0% found this document useful (0 votes)
553 views1 page

HIPAA Compliance Checklist Download

This document is a HIPAA compliance checklist that lists elements an organization should have in place as part of an effective compliance program. It includes conducting annual audits and assessments in key areas like security, privacy standards, and devices/assets. Organizations should identify gaps, create documented remediation plans, provide staff training, have policies/procedures, manage business associates, and have an incident response process. Maintaining documentation for six years is also emphasized.

Uploaded by

Hetik Go
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
553 views1 page

HIPAA Compliance Checklist Download

This document is a HIPAA compliance checklist that lists elements an organization should have in place as part of an effective compliance program. It includes conducting annual audits and assessments in key areas like security, privacy standards, and devices/assets. Organizations should identify gaps, create documented remediation plans, provide staff training, have policies/procedures, manage business associates, and have an incident response process. Maintaining documentation for six years is also emphasized.

Uploaded by

Hetik Go
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 1

HIPAA Compliance Checklist

The following are identified by HHS OCR as elements of an effective compliance program.
Please check off as applicable to self-evaluate your practice or organization.

Have you conducted the following six (6) required annual Audits/Assessments?
❑ Security Risk Assessment ❑ Security Standards Audit
❑ Privacy Standards Audit (Not required for BAs) ❑ Asset and Device Audit
❑ HITECH Subtitle D Privacy Audit ❑ Physical Site Audit

Have you identified all gaps uncovered in the audits above?


❑ Have you documented all deficiencies?

Have you created remediation plans to address deficiencies found in all six (6) Audits?
❑ Are these remediation plans fully documented in writing?
❑ Do you update and review these remediation plans annually?
❑ Are annually documented remediation plans retained in your records for six (6) years?

Have all staff members undergone annual HIPAA training?


❑ Do you have documentation of their training?
❑ Is there a staff member designated as the HIPAA Compliance, Privacy, and/or Security Officer?

Do you have Policies and Procedures relevant to the annual HIPAA Privacy, Security, and
Breach Notification Rules?
❑ Have all staff members read and legally attested to the Policies and Procedures?
❑ Do you have documentation of their legal attestation?
❑ Do you have documentation for annual reviews of your Policies and Procedures?

Have you identified all of your vendors and Business Associates?


❑ Do you have Business Associate Agreements in place with all Business Associates?
❑ Have you performed due diligence on your Business Associates to assess their HIPAA compliance?
❑ Are you tracking and reviewing your Business Associate Agreements annually?
❑ Do you have Confidentiality Agreements with non-Business Associate vendors?

Do you have a defined process for incidents or breaches?


❑ Do you have the ability to track and manage the investigations of all incidents?
❑ Are you able to provide the required reporting of minor or meaningful breaches or incidents?
❑ Do your staff members have the ability to anonymously report an incident?

* AUDIT TIP: If audited, you must provide all documentation for the past six (6) years to auditors.

Need help completing your Checklist? Schedule your HIPAA consultation today at
855-85-HIPAA or info@compliancygroup.com
This checklist is composed of general questions about the measures your organization should have in place to state that you are HIPAA compliant,
and does not qualify as legal advice. Successfully completing this checklist does not certify that you or your organization are HIPAA compliant.

Private & Confidential

You might also like

pFad - Phonifier reborn

Pfad - The Proxy pFad of © 2024 Garber Painting. All rights reserved.

Note: This service is not intended for secure transactions such as banking, social media, email, or purchasing. Use at your own risk. We assume no liability whatsoever for broken pages.


Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy