HIPAA Compliance Audit Readiness Checklist for Small Practices
A practical checklist of the evidence and documentation a small clinic needs to be ready for a HIPAA audit, with the specific CFR citations OCR expects you to follow.
What Evidence Does a Small Practice Need for a HIPAA Audit?
When the HHS Office for Civil Rights (OCR) conducts a HIPAA audit or investigates a complaint, they request specific documentation. Small practices are held to the same standards as large health systems. The difference is scope, not obligation. Here is what OCR typically expects to see:
- Security Risk Assessment documentation under 45 CFR §164.308(a)(1)(ii)(A) — a written analysis identifying threats and vulnerabilities to all electronic PHI your practice creates, receives, maintains, or transmits
- Written policies and procedures under 45 CFR §164.316(a) — documented standards covering PHI handling, access controls, workforce conduct, and breach response
- Workforce training records under 45 CFR §164.308(a)(5)(i) — evidence that all workforce members with PHI access received HIPAA training at hire and when policies changed, including dates, topics, and attendance
- Business Associate Agreement inventory under 45 CFR §164.502(e) — signed BAAs for every vendor that creates, receives, maintains, or transmits PHI on your behalf
- Incident response plan and breach notification procedures under 45 CFR §164.404(b) — a documented process for identifying, investigating, and reporting breaches, including notification to affected individuals within 60 days of discovery
- Documentation retention proof under 45 CFR §164.530(j) — evidence that compliance-related records (policies, training logs, risk assessments, BAAs, incident reports) have been retained for at least six years
Key point: OCR does not expect perfection. They expect to see that your practice has identified its risks, put reasonable safeguards in place, documented those efforts, and is maintaining an ongoing compliance program. A practice with a documented risk assessment and written policies is in a fundamentally different position than one with nothing on paper.
The HIPAA Audit-Readiness Checklist
Use this checklist to verify that your practice has the documentation and safeguards OCR expects. Each item references the specific CFR section that establishes the requirement.
What to Do If Your Clinic Has No Risk Assessment or Written Policies
If your clinic has no HIPAA risk assessment or written policies yet, start with a Security Risk Analysis now: identify where PHI is stored and transmitted, list your vendors and devices, document the main risks, then put the required policies and procedures in writing and assign someone responsible for security. HHS says regulated entities must periodically assess how well their policies and safeguards meet the Security Rule, and ONC/HHS offers a Security Risk Assessment Tool to help get started.
Here is a practical starting sequence for a small practice beginning from scratch:
- Designate a Security Officer — Under §164.308(a)(2), someone in your practice must be formally responsible for HIPAA security. In a small clinic, this is often the office manager or practice owner.
- Conduct a Security Risk Assessment — Under §164.308(a)(1)(ii)(A), identify where electronic PHI lives in your practice: your EHR, email, fax machines, portable devices, cloud storage, and vendor systems. Document the threats and vulnerabilities for each.
- Inventory your vendors and devices — List every vendor that touches PHI (EHR, billing service, cloud backup, IT support, shredding company) and every device that stores or accesses PHI (computers, phones, tablets, external drives).
- Get BAAs signed — Under §164.502(e), every vendor handling PHI must have a signed Business Associate Agreement. If you do not have BAAs in place, start with your EHR vendor, billing service, and cloud providers.
- Put policies in writing — Under §164.316(a), your practice needs written policies and procedures covering access controls, PHI handling, breach notification, workforce sanctions, and device management.
- Train your staff — Under §164.308(a)(5)(i), all workforce members must receive HIPAA training and you must document it with dates, topics, and attendance records.
The most important step is the first one. A practice that has started documenting its risks and putting safeguards in place is in a much stronger position than one that has done nothing. OCR has stated that the lack of a risk assessment is the most common finding in enforcement actions. Starting now, even if the work is not yet complete, demonstrates a good-faith compliance effort.
This content is for educational and informational purposes only and should not be construed as legal advice.
HIPAA Audit Readiness Questions
Learn More About HIPAA Audit Readiness
Book Your Free HIPAA Compliance Review
Schedule a free 30-minute call to review your current compliance status and identify what your practice needs for audit readiness.
Book Your Free HIPAA Compliance Review