You are currently viewing HIPAA Compliance Checklist for 2026

HIPAA Compliance Checklist for 2026

A HIPAA compliance checklist only helps if it matches what the law asks for right now, not what a vendor hopes to sell you. This one covers the safeguards regulators actually check in 2026, in plain order. Work through it in an afternoon and you will know exactly where your practice stands, and what a fair price looks like for closing the gaps.

Shopping for HIPAA compliance? Skip the vendor calls — we’ll get you real quotes from 3 vetted providers in 24 hours. Free, no obligation. Get my free shortlist → How we make money →

The Short Answer

A HIPAA compliance checklist for 2026 requires running a security risk assessment annually and after major changes, implementing administrative, physical, and technical safeguards, and signing business associate agreements with all vendors handling PHI. The proposed Security Rule update from January 2025 would add mandatory annual penetration testing and semi-annual vulnerability scanning, though these are not yet required. Practices should document all policies, assessments, and training records for six years to meet regulatory expectations. Encryption of PHI on devices and in transit is essential, as skipping it could lead to legal consequences after a breach.

The HIPAA Compliance Checklist That Applies in 2026

A HIPAA compliance checklist for 2026 covers five jobs: run a security risk assessment, fix what it finds, control who touches patient data, get a signed business associate agreement from every vendor that handles that data, and keep written proof of all of it. Everything else on the list below hangs off one of those five.

One thing to clear up first, because vendors muddy it constantly. There is no new 2026 version of the Security Rule. Today’s rule asks for risk-based evaluation: you assess your own threats and pick reasonable safeguards for your size and setup. A proposed update from January 2025 would add stricter testing requirements, and we cover exactly what that means further down, clearly labeled as proposed.

This guide updates our original HIPAA checklist with what has changed since we wrote it, and what has not.

What HIPAA Requires Today

The Security Rule splits safeguards into three buckets: administrative, physical, and technical. Work through them in that order, because the paperwork in the first bucket decides what you buy in the third.

Administrative safeguards

  • Run a security risk assessment that lists where electronic PHI lives, what threatens it, and how likely each threat is. Repeat it at least annually and after any big change, like a new EHR or a new location.
  • Turn the findings into a written risk management plan with an owner and a deadline for each gap.
  • Name a security officer. In a small practice one person can hold the role, but the name has to go on paper.
  • Train every workforce member on phishing, passwords, and PHI handling, then keep the attendance records.
  • Write a sanction policy that says what happens when someone breaks the rules, and apply it evenly.
  • Build an incident response plan: who investigates, who decides whether an event counts as a breach, and who notifies patients and HHS on the breach notification clock.

Physical safeguards

  • Control entry to any room where servers, workstations, or paper charts sit. Badge logs and keyed access both count.
  • Track every device that stores PHI, from laptops to the old billing PC in the closet.
  • Set a disposal process that wipes or destroys drives before equipment leaves the building.
  • Position screens so patients in the waiting room cannot read them, and lock workstations when staff step away.

Technical safeguards

  • Give every user a unique login. Shared accounts hide who did what, and auditors treat them as an automatic finding.
  • Turn on multi-factor authentication for email, the EHR, and remote access. Microsoft’s 2023 research found MFA blocks roughly 99% of automated account compromise, which makes it the cheapest high-impact item on this list.
  • Encrypt PHI on laptops, phones, servers, and backups, and in transit. Skipping encryption means defending that decision in writing after a breach, so almost nobody should skip it.
  • Set automatic logoff on workstations and configure audit logs in the EHR, then actually review those logs monthly.
  • Back up ePHI and test a restore at least quarterly. A backup nobody has ever restored is a hope, not a control.

Vendors and paperwork

  • Sign a business associate agreement with every vendor that touches PHI: the EHR company, the billing service, the IT firm, the shredding company, the cloud backup provider.
  • Keep all policies, assessments, and training records for six years. When an investigator asks, documentation makes the difference between a corrective action plan and a fine.
  • Review your list of business associates annually, because practices add tools far faster than they add contracts.

The One Item to Watch: The Proposed Security Rule Update

In January 2025, HHS published a proposed rule, an NPRM, that would tighten the Security Rule. Two changes matter most for a checklist: penetration testing every 12 months and vulnerability scanning every 6 months would become explicit requirements instead of options you weigh in a risk assessment.

None of that is law yet. Final action will come no earlier than 2027, and the details may change before then. So the honest checklist entry reads like this: Proposed, not required today: annual penetration testing and twice-yearly vulnerability scanning, if the proposed rule finalizes as written.

Worth knowing: many practices already run an annual test anyway, because it is the clearest way to prove the risk-based evaluation today’s rule does require. If you go that route, read up on what penetration testing actually costs before anyone quotes you, since the same three words can describe $500 of scanner time or two weeks of skilled human work.

Want to skip the line? Browse vetted HIPAA compliance services and order on your terms. Self-Order in the Marketplace →

What a Fair Quote Looks Like

Vendors sell HIPAA work in pieces, so sanity-check each piece against these bands before you sign anything.

