HIPAA Compliance Checklist 2018
HIPAA compliance remains a year-round obligation for covered entities and business associates, and the 2018 environment brought heightened attention to risk analysis, breach reporting, and business associate accountability. This checklist summarizes the core requirements and practical steps organizations should follow to meet federal privacy and security rules.
- HIPAA Compliance Checklist 2018
- Scope and Applicability
- Required Actions on the HIPAA Compliance Checklist 2018
- 1. Conduct a Thorough Risk Analysis
- 2. Implement Administrative Safeguards
- 3. Apply Physical Safeguards
- 4. Apply Technical Safeguards
- 5. Update the Notice of Privacy Practices
- 6. Establish Business Associate Agreements
- 7. Prepare for Breach Notification
- 8. Document Training and Workforce Awareness
- 9. Review and Update Policies Regularly
- Common Gaps to Watch for in 2018
- Keeping the Checklist Current
More from this site
Keep reading the latest coverage
Scope and Applicability
The HIPAA Privacy, Security, and Breach Notification Rules apply to health plans, healthcare clearinghouses, providers who transmit electronic transactions, and their business associates. A compliance program must address all three rule sets, with policies and safeguards tailored to the organization's size, complexity, and risk profile.
Required Actions on the HIPAA Compliance Checklist 2018
1. Conduct a Thorough Risk Analysis
A current, documented risk analysis is the foundation of the Security Rule. Organizations must identify where ePHI is created, received, maintained, or transmitted, assess threats and vulnerabilities, and document the results. The 2018 guidance emphasized that risk analysis should be a living process, revisited when operations, technology, or threats change.
2. Implement Administrative Safeguards
- Designate a security official responsible for policies and procedures.
- Train workforce members on HIPAA requirements and security practices.
- Establish an information access management process and contingency plan.
- Perform regular evaluations of security policies and technical safeguards.
3. Apply Physical Safeguards
Control physical access to facilities and workstations where ePHI is stored. This includes facility access plans, workstation security policies, and device and media controls for hardware that holds or moves ePHI.
4. Apply Technical Safeguards
Implement access controls, audit logs, integrity controls, and transmission security measures. Unique user IDs, automatic logoff, and encryption of ePHI in transit and at rest are key technical measures to evaluate.
5. Update the Notice of Privacy Practices
Organizations must maintain a current Notice of Privacy Practices and make it available to individuals. The notice should clearly describe how ePHI may be used and disclosed and outline individual rights under HIPAA.
6. Establish Business Associate Agreements
Every vendor or partner that creates, receives, or handles ePHI on your behalf must have a signed business associate agreement. The agreement should specify permitted uses, required safeguards, and breach notification duties.
7. Prepare for Breach Notification
Update breach notification procedures to reflect the 2018 emphasis on timely notification to affected individuals, the HHS Office for Civil Rights, and, in large breaches, the media. Document the breach risk assessment and response steps clearly.
8. Document Training and Workforce Awareness
Maintain records of HIPAA training dates, attendees, and content. Training should address security awareness, phishing, and proper handling of ePHI, and it should be refreshed at least annually.
9. Review and Update Policies Regularly
HIPAA policies should be reviewed at least once a year or whenever significant regulatory, operational, or technological changes occur. Updates must be approved, distributed, and acknowledged by workforce members.
Common Gaps to Watch for in 2018
- Outdated risk analyses that do not reflect current technology or threat landscape.
- Missing or incomplete business associate agreements.
- Inconsistent workforce training records or lack of role-specific security training.
- Insufficient technical safeguards, such as missing encryption or audit logging.
- Breach response plans that have not been tested or updated.
Keeping the Checklist Current
While the core HIPAA rules remain stable, enforcement expectations and guidance evolve. Organizations should monitor HHS Office for Civil Rights updates, settle potential violations promptly, and use enforcement actions as a learning resource. A well-maintained compliance program reduces risk and supports sustained adherence to federal privacy and security standards.