HIPAA

HIPAA Compliance Checklist

Cycore's 70-item HIPAA self-assessment. Settle whether HIPAA applies to you first, then score your safeguards out of 140 and take the gaps to counsel.

Download the PDF
PDF, 13 pages, no form

We built this 70-item checklist for teams that need to know where they stand on HIPAA. It starts with the question that decides everything else: whether you're a covered entity or a business associate. Handling health data on its own doesn't make you either one, and the checklist says what to do if you can't answer yet. If you run a GRC platform, use this before mapping to its HIPAA framework: it marks which items are law and which are our advice.

What's inside

Nine sections, 70 items:

  • Foundational Decisions (6)
  • Administrative Safeguards (10)
  • Physical Safeguards (7)
  • Technical Safeguards (10)
  • Privacy Rule Requirements (8)
  • Business Associate Management (7)
  • Breach Notification Preparedness (8)
  • Documentation and Training (8)
  • Audit Readiness (6)

Every item carries one of four labels: HIPAA required, HIPAA addressable, Cycore recommended practice, or Scope-dependent. Items that claim a rule cite it.

How to use it

Print it and mark it by hand. Answer the applicability question first, then score each item 0 (not in place), 1 (partial), or 2 (in place and documented), add up each section, and total your score out of 140. The total is a Cycore planning number. It isn't an HHS score, and it doesn't tell you whether you're compliant. Put a name next to every 0 and 1, then take the list and its open questions to counsel.

The button on this page downloads the PDF.

Download the PDF
Format
PDF, 13 pages
Last reviewed
September 23, 2026
Form
None

proof of work

Read the case study
HIPAA

HIPAA Compliance Checklist

Cycore's 70-item HIPAA self-assessment. Settle whether HIPAA applies to you first, then score your safeguards out of 140 and take the gaps to counsel.

Download the PDF

We built this 70-item checklist for teams that need to know where they stand on HIPAA. It starts with the question that decides everything else: whether you're a covered entity or a business associate. Handling health data on its own doesn't make you either one, and the checklist says what to do if you can't answer yet. If you run a GRC platform, use this before mapping to its HIPAA framework: it marks which items are law and which are our advice.

What's inside

Nine sections, 70 items:

  • Foundational Decisions (6)
  • Administrative Safeguards (10)
  • Physical Safeguards (7)
  • Technical Safeguards (10)
  • Privacy Rule Requirements (8)
  • Business Associate Management (7)
  • Breach Notification Preparedness (8)
  • Documentation and Training (8)
  • Audit Readiness (6)

Every item carries one of four labels: HIPAA required, HIPAA addressable, Cycore recommended practice, or Scope-dependent. Items that claim a rule cite it.

How to use it

Print it and mark it by hand. Answer the applicability question first, then score each item 0 (not in place), 1 (partial), or 2 (in place and documented), add up each section, and total your score out of 140. The total is a Cycore planning number. It isn't an HHS score, and it doesn't tell you whether you're compliant. Put a name next to every 0 and 1, then take the list and its open questions to counsel.

The button on this page downloads the PDF.

HIPAA framework page

Read the case study

More Cycore resources

Next step

Talk to Cycore about your HIPAA program

This checklist is a Cycore diagnostic organized around the AICPA Trust Services Criteria. It is not an AICPA checklist and it is not legal or audit advice. Your auditor determines examination scope, evidence, and conclusions. Completing every item does not guarantee readiness or a particular audit outcome.