA gap assessment is not the same as a risk analysis.
Update the risk analysis
The risk analysis should be reviewed when important changes occur, such as:
• New systems
• System migration
• Mergers
• Major incidents
Evidence:
• Review and update records
Manage identified risks
You must take reasonable steps to reduce identified risks.
Evidence:
• Risk treatment/management plan
• Risk owner
• Corrective action
• Target/completion date
• Evidence that significant risks were addressed
Apply sanctions
Employees who do not follow security requirements should be subject to appropriate sanctions.
Evidence:
• Sanction policy
• Records of actions taken
Review system activity
You must regularly review activity involving systems containing health information.
This can include:
• Audit logs
• Access reports
• Security alerts
• Incident records
Simply collecting logs is not enough. You should be able to show that someone reviewed them and acted when necessary.
Evidence:
• Review records
• Responsible person
• Review frequency
• Actions taken
Appoint a security official
Someone must have responsibility for HIPAA security policies and procedures.
Evidence:
• Formal designation
• Responsibilities and authority
Control employee access
Access to PHI must be:
• Properly authorised
• Supervised
• Removed when employment ends
Evidence:
• Access procedures
• Employee clearance process
• Termination records
• Evidence that access was removed promptly
Manage access based on job roles
Employees should receive access according to their responsibilities.
Access should be updated when their role changes and reviewed regularly.
Evidence:
• Access approval records
• Role definitions
• Periodic access reviews
• Corrective actions for inappropriate access
Provide security awareness training
Everyone who works with your organisation, including management, should receive appropriate security awareness training.
Training should cover areas such as:
• Security reminders
• Malware protection
• Login monitoring
• Password security
Evidence:
• Training records
• Refresher-training schedule
Manage security incidents
You must identify, respond to, reduce the impact of and document security incidents.
This includes incidents that do not necessarily become breaches.
Evidence:
• Security incident register
• Investigation records
• Actions taken
• Final outcomes
Have a backup and recovery process
You must have a system for backing up important data and should demonstrate that the data can actually be restored.
Evidence:
• Backup procedures
• Backup records
• Restore-test results
Have a disaster recovery plan
You need a documented plan for recovering systems and data after a major disruption.
Evidence:
• Disaster recovery plan
• Recovery procedures
Have an emergency operating plan
You need a plan to keep critical healthcare operations running during an emergency.
Evidence:
• Emergency operating plan
Test your contingency plans
You should test and update your contingency plans and identify which systems and data are most critical.
Evidence:
• Test records
• Test dates
• Results
• Corrective actions
• Criticality analysis
Regularly evaluate your security controls
You must periodically check whether your security measures continue to meet HIPAA requirements.
This should happen periodically and after significant changes.
Evidence:
• Evaluation reports
• Date and scope
• Method used
• Findings
• Corrective actions and closure records
________________________________________
4. Security Rule — Physical and Technical Safeguards
Clauses: §164.310, §164.312, §164.316
Control physical access
Physical access to locations and systems containing PHI must be controlled.
Evidence:
• Facility access controls
• Facility security plan
• Emergency access arrangements
• Maintenance records
Define workstation requirements
You should have rules explaining:
• How workstations may be used
• Where they should be located
• What activities are permitted
Evidence:
• Workstation-use policy
Protect workstations
Workstations should be physically protected from unauthorised use.
This includes remote and home-working environments.
Evidence:
• Physical security controls
• Remote-working safeguards
Control devices and media
You must have procedures for:
• Disposal
• Re-use
• Movement of equipment
• Media handling
• Backups before equipment is moved
Evidence:
• Disposal records
• Data sanitisation records
• Destruction certificates
• Equipment movement records
• Backup records
Give every user a unique ID
Users should have individual accounts.
Shared accounts should not be used unless there is a documented reason and appropriate controls.
Evidence:
• User-account records
• Justification and controls for any shared accounts
Have emergency access procedures
There must be a way for authorised people to access necessary health information during an emergency.
Evidence:
• Emergency or "break-glass" access procedure
Use automatic logoff and encryption appropriately
Where required, use controls such as:
• Automatic logoff
• Encryption
If an addressable safeguard is not implemented, you should document why it is not reasonable or appropriate and what alternative control is being used.
Evidence:
• System configuration
• Written assessment
• Alternative safeguards
Monitor system activity
You should record and review activity in systems containing PHI.
Evidence:
• Audit controls
• Audit logs
• Evidence that logs are reviewed
Protect data integrity
You must protect PHI against unauthorised changes or destruction.
Evidence:
• Integrity controls
• System safeguards
Verify user identity
You must confirm that a person or system requesting access is actually authorised.
Evidence:
• Authentication controls
• MFA where appropriate based on risk
Protect information during transmission
PHI must be protected when it is being transmitted.
Evidence:
• Transmission-security controls
• Encryption and integrity controls
• Written risk assessment if encryption is not used
Maintain policies and records for six years
HIPAA policies and procedures must be documented and retained for six years from creation or the date they were last in effect, whichever is later.
Evidence:
• Current policies
• Previous versions
• Review and update records
• Retention records
Document important decisions
Required assessments and decisions must be documented, including decisions not to implement an addressable safeguard.
Evidence:
• Written assessments
• Risk-based decisions
• Alternative controls
________________________________________
5. When a HIPAA Breach Happens
Clauses: §164.402, §164.404, §164.406, §164.408, §164.410
Investigate every suspected breach
When PHI is improperly used or disclosed, you need to perform the required four-factor assessment.
Consider:
1. What information was involved?
2. Who received or used it?
3. Was the information actually viewed or obtained?
4. What steps were taken to reduce the risk?
Evidence:
• Documented assessment
• Investigation findings
• Final conclusion
A decision that there is a low probability of compromise should be supported by evidence.
Record incidents that are not considered breaches
Even when an incident is determined not to be a breach, the decision and reasoning should be documented.
Evidence:
• Incident register
• Assessment
• Reason for the decision
Understand encryption and destruction exceptions
Properly encrypted or properly destroyed information may fall outside the breach definition.
Evidence:
• Encryption evidence
• Destruction/sanitisation evidence
Notify affected individuals
Affected individuals must generally be notified without unreasonable delay and within 60 days of discovering the breach.
Evidence:
• Notification letters
• Date of discovery
• Date notifications were sent
• Substitute notice where contact information is unavailable
Include the required information in notifications
The notification should explain:
• What happened
• When it happened
• What type of information was involved
• What individuals should do
• What your organisation is doing
• How they can contact you
Notify the media when required
If a breach affects 500 or more residents of a State or jurisdiction, prominent media notification may be required within 60 days.
Evidence:
• Media notification records
Notify HHS
For breaches affecting 500 or more individuals, notification to HHS is required without unreasonable delay.
For smaller breaches, reporting is generally done annually within the required timeframe.
Evidence:
• HHS submission records
• Submission dates
• Reference numbers
• Annual small-breach reports
Business Associates must notify Covered Entities
If you are a Business Associate, you must notify the Covered Entity about a breach without unreasonable delay and within the applicable HIPAA timeframe.
Evidence:
• Notification records
• Details of affected individuals
• Contractual notification requirements
________________________________________
6. Business Associates and Vendors
Clauses: §164.502(e), §164.504(e), §164.314(a)
Have agreements with all Business Associates
You should have a signed Business Associate Agreement (BAA) with every applicable Business Associate.
Evidence:
• Complete BAA register
• Signed agreements
• Supplier/vendor list reconciled with the BAA register
Make sure the BAA contains the required terms
The agreement should address areas such as:
• Permitted uses and disclosures
• Security safeguards
• Reporting of incidents
• Subcontractors
• Individual access rights
• Amendments
• Accounting of disclosures
• HHS access to records
• Return or destruction of information
Evidence:
• Reviewed and signed BAA
Manage subcontractors
If you are a Business Associate and use subcontractors who handle PHI, you must have appropriate agreements with them.
Evidence:
• Subcontractor agreements
Check that vendors actually protect PHI
Signing a BAA alone is not enough. You should perform appropriate due diligence and ongoing checks.
Evidence:
• Vendor assessments
• Due-diligence records
• Periodic reviews
• Security evidence
Take action when a vendor violates the agreement
If a Business Associate does not meet its obligations, you should take appropriate action.
Evidence:
• Investigation records
• Corrective actions
• Vendor communication
________________________________________
7. Be Ready for an OCR Investigation
Keep your HIPAA compliance records organised
You should be able to quickly provide your compliance documentation if the Office for Civil Rights (OCR) asks for it.
Evidence:
• Organised and indexed compliance file
• Policies
• Risk assessments
• Training records
• Incident records
• Vendor/BAA records
• Audit and review records
Make senior management aware of compliance risks
Management should understand the consequences of HIPAA non-compliance.
Evidence:
• Management briefings
• Meeting records
• Compliance reports
HIPAA penalties depend on factors such as the level of responsibility and whether violations were corrected.
Check state privacy and breach laws
HIPAA is not the only requirement that may apply.
You should check whether state laws impose additional or stricter requirements, particularly for:
• Breach notifications
• Privacy requirements
• Data handling
Evidence:
• State-law review
• Legal/compliance analysis
• Documented applicable requirements
________________________________________
How to Use This Document
This document is not asking you to create hundreds of manuals, forms or files.
The main objective is to show that your organisation has:
• Made the required decisions
• Implemented appropriate controls
• Assigned responsibilities
• Recorded important decisions
• Monitored what is happening
• Corrected problems when they occur
Simply having a long policy document does not mean you are compliant.
A procedure is useful only when employees actually follow it.
For example, if your policy says employees review audit logs every month, but there is no evidence that anyone actually reviewed them, an auditor may identify this as a gap.
The key question is:
Can you show that the controls you have documented are actually being followed in practice?
In simple terms, HIPAA compliance is not about having more documents. It is about having the right controls, following them consistently, and being able to provide evidence that they work.
What this covers
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for HIPAA, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- Automotive Suppliers Face Stricter Cybersecurity Assessments
Cybersecurity is becoming a key part of supplier evaluations in the automotive industry. Vehicle manufacturers now check how suppliers protect data and systems alongside quality, cost, and delivery.
13 settembre 2026
- Automotive OEM Vendor Cybersecurity Assessment: Controls, Scoring and ISO Standards Mapping
What does an automotive vendor cybersecurity assessment cover?
13 settembre 2026
- Inside an Automotive OEM Vendor Cybersecurity Assessment: The 19 Control Families and What They Actually Ask For
The nineteen control families in an automotive vendor cybersecurity assessment, where the structure came from, and why good controls still score zero.
13 settembre 2026
