HIPAA checklist
The HIPAA safeguards the mid-market clinic actually faces.
The Privacy Rule, the Security Rule, and the Breach Notification obligations the HHS Office for Civil Rights pulls on first — mapped to the administrative, physical, and technical safeguards the mid-market clinic actually faces. The full control walk-through, the evidence artifacts each one demands, and the package the auditor signs off on are written up in the long-form checklist.
Privacy Rule · Security Rule · Breach Notification
What “HIPAA-ready” looks like
A working HIPAA program at the Tier 1 Foundation level covers the Security Rule technical safeguards (access control, audit controls, integrity, transmission security), the administrative safeguards (workforce training, contingency planning, the BAA roster), and the Breach Notification clock — the 60-day notification window that drives most of the operational risk in the clinic.
The full checklist — control-by-control evidence list, the workforce-training cadence, and the BAA/DPA templates — is being written up against the founder’s first reviewer round. For now, the hub at /resources indexes all four framework checklists; pricing for HIPAA-only coverage starts at the $2K Foundation tier.
More frameworks
See all checklists →HIPAA, SOC 2, PCI DSS, GDPR — pick by the framework your auditor opens on first.