Service What a fair quote looks like
Security risk assessment A fixed fee scoped to your locations, systems, and vendor count, with a written report and remediation plan included
Penetration test $5,000 to $20,000 per project, depending on scope
Endpoint detection and response (EDR) $8 to $15 per device per month
Managed detection and response (MDR) $15 to $25 per device per month
Zero trust and identity stack $5 to $15 per user per month
Virtual CISO Priced by hours per month; get the hour count and deliverables in writing

Two patterns should make you pause. A “complete HIPAA compliance” package priced under a thousand dollars is almost always a policy template bundle with no real assessment behind it. At the other end, a quote that mixes tools, testing, and consulting into one round number with no line items makes comparison shopping impossible.

Most small practices do better bundling the technical safeguards into managed cyber security services than buying five tools separately, because one provider then owns the monitoring, the patching, and the audit trail your documentation depends on.

How to Choose a HIPAA Compliance Provider

Start with questions that separate practitioners from template shops:

  • Show me a sample risk assessment report. A real one maps threats to your actual systems, not a generic list with your logo on it.
  • Who does the work, and what are their credentials? Ask for names, not a reassurance about “our team”.
  • How do you handle findings? An assessment without a remediation plan and follow-up dates just documents your liability.
  • What happens if OCR investigates us? Good providers explain exactly what documentation they hand you, and how fast.
  • Is the proposed rule in your roadmap? The right answer notes that it is a proposal and may change. A vendor that calls annual penetration testing “already mandatory” is either confused or pressuring you.

The biggest trap in this market is the word “certified”, because no government body certifies HIPAA compliance. Any seal or certificate a vendor sells works as training evidence, never as a legal shield. Another trap is the vulnerability scan invoiced as a penetration test, which the pricing post linked above breaks down in detail.

When is the cheap option fine? A solo practice on a fully hosted EHR, with three laptops and no server closet, can reasonably start with a solid risk assessment, MFA everywhere, encrypted laptops, and staff training, then grow from there. Spend more when you run your own servers, hold years of records, or bill for multiple providers.

This is where the broker model earns its keep. In our network, 54 providers run security risk assessments, 52 do penetration testing, and 40 offer virtual CISO services, and we match you with three that fit your size and budget within 24 hours. Vendors pay us, you never do, so we have no reason to push the expensive option.

Frequently Asked Questions

What does a HIPAA compliance checklist need to cover?

Five areas: a security risk assessment, administrative safeguards like training and policies, physical safeguards for offices and devices, technical safeguards like MFA and encryption, and business associate agreements with every vendor that touches PHI. Documentation ties it all together, since investigators judge you on what you can prove, and six years is the standard retention period for those records.

Does HIPAA require penetration testing?

Not today. The current Security Rule requires a risk-based evaluation, and you choose how to test based on your own risk assessment. A proposed rule from January 2025 would mandate penetration testing every 12 months and vulnerability scanning every 6, but final action will come no earlier than 2027 and the details may change. Treat annual testing as smart practice for now, not a legal mandate.

How often does a HIPAA risk assessment need to happen?

At least once a year, plus after any significant change: a new EHR, a new location, a merger, or a breach. HHS never wrote an exact interval into the rule, but annual is the cadence investigators expect to see and the one that keeps your documentation current. Many practices pair the assessment with their cyber insurance renewal so both use the same evidence.

Is there an official HIPAA certification?

No. Neither HHS nor OCR certifies any organization as HIPAA compliant, so every certificate on the market is a private credential rather than a government one. Certificates can still help as training evidence and customer reassurance. Just never treat one as proof of compliance, because regulators judge your risk assessment, safeguards, and records at the moment something goes wrong.

How much does HIPAA compliance cost a small practice?

Plan in pieces rather than one number. A risk assessment is a scoped project tied to your size, EDR runs $8 to $15 per device per month, MDR runs $15 to $25 per device per month, and a penetration test runs $5,000 to $20,000 per project if you choose to do one. Training and policy work add a modest annual cost. Get line items so you can compare quotes fairly.

Written by Russ Herman, founder of Defend My Business. We are a technology broker, like a mortgage broker but for business security, internet, and voice. We hold agreements with 400+ vetted providers. Vendors pay us, you never do. See exactly how we make money. Questions: 1-877-453-8759 or [email protected].

Get a Tailored HIPAA compliance Shortlist

3 vetted vendors matched to your size, industry, and budget. Free, vendor-neutral, 24-hour turnaround.

Get a Quote →
Get It Right the First Time

Want help getting your compliance program right?

Defend My Business helps SMBs cut through the marketing and get their compliance program right for their environment, budget, and compliance needs — then deploy and manage it. Through our 400+ vendor network we can often secure better pricing and terms than buying direct, and we stay vendor-neutral, so the recommendation fits you, not a sales quota. Want a second opinion? Pair this with our compliance services or talk it through with an advisor.

Book a free call with a DMB advisor →

Russ Herman

Russ Herman is the founder of Defend My Business, a cybersecurity advisory for small and mid-sized businesses. He works with the DisruptionIO partner network of 400+ vetted providers across cybersecurity, connectivity, cloud, and disaster recovery to help SMB owners and IT leaders cut through vendor noise with plain-English guidance and 24-hour shortlists from a pre-vetted ecosystem.

Leave a Reply