HIPAA
HIPAA Compliance Checklist
Cycore's 70-item HIPAA self-assessment. Settle whether HIPAA applies to you first, then score your safeguards out of 140 and take the gaps to counsel.
We built this 70-item checklist for teams that need to know where they stand on HIPAA. It starts with the question that decides everything else: whether you're a covered entity or a business associate. Handling health data on its own doesn't make you either one, and the checklist says what to do if you can't answer yet. If you run a GRC platform, use this before mapping to its HIPAA framework: it marks which items are law and which are our advice.
What's inside
Nine sections, 70 items:
- Foundational Decisions (6)
- Administrative Safeguards (10)
- Physical Safeguards (7)
- Technical Safeguards (10)
- Privacy Rule Requirements (8)
- Business Associate Management (7)
- Breach Notification Preparedness (8)
- Documentation and Training (8)
- Audit Readiness (6)
Every item carries one of four labels: HIPAA required, HIPAA addressable, Cycore recommended practice, or Scope-dependent. Items that claim a rule cite it.
How to use it
Print it and mark it by hand. Answer the applicability question first, then score each item 0 (not in place), 1 (partial), or 2 (in place and documented), add up each section, and total your score out of 140. The total is a Cycore planning number. It isn't an HHS score, and it doesn't tell you whether you're compliant. Put a name next to every 0 and 1, then take the list and its open questions to counsel.
The button on this page downloads the PDF.
proof of work
Read the case study