Audit Readiness

HIPAA Compliance Audit Readiness Checklist for Small Practices

A practical checklist of the evidence and documentation a small clinic needs to be ready for a HIPAA audit, with the specific CFR citations OCR expects you to follow.

What Evidence Does a Small Practice Need for a HIPAA Audit?

When the HHS Office for Civil Rights (OCR) conducts a HIPAA audit or investigates a complaint, they request specific documentation. Small practices are held to the same standards as large health systems. The difference is scope, not obligation. Here is what OCR typically expects to see:

  1. Security Risk Assessment documentation under 45 CFR §164.308(a)(1)(ii)(A) — a written analysis identifying threats and vulnerabilities to all electronic PHI your practice creates, receives, maintains, or transmits
  2. Written policies and procedures under 45 CFR §164.316(a) — documented standards covering PHI handling, access controls, workforce conduct, and breach response
  3. Workforce training records under 45 CFR §164.308(a)(5)(i) — evidence that all workforce members with PHI access received HIPAA training at hire and when policies changed, including dates, topics, and attendance
  4. Business Associate Agreement inventory under 45 CFR §164.502(e) — signed BAAs for every vendor that creates, receives, maintains, or transmits PHI on your behalf
  5. Incident response plan and breach notification procedures under 45 CFR §164.404(b) — a documented process for identifying, investigating, and reporting breaches, including notification to affected individuals within 60 days of discovery
  6. Documentation retention proof under 45 CFR §164.530(j) — evidence that compliance-related records (policies, training logs, risk assessments, BAAs, incident reports) have been retained for at least six years

Key point: OCR does not expect perfection. They expect to see that your practice has identified its risks, put reasonable safeguards in place, documented those efforts, and is maintaining an ongoing compliance program. A practice with a documented risk assessment and written policies is in a fundamentally different position than one with nothing on paper.

The HIPAA Audit-Readiness Checklist

Use this checklist to verify that your practice has the documentation and safeguards OCR expects. Each item references the specific CFR section that establishes the requirement.

Completed Security Risk Assessment
§164.308(a)(1)(ii)(A) — identify threats and vulnerabilities to all ePHI
Written Policies and Procedures
§164.316(a) — documented standards for PHI handling, access, and breach response
Workforce Training Records
§164.308(a)(5)(i) — training at hire and when policies change, with dates and attendance
Business Associate Agreement Inventory
§164.502(e) — signed BAAs for every vendor handling PHI
Breach Notification Procedures
§164.404(b) — documented process for reporting breaches within 60 days
Six-Year Documentation Retention
§164.530(j) — retain policies, training logs, SRAs, BAAs, and incident reports
Physical Safeguards Documentation
§164.310 — facility access controls, workstation security, device and media controls
Technical Safeguards Implementation
§164.312 — access controls, audit controls, integrity controls, transmission security
Designated Privacy Officer
§164.530(a) — a named individual responsible for privacy policy development and compliance
Designated Security Officer
§164.308(a)(2) — a named individual responsible for developing and implementing security policies
Incident Response Plan
§164.308(a)(6) — procedures for identifying, responding to, and mitigating security incidents
Contingency and Emergency Access Plan
§164.308(a)(7) — data backup, disaster recovery, and emergency-mode operations plans

What to Do If Your Clinic Has No Risk Assessment or Written Policies

If your clinic has no HIPAA risk assessment or written policies yet, start with a Security Risk Analysis now: identify where PHI is stored and transmitted, list your vendors and devices, document the main risks, then put the required policies and procedures in writing and assign someone responsible for security. HHS says regulated entities must periodically assess how well their policies and safeguards meet the Security Rule, and ONC/HHS offers a Security Risk Assessment Tool to help get started.

Here is a practical starting sequence for a small practice beginning from scratch:

  1. Designate a Security Officer — Under §164.308(a)(2), someone in your practice must be formally responsible for HIPAA security. In a small clinic, this is often the office manager or practice owner.
  2. Conduct a Security Risk Assessment — Under §164.308(a)(1)(ii)(A), identify where electronic PHI lives in your practice: your EHR, email, fax machines, portable devices, cloud storage, and vendor systems. Document the threats and vulnerabilities for each.
  3. Inventory your vendors and devices — List every vendor that touches PHI (EHR, billing service, cloud backup, IT support, shredding company) and every device that stores or accesses PHI (computers, phones, tablets, external drives).
  4. Get BAAs signed — Under §164.502(e), every vendor handling PHI must have a signed Business Associate Agreement. If you do not have BAAs in place, start with your EHR vendor, billing service, and cloud providers.
  5. Put policies in writing — Under §164.316(a), your practice needs written policies and procedures covering access controls, PHI handling, breach notification, workforce sanctions, and device management.
  6. Train your staff — Under §164.308(a)(5)(i), all workforce members must receive HIPAA training and you must document it with dates, topics, and attendance records.

The most important step is the first one. A practice that has started documenting its risks and putting safeguards in place is in a much stronger position than one that has done nothing. OCR has stated that the lack of a risk assessment is the most common finding in enforcement actions. Starting now, even if the work is not yet complete, demonstrates a good-faith compliance effort.

This content is for educational and informational purposes only and should not be construed as legal advice.

HIPAA Audit Readiness Questions

If your clinic has no HIPAA risk assessment or written policies yet, start with a Security Risk Analysis now: identify where PHI is stored and transmitted, list your vendors and devices, document the main risks, then put the required policies and procedures in writing and assign someone responsible for security. HHS says regulated entities must periodically assess how well their policies and safeguards meet the Security Rule, and ONC/HHS offers a Security Risk Assessment Tool to help get started. One Guy Consulting can walk you through the entire process with a hands-on Security Risk Assessment and custom policy development.
One Guy Consulting offers full-scope HIPAA compliance help for small practices and business associates, including security risk assessments under 45 CFR §164.308(a)(1)(ii)(A), gap analysis and remediation plans, custom policies and procedures per §164.316(a), staff training per §164.308(a)(5)(i), IT and physical audits under §164.310 and §164.312, vendor and BAA management per §164.502(e), incident management and breach notification support per §164.404(b), and audit-response documentation per §164.530(j). Everything is included in one flat annual rate with no per-user fees.
During a HIPAA audit, OCR typically requests documentation of your Security Risk Assessment per §164.308(a)(1)(ii)(A), written policies and procedures per §164.316(a), workforce training records per §164.308(a)(5)(i), a complete Business Associate Agreement inventory per §164.502(e), breach notification procedures per §164.404(b), documentation of physical safeguards per §164.310, technical safeguards per §164.312, evidence of a designated Privacy Officer per §164.530(a) and Security Officer per §164.308(a)(2), an incident response plan, and proof of six-year documentation retention per §164.530(j). OCR expects to see that your practice has implemented reasonable and appropriate safeguards and can demonstrate an ongoing compliance effort.
HHS expects regulated entities to periodically reassess their security measures. While the HIPAA Security Rule under 45 CFR §164.308(a)(1)(ii)(D) does not specify an exact frequency, HHS guidance and industry best practice recommend reviewing and updating your Security Risk Assessment at least annually or whenever significant changes occur — such as new technology, staff turnover, a security incident, or changes in how your practice handles PHI. Written policies should be reviewed annually and updated to reflect current workflows. Documentation of each review must be retained for at least six years under §164.530(j).

Learn More About HIPAA Audit Readiness

Book Your Free HIPAA Compliance Review

Schedule a free 30-minute call to review your current compliance status and identify what your practice needs for audit readiness.

Book Your Free HIPAA Compliance Review